Win32 alureon, ordinateur infecté

Résolu
Bonjour,

Je constate que je ne suis pas la seule dans ce cas, mon PC est également infecté par win32 alureon. Je n'y connais pas grand chose en informatique, j'essaie de trouver des solutions, mais pour l'instant je suis plutôt dans le mode "je rame". Ca fait un peu plus d'un mois que mon ordinateur est infecté et je ne m'en sors pas. Après avoir parcouru les forums, j'ai téléchargé malware pour détecter le virus, me voilà donc avec 2 rapports auxquels je ne comprends rien ...
Quelqu'un pourrait il m'aider s'il vous plait ?...
D'autre part, j'ai mon lecteur window media qui ne lit plus certains fichiers audios (qu'il lisait sans aucun problème avant), peut il y avoir un rapport ? Cela pourrait être une histoire de codec éventuellement supprimé par le virus...?

Excusez la foire aux questions de ce post...

Merci par avance.
Configuration: Windows Vista Internet Explorer 7.0

42 réponses

Résumé de la discussion

Une infection par Win32 Alureon sur un système Windows Vista est décrite, provoquant des ralentissements et des alertes, tandis que deux rapports d’outils de détection restent difficiles à interpréter. Plusieurs conseils préconisent des scans en ligne et l’usage d’outils spécialisés comme ComboFix pour désinfecter le système, en notant que BitDefender est jugé efficace alors que Avast peut être plus fiable selon les messages. En parallèle, des éléments montrent que le blocage d’accès Internet et les modifications de clés Run et de services nécessitent une intervention manuelle ou une restauration du système, avec sauvegarde préalable des données.

Bobot (l’IA à votre service)
  1. Contributeur sécurité
    bonjour, si tu as des rapport postes les , Merci

    sinon pour y voir plus claire poste un RSIT !!

    1) Télécharges et installes HijackThis :

    https://www.commentcamarche.net/telecharger/securite/11747-hijackthis/

    Cliques sur le fichier hijackthis téléchargé pour lancer l'installation
    laisses toi guider et ne modifies pas les paramètres d'installation .
    A la fin de l’installation, le programme se lance automatiquement
    fermes le en cliquant sur la croix rouge.

    Ne lances pas ce programme pour l'instant et fais la suite

    2) Télécharge Random's System Information Tool (RSIT) de random/random et enregistre l'exécutable sur ton Bureau.

    -> http://images.malwareremoval.com/random/RSIT.exe

    .Déconnectes toi et fermes toutes tes applications en cours

    Double-clique sur " RSIT.exe " pour le lancer.

    Clic droit sous VISTA (exécuter en tant que…)

    .Une première fenêtre s'ouvre avec en titre : " Disclaimer of warranty " .

    .Devant l'option "List files/folders created ..." , tu choisis : 1 months

    .cliques ensuite sur " Continuer " pour lancer l'analyse

    .laisses faire le scan et ne touches pas au PC

    Lorsque l'analyse sera terminée, deux fichiers texte s'ouvriront

    Postes le contenu de " log.txt " , ainsi que de " info.txt " (que tu verras dans la barre des tâches), pour analyse et attends la suite ...

    Important : poste un rapport, puis l'autre dans la réponse suivante

    Si tu essaies de poster les deux en même temps, cela risque d'être trop long pour le forum ??

    Note : les rapports seront en outre sauvegardés dans ce dossier C:\rsit

    0
    1. Merci de cette réponse ultra rapide !

      Voici les 2 rapports (ca me parait très long tout ce que je vais poster, mais je sais ce qu'il faut exactement, désolée) :

      1er rapport :

      info.txt logfile of random's system information tool 1.06 2010-02-12 19:08:37

      ======Uninstall list======

      -->"C:\Program Files\InstallShield Installation Information\{A644254B-92F6-4970-8635-AB0775371E72}\setup.exe" --u:{A644254B-92F6-4970-8635-AB0775371E72}
      -->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{622E6F16-0904-49B6-BBE1-4CC836314CCF}\setup.exe" -l0x40c
      -->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{697AFC77-F318-4CD4-BF16-F50F4C1072DA}\setup.exe" -l0x40c
      Adobe Acrobat and Reader 8.1.2 Security Update 1 (KB403742)-->MsiExec.exe /X{6846389C-BAC0-4374-808E-B120F86AF5D7}
      Adobe Flash Player 10 ActiveX-->C:\Windows\system32\Macromed\Flash\uninstall_activeX.exe
      Adobe Reader 8.1.2 - Français-->MsiExec.exe /I{AC76BA86-7AD7-1036-7B44-A81200000003}
      Adobe® Photoshop® Album Edition Découverte 3.2-->MsiExec.exe /I{A654A805-41D9-40C7-AA46-4AF04F044D61}
      Apple Software Update-->MsiExec.exe /I{6956856F-B6B3-4BE0-BA0B-8F495BE32033}
      Assistant de connexion Windows Live-->MsiExec.exe /I{D3116CC7-24DC-4CA3-9CE1-23FED836E9F2}
      Atheros Driver Installation Program-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{28006915-2739-4EBE-B5E8-49B25D32EB33}\setup.exe" -l0x40c -removeonly
      avast! Free Antivirus-->C:\Program Files\Alwil Software\Avast5\aswRunDll.exe "C:\Program Files\Alwil Software\Avast5\Setup\setiface.dll" RunSetup
      BlazeDTV 2.5a-->"C:\Program Files\BlazeVideo\BlazeDTV 2.5a\unins000.exe"
      Bluetooth Stack for Windows by Toshiba-->MsiExec.exe /X{CEBB6BFB-D708-4F99-A633-BC2600E01EF6}
      Camera Assistant Software for Toshiba-->C:\Program Files\InstallShield Installation Information\{37C866E4-AA67-4725-9E95-A39968DD7960}\setup.exe -runfromtemp -l0x040c
      Canon Camera Support Core Library-->C:\Program Files\Common Files\InstallShield\Driver\8\Intel 32\IDriver.exe /M{A1D0D14A-B776-4907-BC00-5149F2298086} /l1036
      Canon Camera Window DC_DV 5 for ZoomBrowser EX-->C:\Program Files\Common Files\InstallShield\Driver\8\Intel 32\IDriver.exe /M{A2EB8F2E-6D9B-4F8B-96EB-F976D33F416F}
      Canon Camera Window DSLR 5 for ZoomBrowser EX-->C:\Program Files\Common Files\InstallShield\Driver\8\Intel 32\IDriver.exe /M{0A146245-DB79-4197-BF5D-FE1A699A2CC7}
      Canon Camera Window MC 5 for ZoomBrowser EX-->C:\Program Files\Common Files\InstallShield\Driver\8\Intel 32\IDriver.exe /M{36C65B50-37BA-4467-AAD5-0523EFDF6F62}
      Canon EOS Kiss_N REBEL_XT 350D Pilote WIA -->C:\Program Files\Common Files\InstallShield\Driver\8\Intel 32\IDriver.exe /M{33CF7CDF-9805-4500-9CC7-D19D52AD63C4} /l1036
      CANON iMAGE GATEWAY Task for ZoomBrowser EX-->C:\Program Files\Common Files\InstallShield\Driver\8\Intel 32\IDriver.exe /M{5B03B93F-1B32-4509-9CA6-4BB33E9987EF}
      Canon Internet Library for ZoomBrowser EX-->C:\Program Files\Common Files\InstallShield\Driver\8\Intel 32\IDriver.exe /M{D0E8C34D-19D2-49FD-A900-88DEB788FF86}
      Canon iP1800 series-->"C:\Windows\system32\CanonIJ Uninstaller Information\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_iP1800_series\DelDrv.exe" /U:{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_iP1800_series /L0x000c
      Canon MP Navigator 3.1-->"C:\Program Files\Canon\MP Navigator 3.1\Maint.exe" /UninstallRemove C:\Program Files\Canon\MP Navigator 3.1\uninst.ini
      Canon MP140 series-->"C:\Windows\system32\CanonIJ Uninstaller Information\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MP140_series\DelDrv.exe" /U:{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MP140_series /L0x000c
      Canon PhotoRecord-->MsiExec.exe /X{BBBC2B89-E193-4348-A83C-C8DD8210A4AC}
      Canon RAW Image Task for ZoomBrowser EX-->C:\Program Files\Common Files\InstallShield\Driver\8\Intel 32\IDriver.exe /M{BAA43DA2-B6C5-46EC-B163-0E8EEAF975A4}
      Canon Utilities Digital Photo Professional 2.0-->C:\Program Files\Common Files\InstallShield\Driver\8\Intel 32\IDriver.exe /M{17BF3045-AB1D-4048-8356-6C584B83565E} /l1036
      Canon Utilities Easy-LayoutPrint-->C:\Program Files\Canon\Easy-LayoutPrint\uninst.exe uninst.ini
      Canon Utilities Easy-PhotoPrint-->C:\Program Files\Canon\Easy-PhotoPrint\uninst.exe uninst.ini
      Canon Utilities Easy-PrintToolBox-->C:\Program Files\Canon\Easy-PrintToolBox\uninst.exe uninst.ini
      Canon Utilities EOS Capture 1.5-->C:\Program Files\Common Files\InstallShield\Driver\8\Intel 32\IDriver.exe /M{589D17BB-C997-48C0-BCD2-CC8DC3375FE8}
      Canon Utilities PhotoStitch 3.1-->C:\Program Files\Common Files\InstallShield\Driver\8\Intel 32\IDriver.exe /M{874E44F3-B9A7-4AA1-B4BA-83E5684ED9C6}
      Canon ZoomBrowser EX (F)-->MsiExec.exe /X{C1D76D7A-F3BB-47EA-A746-5B1E2FFC1DF2}
      Codeur Windows Media Série 9-->msiexec.exe /I {E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}
      Codeur Windows Media Série 9-->MsiExec.exe /I{E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}
      Desktop SMS-->MsiExec.exe /I{5980B928-1C95-4B3E-957B-B02D8147FF9E}
      DivX Web Player-->C:\Program Files\DivX\DivXWebPlayerUninstall.exe /PLUGIN
      DVD MovieFactory for TOSHIBA-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F214EAA4-A069-4BAF-9DA4-4DB8BEEDE485}\setup.exe" -l0x40c
      Emdedded IR Driver-->C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\1050\INTEL3~1\IDriver.exe /M{A6D4234C-CB02-4048-AC3E-AD09404FA35A}
      eMule-->"C:\Program Files\eMule\Uninstall.exe"
      Enregistrement utilisateur de Canon iP1800 series-->C:\Program Files\Canon\IJEREG\iP1800 series\UNINST.EXE
      Enregistrement utilisateur de Canon MP140 series-->C:\Program Files\Canon\IJEREG\MP140 series\UNINST.EXE
      Galerie de photos Windows Live-->MsiExec.exe /X{B131E59D-202C-43C6-84C9-68F0C37541F1}
      Google Toolbar for Internet Explorer-->"C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarManager_E85CDE7661A53A6A.exe" /uninstall
      Google Toolbar for Internet Explorer-->MsiExec.exe /I{18455581-E099-4BA8-BC6B-F34B2F06600C}
      Google Update Helper-->MsiExec.exe /I{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}
      HijackThis 2.0.2-->"C:\Program Files\trend micro\HijackThis.exe" /uninstall
      Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)-->C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall /qb+ REBOOTPROMPT=""
      Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)-->C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {A7EEA2F2-BFCD-4A54-A575-7B81A786E658} /qb+ REBOOTPROMPT=""
      Installation Windows Live-->C:\Program Files\Windows Live\Installer\wlarp.exe
      Installation Windows Live-->MsiExec.exe /I{46ABBC54-1872-4AA3-95E2-F2C063A63F31}
      Intel Matrix Storage Manager-->C:\Windows\system32\imsmudlg.exe -uninstall
      Intel(R) Graphics Media Accelerator Driver-->C:\Windows\system32\igxpun.exe -uninstall
      Java(TM) 6 Update 12-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216012FF}
      Junk Mail filter update-->MsiExec.exe /I{E2DFE069-083E-4631-9B6C-43C48E991DE5}
      K-Lite Codec Pack 3.7.0 Full-->"C:\Program Files\K-Lite Codec Pack\unins000.exe"
      LiveUpdate 3.2 (Symantec Corporation)-->"C:\Program Files\Symantec\LiveUpdate\LSETUP.EXE" /U
      LiveUpdate Notice (Symantec Corporation)-->MsiExec.exe /X{DBA4DB9D-EE51-4944-A419-98AB1F1249C8}
      Logiciel d'archivage WinRAR-->C:\Program Files\WinRAR\uninstall.exe
      Microsoft .NET Framework 3.5 Language Pack SP1 - fra-->MsiExec.exe /I{3E31821C-7917-367E-938E-E65FC413EA31}
      Microsoft .NET Framework 3.5 SP1-->C:\Windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setup.exe
      Microsoft .NET Framework 3.5 SP1-->MsiExec.exe /I{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}
      Microsoft Choice Guard-->MsiExec.exe /X{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}
      Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0016-040C-0000-0000000FF1CE} /uninstall {AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
      Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0018-040C-0000-0000000FF1CE} /uninstall {AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
      Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001B-040C-0000-0000000FF1CE} /uninstall {AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
      Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-006E-040C-0000-0000000FF1CE} /uninstall {B165D3C2-40AE-4D39-86F7-E5C87C4264C0}
      Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-00A1-040C-0000-0000000FF1CE} /uninstall {AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
      Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}
      Microsoft Office Excel MUI (French) 2007-->MsiExec.exe /X{90120000-0016-040C-0000-0000000FF1CE}
      Microsoft Office Home and Student 2007-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE12\Office Setup Controller\setup.exe" /uninstall HOMESTUDENTR /dll OSETUP.DLL
      Microsoft Office Home and Student 2007-->MsiExec.exe /X{91120000-002F-0000-0000-0000000FF1CE}
      Microsoft Office Live Add-in 1.3-->MsiExec.exe /I{57F0ED40-8F11-41AA-B926-4A66D0D1A9CC}
      Microsoft Office OneNote MUI (French) 2007-->MsiExec.exe /X{90120000-00A1-040C-0000-0000000FF1CE}
      Microsoft Office PowerPoint MUI (French) 2007-->MsiExec.exe /X{90120000-0018-040C-0000-0000000FF1CE}
      Microsoft Office Proof (Arabic) 2007-->MsiExec.exe /X{90120000-001F-0401-0000-0000000FF1CE}
      Microsoft Office Proof (Dutch) 2007-->MsiExec.exe /X{90120000-001F-0413-0000-0000000FF1CE}
      Microsoft Office Proof (English) 2007-->MsiExec.exe /X{90120000-001F-0409-0000-0000000FF1CE}
      Microsoft Office Proof (French) 2007-->MsiExec.exe /X{90120000-001F-040C-0000-0000000FF1CE}
      Microsoft Office Proof (German) 2007-->MsiExec.exe /X{90120000-001F-0407-0000-0000000FF1CE}
      Microsoft Office Proof (Spanish) 2007-->MsiExec.exe /X{90120000-001F-0C0A-0000-0000000FF1CE}
      Microsoft Office Proofing (French) 2007-->MsiExec.exe /X{90120000-002C-040C-0000-0000000FF1CE}
      Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0401-0000-0000000FF1CE} /uninstall {14809F99-C601-4D4A-9391-F1E8FAA964C5}
      Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0407-0000-0000000FF1CE} /uninstall {A0516415-ED61-419A-981D-93596DA74165}
      Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0409-0000-0000000FF1CE} /uninstall {ABDDE972-355B-4AF1-89A8-DA50B7B5C045}
      Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-040C-0000-0000000FF1CE} /uninstall {F580DDD5-8D37-4998-968E-EBB76BB86787}
      Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0413-0000-0000000FF1CE} /uninstall {D66D5A44-E480-4BA4-B4F2-C554F6B30EBB}
      Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0C0A-0000-0000000FF1CE} /uninstall {187308AB-5FA7-4F14-9AB9-D290383A10D9}
      Microsoft Office Shared MUI (French) 2007-->MsiExec.exe /X{90120000-006E-040C-0000-0000000FF1CE}
      Microsoft Office Word MUI (French) 2007-->MsiExec.exe /X{90120000-001B-040C-0000-0000000FF1CE}
      Microsoft Search Enhancement Pack-->MsiExec.exe /X{4CBA3D4C-8F51-4D60-B27E-F6B641C571E7}
      Microsoft Silverlight-->MsiExec.exe /X{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
      Microsoft SQL Server 2005 Compact Edition [ENU]-->MsiExec.exe /I{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}
      Microsoft Sync Framework Runtime Native v1.0 (x86)-->MsiExec.exe /I{8A74E887-8F0F-4017-AF53-CBA42211AAA5}
      Microsoft Sync Framework Services Native v1.0 (x86)-->MsiExec.exe /I{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}
      Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148-->MsiExec.exe /X{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}
      Mise à jour Microsoft Office Excel 2007 Help (KB963678)-->msiexec /package {90120000-0016-040C-0000-0000000FF1CE} /uninstall {B761869A-B85C-40E2-994C-A1CE78AC8F2C}
      Mise à jour Microsoft Office Powerpoint 2007 Help (KB963669)-->msiexec /package {90120000-0018-040C-0000-0000000FF1CE} /uninstall {C3DCA38E-005E-41BA-A52A-7C3429F351C3}
      Mise à jour Microsoft Office Word 2007 Help (KB963665)-->msiexec /package {90120000-001B-040C-0000-0000000FF1CE} /uninstall {81536A04-DBFB-4DB3-978F-0F284590C223}
      Module linguistique Microsoft .NET Framework 3.5 SP1- fra-->C:\Windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 Language Pack SP1 - fra\setup.exe
      MSVCRT-->MsiExec.exe /I{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}
      MSXML 4.0 SP2 (KB927978)-->MsiExec.exe /I{37477865-A3F1-4772-AD43-AAFC6BCFF99F}
      MSXML 4.0 SP2 (KB936181)-->MsiExec.exe /I{C04E32E0-0416-434D-AFB9-6969D703A9EF}
      MSXML 4.0 SP2 (KB941833)-->MsiExec.exe /I{C523D256-313D-4866-B36A-F3DE528246EF}
      MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
      MSXML 4.0 SP2 (KB973688)-->MsiExec.exe /I{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}
      myphotobook 3.1-->C:\Program Files\myphotobook\uninst.exe
      Orange - Logiciels Internet-->C:\Program Files\OrangeHSS\installation\core\Installgui.exe -u
      Outil de téléchargement Windows Live-->MsiExec.exe /I{205C6BDD-7B73-42DE-8505-9A093F35A238}
      PIXMA Extended Survey Program-->C:\Program Files\Canon\IJPLM\SETUP.EXE -R
      QuickTime-->MsiExec.exe /I{8DC42D05-680B-41B0-8878-6C14D24602DB}
      Realtek 8169 PCI, 8168 and 8101E PCIe Ethernet Network Card Driver for Windows Vista-->C:\Program Files\InstallShield Installation Information\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}\setup.exe -runfromtemp -l0x040c -removeonly
      Realtek High Definition Audio Driver-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}\Setup.exe" -l0x40c -removeonly
      Réducteur de bruit lect. CD/DVD-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{9FE35071-CAB2-4E79-93E7-BFC6A2DC5C5D}\setup.exe" -l0x40c
      ScanSoft OmniPage SE 4-->MsiExec.exe /X{DEE88727-779B-47A9-ACEF-F87CA5F92A65}
      Security Update for 2007 Microsoft Office System (KB969559)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {69F52148-9BF6-4CDC-BF76-103DEAF3DD08}
      Security Update for 2007 Microsoft Office System (KB973704)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {E626DC89-A787-4553-9BB3-DC2EC7E1593F}
      Security Update for CAPICOM (KB931906)-->MsiExec.exe /I{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
      Security Update for CAPICOM (KB931906)-->MsiExec.exe /X{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
      Security Update for Microsoft Office Excel 2007 (KB973593)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {7D6255E3-3423-4D8B-A328-F6F8D28DD5FE}
      Security Update for Microsoft Office PowerPoint 2007 (KB957789)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {7559E742-FF9F-4FAE-B279-008ED296CB4D}
      Security Update for Microsoft Office system 2007 (972581)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {3D019598-7B59-447A-80AE-815B703B84FF}
      Security Update for Microsoft Office system 2007 (KB969613)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {5ECEB317-CBE9-4E08-AB10-756CB6F0FB6C}
      Security Update for Microsoft Office system 2007 (KB974234)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {FCD742B9-7A55-44BC-A776-F795F21FEDDC}
      Security Update for Microsoft Office Visio Viewer 2007 (KB973709)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {71127777-8B2C-4F97-AF7A-6CF8CAC8224D}
      Security Update for Windows Media Encoder (KB954156)-->msiexec.exe /I {E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E} MSIPATCHREMOVE={E836F1B7-43FB-46B0-A0D9-E4D2A5951659} /qb
      Synaptics Pointing Device Driver-->rundll32.exe "C:\Program Files\Synaptics\SynTP\SynISDLL.dll",standAloneUninstall
      Texas Instruments PCIxx21/x515/xx12 drivers.-->C:\Program Files\InstallShield Installation Information\{DB780B85-B4B5-4864-A49C-9B706B169C93}\setup.exe -runfromtemp -l0x040c
      TOSHIBA Assist-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{12B3A009-A080-4619-9A2A-C6DB151D8D67}\setup.exe" -l0x40c
      TOSHIBA ConfigFree-->C:\Program Files\InstallShield Installation Information\{78C6A78A-8B03-48C8-A47C-78BA1FCA2307}\setup.exe -runfromtemp -l0x040c uninstall
      TOSHIBA Disc Creator-->MsiExec.exe /X{5DA0E02F-970B-424B-BF41-513A5018E4C0}
      TOSHIBA Extended Tiles for Windows Mobility Center-->C:\Program Files\InstallShield Installation Information\{617C36FD-0CBE-4600-84B2-441CEB12FADF}\setup.exe -runfromtemp -l0x040c
      TOSHIBA Flash Cards Support Utility-->C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{620BBA5E-F848-4D56-8BDA-584E44584C5E}
      TOSHIBA Hardware Setup-->C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{5279374D-87FE-4879-9385-F17278EBB9D3} /l1036
      TOSHIBA Mot de passe responsable-->C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{51B4E156-14A5-4904-9AE4-B1AA2A0E46BE} /l1036
      Toshiba Online Product Information-->C:\Program Files\InstallShield Installation Information\{2290A680-4083-410A-ADCC-7092C67FC052}\setup.exe -runfromtemp -l0x040c -removeonly
      TOSHIBA SD Memory Utilities-->MsiExec.exe /X{EBFF48F5-3CFA-436F-8FD5-94FB01D3A0A7}
      TOSHIBA Software Modem-->Tosmreg -U
      TOSHIBA Value Added Package-->C:\Program Files\InstallShield Installation Information\{FEDD27A0-B306-45EF-BF58-B527406B42C8}\setup.exe -runfromtemp -l0x040c
      Update for 2007 Microsoft Office System (KB967642)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {C444285D-5E4F-48A4-91DD-47AAAA68E92D}
      Update for Microsoft .NET Framework 3.5 SP1 (KB963707)-->C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {B2AE9C82-DC7B-3641-BFC8-87275C4F3607} /qb+ REBOOTPROMPT=""
      Update for Microsoft Office InfoPath 2007 (KB976416)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {432C5EE4-8096-4FF1-95E1-65219365DFF7}
      Update for Microsoft Office Word 2007 (KB974561)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {0CDDBAA2-2111-4A0E-A1B0-76C40C635331}
      Update Service-->C:\Program Files\Sony Ericsson\Update Service\uninst.exe
      VC80CRTRedist - 8.0.50727.762-->MsiExec.exe /I{767CC44C-9BBC-438D-BAD3-FD4595DD148B}
      Windows Live Call-->MsiExec.exe /I{82C7B308-0BDD-49D8-8EA5-9CD3A3F9DF41}
      Windows Live Communications Platform-->MsiExec.exe /I{ED00D08A-3C5F-488D-93A0-A04F21F23956}
      Windows Live Contrôle parental-->MsiExec.exe /X{D5D81435-B8DE-4CAF-867F-7998F2B92CFC}
      Windows Live FolderShare-->MsiExec.exe /X{2075CB0A-D26F-4DAA-B424-5079296B43BA}
      Windows Live Mail-->MsiExec.exe /I{5DD76286-9BE7-4894-A990-E905E91AC818}
      Windows Live Messenger-->MsiExec.exe /X{770F1BEC-2871-4E70-B837-FB8525FFA3B1}
      Windows Live Movie Maker-->MsiExec.exe /X{53B20C18-D8D4-4588-8737-9BBFE303C354}
      Windows Live Toolbar-->MsiExec.exe /X{F7D27C70-90F5-49B9-B188-0A133C0CE353}
      Windows Live Writer-->MsiExec.exe /X{4634B21A-CC07-4396-890C-2B8168661FEA}
      WinZip 12.1-->MsiExec.exe /X{CD95F661-A5C4-44F5-A6AA-ECDD91C240B8}

      ======Security center information======

      AV: Antivirus BitDefender (disabled) (outdated)
      AV: avast! Antivirus
      AS: BitDefender AntiSpam (disabled)
      AS: Windows Defender
      AS: avast! Antivirus

      ======System event log======

      Computer Name: PC-de-ginie
      Event Code: 7000
      Message: Le service Parallel port driver n'a pas pu démarrer en raison de l'erreur :
      Le service ne peut pas être démarré parce qu'il est désactivé ou qu'aucun périphérique activé ne lui est associé.
      Record Number: 217344
      Source Name: Service Control Manager
      Time Written: 20100212160430.000000-000
      Event Type: Erreur
      User:

      Computer Name: PC-de-ginie
      Event Code: 7000
      Message: Le service TOSHIBA Bluetooth Service n'a pas pu démarrer en raison de l'erreur :
      Le fichier spécifié est introuvable.
      Record Number: 217369
      Source Name: Service Control Manager
      Time Written: 20100212160430.000000-000
      Event Type: Erreur
      User:

      Computer Name: PC-de-ginie
      Event Code: 6008
      Message: L'arrêt système précédant à 17:14:58 le 12/02/2010 n'était pas prévu.
      Record Number: 217405
      Source Name: EventLog
      Time Written: 20100212174423.000000-000
      Event Type: Erreur
      User:

      Computer Name: PC-de-ginie
      Event Code: 7000
      Message: Le service Parallel port driver n'a pas pu démarrer en raison de l'erreur :
      Le service ne peut pas être démarré parce qu'il est désactivé ou qu'aucun périphérique activé ne lui est associé.
      Record Number: 217453
      Source Name: Service Control Manager
      Time Written: 20100212174557.000000-000
      Event Type: Erreur
      User:

      Computer Name: PC-de-ginie
      Event Code: 7000
      Message: Le service TOSHIBA Bluetooth Service n'a pas pu démarrer en raison de l'erreur :
      Le fichier spécifié est introuvable.
      Record Number: 217477
      Source Name: Service Control Manager
      Time Written: 20100212174557.000000-000
      Event Type: Erreur
      User:

      =====Application event log=====

      Computer Name: PC-de-ginie
      Event Code: 5007
      Message: Impossible d’analyser le fichier cible de la plateforme de signalement de problèmes Windows (fichier DLL contenant la liste des problèmes de l’ordinateur et nécessitant la collecte de données supplémentaires à des fins de diagnostic). Le code d’erreur était : 8014FFF9.
      Record Number: 62274
      Source Name: WerSvc
      Time Written: 20100212100519.000000-000
      Event Type: Erreur
      User:

      Computer Name: PC-de-ginie
      Event Code: 513
      Message: Les services de chiffrement ont échoué lors du traitement de l’appel OnIdentity() dans l’objet System Writer.

      Details:
      AddCoreCsiFiles : BeginFileEnumeration() failed.

      System Error:
      Accès refusé.
      .
      Record Number: 62278
      Source Name: Microsoft-Windows-CAPI2
      Time Written: 20100212100647.000000-000
      Event Type: Erreur
      User:

      Computer Name: PC-de-ginie
      Event Code: 513
      Message: Les services de chiffrement ont échoué lors du traitement de l’appel OnIdentity() dans l’objet System Writer.

      Details:
      AddCoreCsiFiles : BeginFileEnumeration() failed.

      System Error:
      Accès refusé.
      .
      Record Number: 62279
      Source Name: Microsoft-Windows-CAPI2
      Time Written: 20100212100654.000000-000
      Event Type: Erreur
      User:

      Computer Name: PC-de-ginie
      Event Code: 5007
      Message: Impossible d’analyser le fichier cible de la plateforme de signalement de problèmes Windows (fichier DLL contenant la liste des problèmes de l’ordinateur et nécessitant la collecte de données supplémentaires à des fins de diagnostic). Le code d’erreur était : 8014FFF9.
      Record Number: 62319
      Source Name: WerSvc
      Time Written: 20100212160805.000000-000
      Event Type: Erreur
      User:

      Computer Name: PC-de-ginie
      Event Code: 5007
      Message: Impossible d’analyser le fichier cible de la plateforme de signalement de problèmes Windows (fichier DLL contenant la liste des problèmes de l’ordinateur et nécessitant la collecte de données supplémentaires à des fins de diagnostic). Le code d’erreur était : 8014FFF9.
      Record Number: 62351
      Source Name: WerSvc
      Time Written: 20100212174924.000000-000
      Event Type: Erreur
      User:

      =====Security event log=====

      Computer Name: PC-de-ginie
      Event Code: 4672
      Message: Privilèges spéciaux attribués à la nouvelle ouverture de session.

      Sujet :
      ID de sécurité : S-1-5-18
      Nom du compte : SYSTEM
      Domaine du compte : AUTORITE NT
      ID d’ouverture de session : 0x3e7

      Privilèges : SeAssignPrimaryTokenPrivilege
      SeTcbPrivilege
      SeSecurityPrivilege
      SeTakeOwnershipPrivilege
      SeLoadDriverPrivilege
      SeBackupPrivilege
      SeRestorePrivilege
      SeDebugPrivilege
      SeAuditPrivilege
      SeSystemEnvironmentPrivilege
      SeImpersonatePrivilege
      Record Number: 36758
      Source Name: Microsoft-Windows-Security-Auditing
      Time Written: 20090623172043.235967-000
      Event Type: Succès de l'audit
      User:

      Computer Name: PC-de-ginie
      Event Code: 4648
      Message: Tentative d’ouverture de session en utilisant des informations d’identification explicites.

      Sujet :
      ID de sécurité : S-1-5-18
      Nom du compte : PC-DE-GINIE$
      Domaine du compte : WORKGROUP
      ID d’ouverture de session : 0x3e7
      GUID d’ouverture de session : {00000000-0000-0000-0000-000000000000}

      Compte dont les informations d’identification ont été utilisées :
      Nom du compte : ginie
      Domaine du compte : PC-de-ginie
      GUID d’ouverture de session : {00000000-0000-0000-0000-000000000000}

      Serveur cible :
      Nom du serveur cible : localhost
      Informations supplémentaires : localhost

      Informations sur le processus :
      ID du processus : 0x320
      Nom du processus : C:\Windows\System32\winlogon.exe

      Informations sur le réseau :
      Adresse du réseau : 127.0.0.1
      Port : 0

      Cet événement est généré lorsqu’un processus tente d’ouvrir une session pour un compte en spécifiant explicitement les informations d’identification de ce compte. Ceci se produit le plus souvent dans les configurations par lot comme les tâches planifiées, ou avec l’utilisation de la commande RUNAS.
      Record Number: 36759
      Source Name: Microsoft-Windows-Security-Auditing
      Time Written: 20090623172330.374367-000
      Event Type: Succès de l'audit
      User:

      Computer Name: PC-de-ginie
      Event Code: 4624
      Message: L’ouverture de session d’un compte s’est correctement déroulée.

      Sujet :
      ID de sécurité : S-1-5-18
      Nom du compte : PC-DE-GINIE$
      Domaine du compte : WORKGROUP
      ID d’ouverture de session : 0x3e7

      Type d’ouverture de session : 2

      Nouvelle ouverture de session :
      ID de sécurité : S-1-5-21-3274394378-4107285941-262733215-1000
      Nom du compte : ginie
      Domaine du compte : PC-de-ginie
      ID d’ouverture de session : 0x67781
      GUID d’ouverture de session : {00000000-0000-0000-0000-000000000000}

      Informations sur le processus :
      ID du processus : 0x320
      Nom du processus : C:\Windows\System32\winlogon.exe

      Informations sur le réseau :
      Nom de la station de travail : PC-DE-GINIE
      Adresse du réseau source : 127.0.0.1
      Port source : 0

      Informations détaillées sur l’authentification :
      Processus d’ouverture de session : User32
      Package d’authentification : Negotiate
      Services en transit : -
      Nom du package (NTLM uniquement) : -
      Longueur de la clé : 0

      Cet événement est généré lors de la création d’une ouverture de session. Il est généré sur l’ordinateur sur lequel l’ouverture de session a été effectuée.

      Le champ Objet indique le compte sur le système local qui a demandé l’ouverture de session. Il s’agit le plus souvent d’un service, comme le service Serveur, ou un processus local tel que Winlogon.exe ou Services.exe.

      Le champ Type d’ouverture de session indique le type d’ouverture de session qui s’est produit. Les types les plus courants sont 2 (interactif) et 3 (réseau).

      Le champ Nouvelle ouverture de session indique le compte pour lequel la nouvelle ouverture de session a été créée, par exemple, le compte qui s’est connecté.

      Les champs relatifs au réseau indiquent la provenance d’une demande d’ouverture de session à distance. Le nom de la station de travail n’étant pas toujours disponible, peut être laissé vide dans certains cas.

      Les champs relatifs aux informations d’authentification fournissent des détails sur cette demande d’ouverture de session spécifique.
      - Le GUID d’ouverture de session est un identificateur unique pouvant servir à associer cet événement à un événement KDC .
      - Les services en transit indiquent les services intermédiaires qui ont participé à cette demande d’ouverture de session.
      - Nom du package indique quel est le sous-protocole qui a été utilisé parmi les protocoles NTLM.
      - La longueur de la clé indique la longueur de la clé de session générée. Elle a la valeur 0 si aucune clé de session n’a été demandée.
      Record Number: 36760
      Source Name: Microsoft-Windows-Security-Auditing
      Time Written: 20090623172330.374367-000
      Event Type: Succès de l'audit
      User:

      Computer Name: PC-de-ginie
      Event Code: 4624
      Message: L’ouverture de session d’un compte s’est correctement déroulée.

      Sujet :
      ID de sécurité : S-1-5-18
      Nom du compte : PC-DE-GINIE$
      Domaine du compte : WORKGROUP
      ID d’ouverture de session : 0x3e7

      Type d’ouverture de session : 2

      Nouvelle ouverture de session :
      ID de sécurité : S-1-5-21-3274394378-4107285941-262733215-1000
      Nom du compte : ginie
      Domaine du compte : PC-de-ginie
      ID d’ouverture de session : 0x677d3
      GUID d’ouverture de session : {00000000-0000-0000-0000-000000000000}

      Informations sur le processus :
      ID du processus : 0x320
      Nom du processus : C:\Windows\System32\winlogon.exe

      Informations sur le réseau :
      Nom de la station de travail : PC-DE-GINIE
      Adresse du réseau source : 127.0.0.1
      Port source : 0

      Informations détaillées sur l’authentification :
      Processus d’ouverture de session : User32
      Package d’authentification : Negotiate
      Services en transit : -
      Nom du package (NTLM uniquement) : -
      Longueur de la clé : 0

      Cet événement est généré lors de la création d’une ouverture de session. Il est généré sur l’ordinateur sur lequel l’ouverture de session a été effectuée.

      Le champ Objet indique le compte sur le système local qui a demandé l’ouverture de session. Il s’agit le plus souvent d’un service, comme le service Serveur, ou un processus local tel que Winlogon.exe ou Services.exe.

      Le champ Type d’ouverture de session indique le type d’ouverture de session qui s’est produit. Les types les plus courants sont 2 (interactif) et 3 (réseau).

      Le champ Nouvelle ouverture de session indique le compte pour lequel la nouvelle ouverture de session a été créée, par exemple, le compte qui s’est connecté.

      Les champs relatifs au réseau indiquent la provenance d’une demande d’ouverture de session à distance. Le nom de la station de travail n’étant pas toujours disponible, peut être laissé vide dans certains cas.

      Les champs relatifs aux informations d’authentification fournissent des détails sur cette demande d’ouverture de session spécifique.
      - Le GUID d’ouverture de session est un identificateur unique pouvant servir à associer cet événement à un événement KDC .
      - Les services en transit indiquent les services intermédiaires qui ont participé à cette demande d’ouverture de session.
      - Nom du package indique quel est le sous-protocole qui a été utilisé parmi les protocoles NTLM.
      - La longueur de la clé indique la longueur de la clé de session générée. Elle a la valeur 0 si aucune clé de session n’a été demandée.
      Record Number: 36761
      Source Name: Microsoft-Windows-Security-Auditing
      Time Written: 20090623172330.374367-000
      Event Type: Succès de l'audit
      User:

      Computer Name: PC-de-ginie
      Event Code: 4672
      Message: Privilèges spéciaux attribués à la nouvelle ouverture de session.

      Sujet :
      ID de sécurité : S-1-5-21-3274394378-4107285941-262733215-1000
      Nom du compte : ginie
      Domaine du compte : PC-de-ginie
      ID d’ouverture de session : 0x67781

      Privilèges : SeSecurityPrivilege
      SeBackupPrivilege
      SeRestorePrivilege
      SeTakeOwnershipPrivilege
      SeDebugPrivilege
      SeSystemEnvironmentPrivilege
      SeLoadDriverPrivilege
      SeImpersonatePrivilege
      Record Number: 36762
      Source Name: Microsoft-Windows-Security-Auditing
      Time Written: 20090623172330.374367-000
      Event Type: Succès de l'audit
      User:

      ======Environment variables======

      "ComSpec"=%SystemRoot%\system32\cmd.exe
      "FP_NO_HOST_CHECK"=NO
      "OS"=Windows_NT
      "Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;C:\PROGRA~1\COMMON~1\ULEADS~1\MPEG;C:\Program Files\QuickTime\QTSystem\
      "PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC
      "PROCESSOR_ARCHITECTURE"=x86
      "TEMP"=%SystemRoot%\TEMP
      "TMP"=%SystemRoot%\TEMP
      "USERNAME"=SYSTEM
      "windir"=%SystemRoot%
      "PROCESSOR_LEVEL"=6
      "PROCESSOR_IDENTIFIER"=x86 Family 6 Model 15 Stepping 13, GenuineIntel
      "PROCESSOR_REVISION"=0f0d
      "NUMBER_OF_PROCESSORS"=2
      "CLASSPATH"=.;C:\Program Files\Java\jre1.6.0\lib\ext\QTJava.zip
      "QTJAVA"=C:\Program Files\Java\jre1.6.0\lib\ext\QTJava.zip

      -----------------EOF-----------------

      2ème rapport :

      Logfile of random's system information tool 1.06 (written by random/random)
      Run by ginie at 2010-02-12 19:08:07
      Microsoft® Windows Vista™ Édition Familiale Premium
      System drive C: has 4 GB (6%) free of 76 GB
      Total RAM: 2038 MB (49% free)

      Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 19:08:33, on 12/02/2010
      Platform: Windows Vista (WinNT 6.00.1904)
      MSIE: Internet Explorer v7.00 (7.00.6000.16982)
      Boot mode: Normal

      Running processes:
      C:\Windows\system32\taskeng.exe
      C:\Windows\system32\Dwm.exe
      C:\Windows\Explorer.EXE
      C:\Program Files\Windows Defender\MSASCui.exe
      C:\Program Files\TOSHIBA\Utilities\KeNotify.exe
      C:\Windows\RtHDVCpl.exe
      C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe
      C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe
      C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe
      C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe
      C:\Program Files\IDM\Desktop SMS\DesktopSMS.exe
      C:\Program Files\TOSHIBA\Toshiba Online Product Information\TOPI.exe
      C:\Windows\System32\igfxtray.exe
      C:\Windows\System32\hkcmd.exe
      C:\Windows\System32\igfxpers.exe
      C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe
      C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
      C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
      C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe
      C:\Program Files\Java\jre6\bin\jusched.exe
      C:\Program Files\ScanSoft\OmniPageSE4\OpWareSE4.exe
      C:\Program Files\Alwil Software\Avast5\AvastUI.exe
      C:\Program Files\Windows Sidebar\sidebar.exe
      C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe
      C:\Windows\ehome\ehtray.exe
      C:\Program Files\Windows Live\Messenger\msnmsgr.exe
      C:\Program Files\BlazeVideo\BlazeDTV 2.5a\MediaDetector.exe
      C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
      C:\Program Files\Windows Media Player\wmpnscfg.exe
      C:\Program Files\WinZip\WZQKPICK.EXE
      C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
      C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
      C:\Windows\system32\igfxsrvc.exe
      C:\Windows\ehome\ehmsas.exe
      C:\Program Files\Camera Assistant Software for Toshiba\CEC_MAIN.exe
      C:\Program Files\Synaptics\SynTP\SynToshiba.exe
      C:\PROGRA~1\COMMON~1\France Telecom\Shared Modules\AlertModule\0\AlertModule.exe
      C:\Program Files\OrangeHSS\systray\systrayapp.exe
      C:\Program Files\Windows Mail\WinMail.exe
      C:\Program Files\TOSHIBA\ConfigFree\CFSwMgr.exe
      C:\Program Files\Windows Live\Contacts\wlcomm.exe
      C:\Program Files\Internet Explorer\iexplore.exe
      C:\Program Files\Windows Live\Toolbar\wltuser.exe
      C:\Windows\system32\wuauclt.exe
      C:\Users\ginie\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\IYUDHB5W\RSIT[1].exe
      C:\Windows\system32\SearchFilterHost.exe
      C:\Program Files\trend micro\ginie.exe

      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.google.fr/?gws_rd=ssl
      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.google.fr/?gws_rd=ssl
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
      R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\Program Files\OrangeHSS\SearchURLHook\SearchPageURL.dll
      O1 - Hosts: ::1 localhost
      O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
      O2 - BHO: &IE Help - {35A5B43B-CB8A-49CA-A9F4-D3B308D2E3CC} - C:\Windows\System32\iehelpmod.dll (file missing)
      O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
      O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
      O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
      O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
      O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.5.4723.1820\swg.dll
      O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
      O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
      O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
      O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
      O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
      O4 - HKLM\..\Run: [KeNotify] C:\Program Files\TOSHIBA\Utilities\KeNotify.exe
      O4 - HKLM\..\Run: [SVPWUTIL] C:\Program Files\TOSHIBA\Utilities\SVPWUTIL.exe SVPwUTIL
      O4 - HKLM\..\Run: [HWSetup] \HWSetup.exe hwSetUP
      O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
      O4 - HKLM\..\Run: [TPwrMain] %ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE
      O4 - HKLM\..\Run: [HSON] %ProgramFiles%\TOSHIBA\TBS\HSON.exe
      O4 - HKLM\..\Run: [SmoothView] %ProgramFiles%\Toshiba\SmoothView\SmoothView.exe
      O4 - HKLM\..\Run: [00TCrdMain] %ProgramFiles%\TOSHIBA\FlashCards\TCrdMain.exe
      O4 - HKLM\..\Run: [NDSTray.exe] NDSTray.exe
      O4 - HKLM\..\Run: [Desktop SMS] C:\Program Files\IDM\Desktop SMS\DesktopSMS.exe /auto
      O4 - HKLM\..\Run: [topi] C:\Program Files\TOSHIBA\Toshiba Online Product Information\topi.exe -startup
      O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
      O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
      O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
      O4 - HKLM\..\Run: [Camera Assistant Software] "C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe"
      O4 - HKLM\..\Run: [SynTPStart] C:\Program Files\Synaptics\SynTP\SynTPStart.exe
      O4 - HKLM\..\Run: [Toshiba Registration] C:\Program Files\Toshiba\Registration\ToshibaRegistration.exe
      O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
      O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
      O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
      O4 - HKLM\..\Run: [ORAHSSSessionManager] C:\Program Files\OrangeHSS\SessionManager\SessionManager.exe
      O4 - HKLM\..\Run: [Easy-PrintToolBox] C:\Program Files\Canon\Easy-PrintToolBox\BJPSMAIN.EXE /logon
      O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe"
      O4 - HKLM\..\Run: [sysldtray] C:\Windows\ld15.exe
      O4 - HKLM\..\Run: [sysfbtray] C:\Windows\freddy70.exe
      O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
      O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
      O4 - HKLM\..\Run: [OpwareSE4] "C:\Program Files\ScanSoft\OmniPageSE4\OpwareSE4.exe"
      O4 - HKLM\..\Run: [avast5] C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe /nogui
      O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
      O4 - HKCU\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
      O4 - HKCU\..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe
      O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
      O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
      O4 - HKCU\..\Run: [BlazeServoTool] "C:\Program Files\BlazeVideo\BlazeDTV 2.5a\MediaDetector.exe"
      O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
      O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
      O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
      O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
      O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
      O4 - Startup: OneNote 2007 - Capture d'écran et lancement.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
      O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
      O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
      O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
      O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
      O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
      O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
      O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
      O9 - Extra button: eBay - Achetez, Vendez - {76577871-04EC-495E-A12B-91F7C3600AFA} - https://www.ebay.fr (file missing)
      O9 - Extra button: Amazon.fr - {8A918C1D-E123-4E36-B562-5C1519E434CE} - https://www.amazon.fr/exec/obidos/subst/home/home.html/262-6263521-6325360?_encoding=UTF8&link_code=hom&tag=Toshibafrbholink-21 (file missing)
      O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
      O9 - Extra button: eBay - {C08CAF1D-C0A3-40D5-9970-06D067EAC017} - http://www.webtip.ch/cgi-bin/toshiba/tracker_url.pl?FR (file missing)
      O13 - Gopher Prefix:
      O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
      O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w2/resources/VistaMSNPUpldfr-fr.cab
      O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab
      O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://javadl-esd.sun.com/update/1.6.0/jinstall-6-windows-i586.cab
      O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
      O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe
      O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
      O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
      O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
      O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
      O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom SA - C:\PROGRA~1\COMMON~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
      O23 - Service: Service Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
      O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
      O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
      O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
      O23 - Service: PIXMA Extended Survey Program (IJPLMSVC) - Unknown owner - C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE
      O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
      O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
      O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
      O23 - Service: Planificateur LiveUpdate automatique - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
      O23 - Service: TOSHIBA Optical Disc Drive Service (TODDSrv) - TOSHIBA Corporation - C:\Windows\system32\TODDSrv.exe
      O23 - Service: TOSHIBA Power Saver (TosCoSrv) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe
      O23 - Service: TOSHIBA Bluetooth Service - Unknown owner - c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe (file missing)
      O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
      0
      1. J'avais pas vu je poste le deuxième rapport (puisqu'il n'est pas affiché en entier...) :
        2ème rapport :
        2ème rapport :

        Logfile of random's system information tool 1.06 (written by random/random)
        Run by ginie at 2010-02-12 19:08:07
        Microsoft® Windows Vista™ Édition Familiale Premium
        System drive C: has 4 GB (6%) free of 76 GB
        Total RAM: 2038 MB (49% free)

        Logfile of Trend Micro HijackThis v2.0.2
        Scan saved at 19:08:33, on 12/02/2010
        Platform: Windows Vista (WinNT 6.00.1904)
        MSIE: Internet Explorer v7.00 (7.00.6000.16982)
        Boot mode: Normal

        Running processes:
        C:\Windows\system32\taskeng.exe
        C:\Windows\system32\Dwm.exe
        C:\Windows\Explorer.EXE
        C:\Program Files\Windows Defender\MSASCui.exe
        C:\Program Files\TOSHIBA\Utilities\KeNotify.exe
        C:\Windows\RtHDVCpl.exe
        C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe
        C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe
        C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe
        C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe
        C:\Program Files\IDM\Desktop SMS\DesktopSMS.exe
        C:\Program Files\TOSHIBA\Toshiba Online Product Information\TOPI.exe
        C:\Windows\System32\igfxtray.exe
        C:\Windows\System32\hkcmd.exe
        C:\Windows\System32\igfxpers.exe
        C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe
        C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
        C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
        C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe
        C:\Program Files\Java\jre6\bin\jusched.exe
        C:\Program Files\ScanSoft\OmniPageSE4\OpWareSE4.exe
        C:\Program Files\Alwil Software\Avast5\AvastUI.exe
        C:\Program Files\Windows Sidebar\sidebar.exe
        C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe
        C:\Windows\ehome\ehtray.exe
        C:\Program Files\Windows Live\Messenger\msnmsgr.exe
        C:\Program Files\BlazeVideo\BlazeDTV 2.5a\MediaDetector.exe
        C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
        C:\Program Files\Windows Media Player\wmpnscfg.exe
        C:\Program Files\WinZip\WZQKPICK.EXE
        C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
        C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
        C:\Windows\system32\igfxsrvc.exe
        C:\Windows\ehome\ehmsas.exe
        C:\Program Files\Camera Assistant Software for Toshiba\CEC_MAIN.exe
        C:\Program Files\Synaptics\SynTP\SynToshiba.exe
        C:\PROGRA~1\COMMON~1\France Telecom\Shared Modules\AlertModule\0\AlertModule.exe
        C:\Program Files\OrangeHSS\systray\systrayapp.exe
        C:\Program Files\Windows Mail\WinMail.exe
        C:\Program Files\TOSHIBA\ConfigFree\CFSwMgr.exe
        C:\Program Files\Windows Live\Contacts\wlcomm.exe
        C:\Program Files\Internet Explorer\iexplore.exe
        C:\Program Files\Windows Live\Toolbar\wltuser.exe
        C:\Windows\system32\wuauclt.exe
        C:\Users\ginie\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\IYUDHB5W\RSIT[1].exe
        C:\Windows\system32\SearchFilterHost.exe
        C:\Program Files\trend micro\ginie.exe

        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.google.fr/?gws_rd=ssl
        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.google.fr/?gws_rd=ssl
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
        R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
        R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
        R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
        R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\Program Files\OrangeHSS\SearchURLHook\SearchPageURL.dll
        O1 - Hosts: ::1 localhost
        O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
        O2 - BHO: &IE Help - {35A5B43B-CB8A-49CA-A9F4-D3B308D2E3CC} - C:\Windows\System32\iehelpmod.dll (file missing)
        O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
        O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
        O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
        O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
        O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.5.4723.1820\swg.dll
        O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
        O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
        O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
        O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
        O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
        O4 - HKLM\..\Run: [KeNotify] C:\Program Files\TOSHIBA\Utilities\KeNotify.exe
        O4 - HKLM\..\Run: [SVPWUTIL] C:\Program Files\TOSHIBA\Utilities\SVPWUTIL.exe SVPwUTIL
        O4 - HKLM\..\Run: [HWSetup] \HWSetup.exe hwSetUP
        O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
        O4 - HKLM\..\Run: [TPwrMain] %ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE
        O4 - HKLM\..\Run: [HSON] %ProgramFiles%\TOSHIBA\TBS\HSON.exe
        O4 - HKLM\..\Run: [SmoothView] %ProgramFiles%\Toshiba\SmoothView\SmoothView.exe
        O4 - HKLM\..\Run: [00TCrdMain] %ProgramFiles%\TOSHIBA\FlashCards\TCrdMain.exe
        O4 - HKLM\..\Run: [NDSTray.exe] NDSTray.exe
        O4 - HKLM\..\Run: [Desktop SMS] C:\Program Files\IDM\Desktop SMS\DesktopSMS.exe /auto
        O4 - HKLM\..\Run: [topi] C:\Program Files\TOSHIBA\Toshiba Online Product Information\topi.exe -startup
        O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
        O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
        O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
        O4 - HKLM\..\Run: [Camera Assistant Software] "C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe"
        O4 - HKLM\..\Run: [SynTPStart] C:\Program Files\Synaptics\SynTP\SynTPStart.exe
        O4 - HKLM\..\Run: [Toshiba Registration] C:\Program Files\Toshiba\Registration\ToshibaRegistration.exe
        O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
        O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
        O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
        O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
        O4 - HKLM\..\Run: [ORAHSSSessionManager] C:\Program Files\OrangeHSS\SessionManager\SessionManager.exe
        O4 - HKLM\..\Run: [Easy-PrintToolBox] C:\Program Files\Canon\Easy-PrintToolBox\BJPSMAIN.EXE /logon
        O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe"
        O4 - HKLM\..\Run: [sysldtray] C:\Windows\ld15.exe
        O4 - HKLM\..\Run: [sysfbtray] C:\Windows\freddy70.exe
        O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
        O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
        O4 - HKLM\..\Run: [OpwareSE4] "C:\Program Files\ScanSoft\OmniPageSE4\OpwareSE4.exe"
        O4 - HKLM\..\Run: [avast5] C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe /nogui
        O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
        O4 - HKCU\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
        O4 - HKCU\..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe
        O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
        O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
        O4 - HKCU\..\Run: [BlazeServoTool] "C:\Program Files\BlazeVideo\BlazeDTV 2.5a\MediaDetector.exe"
        O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
        O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
        O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
        O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
        O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
        O4 - Startup: OneNote 2007 - Capture d'écran et lancement.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
        O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
        O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
        O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
        O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
        O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
        O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
        O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
        O9 - Extra button: eBay - Achetez, Vendez - {76577871-04EC-495E-A12B-91F7C3600AFA} - https://www.ebay.fr (file missing)
        O9 - Extra button: Amazon.fr - {8A918C1D-E123-4E36-B562-5C1519E434CE} - https://www.amazon.fr/exec/obidos/subst/home/home.html/262-6263521-6325360?_encoding=UTF8&link_code=hom&tag=Toshibafrbholink-21 (file missing)
        O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
        O9 - Extra button: eBay - {C08CAF1D-C0A3-40D5-9970-06D067EAC017} - http://www.webtip.ch/cgi-bin/toshiba/tracker_url.pl?FR (file missing)
        O13 - Gopher Prefix:
        O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
        O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w2/resources/VistaMSNPUpldfr-fr.cab
        O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab
        O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://javadl-esd.sun.com/update/1.6.0/jinstall-6-windows-i586.cab
        O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
        O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe
        O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
        O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
        O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
        O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
        O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom SA - C:\PROGRA~1\COMMON~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
        O23 - Service: Service Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
        O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
        O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
        O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
        O23 - Service: PIXMA Extended Survey Program (IJPLMSVC) - Unknown owner - C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE
        O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
        O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
        O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
        O23 - Service: Planificateur LiveUpdate automatique - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
        O23 - Service: TOSHIBA Optical Disc Drive Service (TODDSrv) - TOSHIBA Corporation - C:\Windows\system32\TODDSrv.exe
        O23 - Service: TOSHIBA Power Saver (TosCoSrv) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe
        O23 - Service: TOSHIBA Bluetooth Service - Unknown owner - c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe (file missing)
        O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe

        End of file - 13816 bytes

        ======Scheduled tasks folder======

        C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
        C:\Windows\tasks\GoogleUpdateTaskMachineUA.job

        ======Registry dump======

        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
        Aide pour le lien d'Adobe PDF Reader - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2006-10-22 62080]

        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{35A5B43B-CB8A-49CA-A9F4-D3B308D2E3CC}]
        &IE Help - C:\Windows\System32\iehelpmod.dll []

        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}]

        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6EBF7485-159F-4bff-A14F-B9E3AAC4465B}]
        Search Helper - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll [2009-05-19 137600]

        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
        Programme d'aide de l'Assistant de connexion Windows Live - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-02-17 408440]

        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
        Google Toolbar Helper - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2010-02-03 279664]

        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
        Google Toolbar Notifier BHO - C:\Program Files\Google\GoogleToolbarNotifier\5.5.4723.1820\swg.dll [2010-02-03 812528]

        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
        Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2009-11-10 35840]

        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E15A8DC0-8516-42A1-81EA-DC94EC1ACF10}]
        Windows Live Toolbar Helper - C:\Program Files\Windows Live\Toolbar\wltcore.dll [2009-02-06 1068904]

        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
        {21FA44EF-376D-4D53-9B0F-8A89D3229068} - &Windows Live Toolbar - C:\Program Files\Windows Live\Toolbar\wltcore.dll [2009-02-06 1068904]
        {2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2010-02-03 279664]

        [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
        "Windows Defender"=C:\Program Files\Windows Defender\MSASCui.exe [2007-07-10 1006264]
        "KeNotify"=C:\Program Files\TOSHIBA\Utilities\KeNotify.exe [2006-11-06 34352]
        "SVPWUTIL"=C:\Program Files\TOSHIBA\Utilities\SVPWUTIL.exe [2006-03-22 438272]
        "HWSetup"=\HWSetup.exe hwSetUP []
        "RtHDVCpl"=C:\Windows\RtHDVCpl.exe [2007-09-03 4702208]
        "TPwrMain"=C:\Program Files\TOSHIBA\Power Saver\TPwrMain.EXE [2007-03-29 411192]
        "HSON"=C:\Program Files\TOSHIBA\TBS\HSON.exe [2006-12-07 55416]
        "SmoothView"=C:\Program Files\Toshiba\SmoothView\SmoothView.exe [2007-04-03 509496]
        "00TCrdMain"=C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe [2007-05-22 538744]
        "NDSTray.exe"=NDSTray.exe []
        "Desktop SMS"=C:\Program Files\IDM\Desktop SMS\DesktopSMS.exe [2007-06-18 1507328]
        "topi"=C:\Program Files\TOSHIBA\Toshiba Online Product Information\topi.exe [2007-07-10 581632]
        "IgfxTray"=C:\Windows\system32\igfxtray.exe [2007-09-20 141848]
        "HotKeysCmds"=C:\Windows\system32\hkcmd.exe [2007-09-20 154136]
        "Persistence"=C:\Windows\system32\igfxpers.exe [2007-09-20 129560]
        "Camera Assistant Software"=C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe [2007-04-10 413696]
        "SynTPStart"=C:\Program Files\Synaptics\SynTP\SynTPStart.exe [2007-07-27 204800]
        "Toshiba Registration"=C:\Program Files\Toshiba\Registration\ToshibaRegistration.exe [2007-02-19 571024]
        "IAAnotif"=C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe [2007-02-12 174872]
        "Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe [2008-01-11 39792]
        "Symantec PIF AlertEng"=C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe [2008-01-29 583048]
        "QuickTime Task"=C:\Program Files\QuickTime\QTTask.exe [2008-09-06 413696]
        "ORAHSSSessionManager"=C:\Program Files\OrangeHSS\SessionManager\SessionManager.exe [2007-12-12 107248]
        "Easy-PrintToolBox"=C:\Program Files\Canon\Easy-PrintToolBox\BJPSMAIN.EXE [2006-10-17 398944]
        "Adobe Photo Downloader"=C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe [2007-03-16 63712]
        "sysldtray"=C:\Windows\ld15.exe []
        "sysfbtray"=C:\Windows\freddy70.exe []
        "SunJavaUpdateSched"=C:\Program Files\Java\jre6\bin\jusched.exe [2009-11-10 148888]
        "SSBkgdUpdate"=C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe [2006-10-25 210472]
        "OpwareSE4"=C:\Program Files\ScanSoft\OmniPageSE4\OpwareSE4.exe [2007-02-04 79400]
        "avast5"=C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe [2010-01-28 2757512]

        [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
        "Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2008-03-11 1232896]
        "WindowsWelcomeCenter"=oobefldr.dll,ShowWelcomeCenter []
        "TOSCDSPD"=C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe [2006-11-13 413696]
        "ehTray.exe"=C:\Windows\ehome\ehTray.exe [2006-11-02 125440]
        "MsnMsgr"=C:\Program Files\Windows Live\Messenger\msnmsgr.exe [2009-07-26 3883856]
        "BlazeServoTool"=C:\Program Files\BlazeVideo\BlazeDTV 2.5a\MediaDetector.exe [2007-03-07 270336]
        "swg"=C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2009-06-23 39408]
        "WMPNSCFG"=C:\Program Files\Windows Media Player\WMPNSCFG.exe [2006-11-02 201728]

        C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
        WinZip Quick Pick.lnk - C:\Program Files\WinZip\WZQKPICK.EXE

        C:\Users\ginie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
        OneNote 2007 - Capture d'écran et lancement.lnk - C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE

        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
        C:\Windows\system32\igfxdev.dll [2007-09-13 204800]

        [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
        "DisableTaskMgr"=0

        [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
        "ConsentPromptBehaviorAdmin"=0
        "EnableLUA"=0
        "dontdisplaylastusername"=0
        "legalnoticecaption"=
        "legalnoticetext"=
        "shutdownwithoutlogon"=1
        "undockwithoutlogon"=1

        [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
        "C:\Program Files\OrangeHSS\Connectivity\ConnectivityManager.exe"="C:\Program Files\OrangeHSS\Connectivity\ConnectivityManager.exe:*:enabled:CSS"

        [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

        [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{15531ff1-8d49-11dd-9038-001b38accff9}]
        shell\AutoRun\command - WDSetup.exe

        [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{41efb5a8-1778-11dd-9886-001b38accff9}]
        shell\Auto\command - RavMonE.exe e
        shell\AutoRun\command - C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL RavMonE.exe e

        [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{9517bc08-243b-11de-8c99-001b38accff9}]
        shell\AutoRun\command - D:\1ogf.exe
        shell\open\command - D:\1ogf.exe

        ======List of files/folders created in the last 1 months======

        2010-02-12 19:08:08 ----D---- C:\Program Files\trend micro
        2010-02-12 19:08:07 ----D---- C:\rsit
        2010-02-10 10:20:38 ----A---- C:\Windows\system32\ntoskrnl.exe
        2010-02-10 10:20:36 ----A---- C:\Windows\system32\ntkrnlpa.exe
        2010-02-10 10:20:27 ----A---- C:\Windows\system32\tcpipcfg.dll
        2010-02-10 10:20:27 ----A---- C:\Windows\system32\netiougc.exe
        2010-02-10 10:20:17 ----A---- C:\Windows\system32\tsbyuv.dll
        2010-02-10 10:20:17 ----A---- C:\Windows\system32\quartz.dll
        2010-02-10 10:20:17 ----A---- C:\Windows\system32\msyuv.dll
        2010-02-10 10:20:17 ----A---- C:\Windows\system32\msvidc32.dll
        2010-02-10 10:20:17 ----A---- C:\Windows\system32\msrle32.dll
        2010-02-10 10:20:17 ----A---- C:\Windows\system32\mciavi32.dll
        2010-02-10 10:20:17 ----A---- C:\Windows\system32\iyuv_32.dll
        2010-02-10 10:20:17 ----A---- C:\Windows\system32\avifil32.dll
        2010-02-10 10:20:16 ----A---- C:\Windows\system32\msvfw32.dll
        2010-02-10 10:20:16 ----A---- C:\Windows\system32\avicap32.dll
        2010-02-07 21:36:15 ----A---- C:\Windows\system32\aswBoot.exe
        2010-02-07 21:35:57 ----D---- C:\ProgramData\Alwil Software
        2010-01-29 12:57:45 ----A---- C:\Windows\avisplitter.INI
        2010-01-22 12:24:48 ----A---- C:\Windows\system32\mshtml.dll
        2010-01-22 12:24:44 ----A---- C:\Windows\system32\wininet.dll
        2010-01-22 12:24:42 ----A---- C:\Windows\system32\urlmon.dll
        2010-01-22 12:24:39 ----A---- C:\Windows\system32\ieframe.dll
        2010-01-22 12:24:37 ----A---- C:\Windows\system32\mstime.dll
        2010-01-22 12:24:36 ----A---- C:\Windows\system32\ieapfltr.dll
        2010-01-22 12:24:35 ----A---- C:\Windows\system32\iedkcs32.dll
        2010-01-22 12:24:34 ----A---- C:\Windows\system32\iertutil.dll
        2010-01-22 12:24:34 ----A---- C:\Windows\system32\dxtmsft.dll
        2010-01-22 12:24:33 ----A---- C:\Windows\system32\occache.dll
        2010-01-22 12:24:33 ----A---- C:\Windows\system32\msfeeds.dll
        2010-01-22 12:24:32 ----A---- C:\Windows\system32\mshtmled.dll
        2010-01-22 12:24:32 ----A---- C:\Windows\system32\ieaksie.dll
        2010-01-22 12:24:31 ----A---- C:\Windows\system32\ieencode.dll
        2010-01-22 12:24:31 ----A---- C:\Windows\system32\icardie.dll
        2010-01-22 12:24:31 ----A---- C:\Windows\system32\dxtrans.dll
        2010-01-22 12:24:30 ----A---- C:\Windows\system32\jsproxy.dll
        2010-01-22 12:24:29 ----A---- C:\Windows\system32\advpack.dll
        2010-01-22 12:24:29 ----A---- C:\Windows\system32\admparse.dll
        2010-01-22 12:24:28 ----A---- C:\Windows\system32\ieui.dll
        2010-01-22 12:24:28 ----A---- C:\Windows\system32\iesetup.dll
        2010-01-22 12:24:28 ----A---- C:\Windows\system32\iernonce.dll
        2010-01-22 12:24:27 ----A---- C:\Windows\system32\pngfilt.dll
        2010-01-22 12:24:27 ----A---- C:\Windows\system32\ieUnatt.exe
        2010-01-22 12:24:27 ----A---- C:\Windows\system32\ie4uinit.exe
        2010-01-22 12:24:25 ----A---- C:\Windows\system32\ieakui.dll
        2010-01-22 12:24:24 ----A---- C:\Windows\system32\mshtmler.dll
        2010-01-18 22:51:47 ----D---- C:\Users\ginie\AppData\Roaming\WinRAR
        2010-01-18 22:51:30 ----D---- C:\Program Files\WinRAR
        2010-01-17 00:47:41 ----D---- C:\Users\ginie\AppData\Roaming\igraal
        2010-01-17 00:47:36 ----D---- C:\Users\ginie\AppData\Roaming\Mozilla
        0
        1. Contributeur sécurité
          bonjour, même ton deuxième rapport n'est pas complet !! mais pas trop grave tu en posterasun tout neuf après pour contrôle !!

          la tu peux faire se qui suit avec usbfix et malwarebytes , merci

          1) passes usbfix option 2

          • Note : "Process.exe", une composante de l'outil, est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool.
          Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.
          Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall...) d'où l'alerte émise par ces antivirus.

          • Telecharges et installes: http://pagesperso-orange.fr/NosTools/Chiquitine29/UsbFix.exe

          (!) Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) suceptible d avoir été infectés sans les ouvrir

          • Fais un clic droit sur le raccourci UsbFix présent sur ton bureau et choisis "éxécuter en tant qu'administrateur" .

          • choisi l'option 2 ( Suppression )

          • Ton bureau disparaitra et le pc redémarrera .

          • Au redémarrage , UsbFix scannera ton pc , laisse travailler l outil.

          • Ensuite post le rapport UsbFix.txt qui apparaitra avec le bureau .

          • Note : Le rapport UsbFix.txt est sauvegardé a la racine du disque.( C:\UsbFix.txt )

          ( CTRL+A Pour tout selectionner , CTRL+C pour copier et CTRL+V pour coller )

          Pendant son nettoyage, l'outil a récolté certains fichiers infectieux.
          Nous vous demandons de nous les faire parvenir pour des futures mises à jour, ainsi que pour un meilleur traitement des infections.
          Nous vous remercions pour votre contribution.


          .UsbFix te proposera d'uploader un dossier compressé à cette adresse : https://www.ionos.fr/?affiliate_id=77097

          Ce dossier a été créé par UsbFix et est enregistré sur ton bureau.

          Merci de l'envoyer à l'adresse indiquée afin d'aider l'auteur de UsbFix dans ses recherches.

          Merci d'avance pour ta contribution !!

          2) fais un examem complet de ton pc avec malwarebytes

          Télécharge Malwarebytes' Anti-Malware: https://www.malekal.com/tutoriel-malwarebyte-anti-malware/

          . sur la page cliques sur Télécharger Malwarebyte's Anti-Malware
          . enregistres le sur le bureau
          . Double cliques sur le fichier téléchargé pour lancer le processus d'installation.
          . si le pare-feu demande l'autorisation de se connecter pour malwarebytes, acceptes
          . rend-toi dans l'onglet, Recherche
          . Sélectionnes Exécuter un examen complet
          . Cliques sur Rechercher
          . Le scan démarre.
          . A la fin de l'analyse, un message s'affiche : L'examen s'est terminé normalement. Cliquez sur 'Afficher les résultats' pour afficher tous les objets trouvés.
          . Cliques sur Ok pour poursuivre.
          . Si des malwares ont été détectés, cliques sur Afficher les résultats
          . Sélectionnes tout (ou laisses cochés) et cliques sur Supprimer la sélection Malwarebytes va détruire les fichiers et clés de registre et en mettre une copie dans la quarantaine.
          . Malwarebytes va ouvrir le bloc-notes et y copier le rapport d'analyse.
          . redemarre le pc si il le fait pas lui même
          . une fois redémarré double-cliques sur malwarebytes
          . rends toi dans l'onglet rapport/log
          . tu cliques dessus pour l'afficher une fois affiché
          . tu cliques sur edition en haut du boc notes,et puis sur sélectionner tous
          . tu recliques sur edition et puis sur copier et tu reviens sur le forum et dans ta réponse
          . tu cliques droit dans le cadre de la reponse et coller

          Si tu as besoin d'aide regarde ce tutoriel :
          https://www.malekal.com/tutoriel-malwarebyte-anti-malware/

          3) relances RSIT et postes le nouveau log.txt

          pour être sur de le poster en entier fais cela :

          . ouvres le rapport situé ici C:\rsit\log.txt
          . tu cliques sur edition en haut du boc notes,et puis sur sélectionner tous
          . tu recliques sur edition et puis sur copier et tu reviens sur le forum et dans ta réponse
          . tu cliques droit dans le cadre de la reponse et coller

          et si pas moyen tu le dis et on le passera par cijoint !!

          0
          1. Contributeur sécurité
            Salut
            O4 - HKLM\..\Run: [sysldtray] C:\Windows\ld15.exe
            O4 - HKLM\..\Run: [sysfbtray] C:\Windows\freddy70.exe
            koobface


            Et alors ...?
            Usbfix se chargera des restes dans le log rsit.
            MBAM peut traiter koobface normalement et efficacement

            Je ne vois pas l'intérêt de cette intervention ........................

            ==> Je sors...

            ginie33,
            https://forums.commentcamarche.net/forum/affich-16564345-win32-alureon-ordinateur-infecte#4
            0
            1. Désolée pour le rapport incomplet ! (j'ai dit que j'étais une bille en informatique, vous étiez prévenu )

              Voilà le rapport usbFix : (que j'ai envoyé aussi à l'adresse indiquée)

              ############################## | UsbFix V6.093 |

              User : ginie (Administrateurs) # PC-DE-GINIE
              Update on 10/02/2010 by El Desaparecido , C_XX & Chimay8
              Start at: 21:29:39 | 12/02/2010
              Website : http://pagesperso-orange.fr/NosTools/index.html
              Contact : FindyKill.Contact@gmail.com

              Intel(R) Pentium(R) Dual CPU T2310 @ 1.46GHz
              Microsoft® Windows Vista™ Édition Familiale Premium (6.0.6000 32-bit) #
              Internet Explorer 7.0.6000.16982
              Windows Firewall Status : Disabled
              AV : Antivirus BitDefender 12.0 [ (!) Disabled | (!) Outdated ]
              AV : avast! Antivirus 5.0.83886476 [ Enabled | Updated ]

              C:\ -> Disque fixe local # 74,52 Go (4,52 Go free) [Vista] # NTFS
              E:\ -> Disque fixe local # 73,06 Go (72,88 Go free) [Data] # NTFS
              F:\ -> Disque CD-ROM

              ############################## | Processus actifs |

              C:\Windows\System32\smss.exe
              C:\Windows\system32\csrss.exe
              C:\Windows\system32\wininit.exe
              C:\Windows\system32\csrss.exe
              C:\Windows\system32\services.exe
              C:\Windows\system32\lsass.exe
              C:\Windows\system32\lsm.exe
              C:\Windows\system32\winlogon.exe
              C:\Windows\system32\svchost.exe
              C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
              C:\Windows\system32\svchost.exe
              C:\Windows\System32\svchost.exe
              C:\Windows\system32\LogonUI.exe
              C:\Windows\System32\svchost.exe
              C:\Windows\System32\svchost.exe
              C:\Windows\system32\svchost.exe
              C:\Windows\system32\AUDIODG.EXE
              C:\Windows\system32\SLsvc.exe
              C:\Windows\system32\svchost.exe
              C:\Windows\system32\svchost.exe
              C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
              C:\Windows\System32\spoolsv.exe
              C:\Program Files\Alwil Software\Avast5\setup\avast.setup
              C:\Windows\system32\svchost.exe
              C:\Windows\system32\agrsmsvc.exe
              C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
              C:\PROGRA~1\COMMON~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
              C:\Program Files\Google\Update\GoogleUpdate.exe
              C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
              C:\Program Files\Google\Update\GoogleUpdate.exe
              C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE
              C:\Program Files\Google\Update\GoogleUpdate.exe
              C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
              C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
              C:\Windows\system32\svchost.exe
              C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
              C:\Windows\system32\svchost.exe
              C:\Windows\system32\TODDSrv.exe
              C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe
              C:\Windows\system32\userinit.exe
              C:\Windows\system32\Dwm.exe
              C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
              C:\Windows\System32\svchost.exe
              C:\Windows\Explorer.EXE
              C:\Windows\system32\SearchIndexer.exe
              C:\Windows\system32\runonce.exe
              C:\Windows\system32\taskeng.exe
              C:\Windows\system32\wbem\wmiprvse.exe
              C:\Windows\system32\taskeng.exe

              ################## | Elements infectieux |

              Supprimé ! C:\Users\ginie\Documents - Raccourci.lnk
              Supprimé ! C:\$Recycle.Bin\S-1-5-18
              Supprimé ! C:\$Recycle.Bin\S-1-5-21-1643969366-1937786268-369828714-500
              Supprimé ! C:\$Recycle.Bin\S-1-5-21-2152478756-3922319563-605102323-500
              Supprimé ! C:\$Recycle.Bin\S-1-5-21-2446354535-3758926445-94421575-500
              Supprimé ! C:\$Recycle.Bin\S-1-5-21-2820803949-3729524370-2303368394-500
              Supprimé ! C:\$Recycle.Bin\S-1-5-21-3104489088-2836857065-1364713530-500
              Supprimé ! C:\$Recycle.Bin\S-1-5-21-3274394378-4107285941-262733215-1000
              Supprimé ! C:\$Recycle.Bin\S-1-5-21-402374355-2776029083-1576359178-500
              Supprimé ! E:\$Recycle.Bin\S-1-5-21-3274394378-4107285941-262733215-1000

              ################## | Registre |

              ################## | Mountpoints2 |

              Supprimé ! HKCU\...\Explorer\MountPoints2\{15531ff1-8d49-11dd-9038-001b38accff9}\Shell\AutoRun\Command
              Supprimé ! HKCU\...\Explorer\MountPoints2\{41efb5a8-1778-11dd-9886-001b38accff9}\Shell\Auto\Command
              Supprimé ! HKCU\...\Explorer\MountPoints2\{9517bc08-243b-11de-8c99-001b38accff9}\Shell\AutoRun\Command

              ################## | Listing des fichiers présent |

              [18/09/2006 22:43|--a------|24] C:\autoexec.bat
              [02/11/2006 10:53|-rahs----|438840] C:\bootmgr
              [18/04/2007 06:03|-ra-s----|8192] C:\BOOTSECT.BAK
              [18/09/2006 22:43|--a------|10] C:\config.sys
              [17/01/2010 00:47|-rahs----|0] C:\IO.SYS
              [17/01/2010 00:47|-rahs----|0] C:\MSDOS.SYS
              [?|?|?] C:\pagefile.sys
              [18/04/2007 06:57|--a------|420] C:\RHDSetup.log
              [16/10/2007 05:42|--ah-----|282] C:\SWSTAMP.TXT
              [12/02/2010 21:39|--a------|4436] C:\UsbFix.txt
              [15/10/2007 16:05|--a----t-|24504] C:\_wdsuef.dmp
              [17/10/2007 12:59|--a------|11] E:\H07739FR.tag

              ################## | Vaccination |

              # C:\autorun.inf -> Dossier créé par UsbFix .
              # E:\autorun.inf -> Dossier créé par UsbFix .

              ################## | Upload |

              Veuillez envoyer le fichier : C:\UsbFix_Upload_Me_PC-de-ginie.zip : https://www.ionos.fr/?affiliate_id=77097
              Merci pour votre contribution .

              Et maintenant je fais l'autre manip, je vous mets le rapport dans un autre post.
              Merci !
              0
              1. Contributeur sécurité
                ok mais c'est pas parce que ton rapport n'est pas pesser en complet que t'es une bille !! cela arrive même perso !! et moi c'est pas une bille dans ce cas mais un boulet !!! lol !!

                oui continu avec malwarebytes attention près de 2 h de scan !!
                0
                1. Scan lancé.
                  Voilà le rapport de RSIT complet (j'espère !)

                  Logfile of random's system information tool 1.06 (written by random/random)
                  Run by ginie at 2010-02-12 22:09:57
                  Microsoft® Windows Vista™ Édition Familiale Premium
                  System drive C: has 5 GB (7%) free of 76 GB
                  Total RAM: 2038 MB (40% free)

                  Logfile of Trend Micro HijackThis v2.0.2
                  Scan saved at 22:10:08, on 12/02/2010
                  Platform: Windows Vista (WinNT 6.00.1904)
                  MSIE: Internet Explorer v7.00 (7.00.6000.16982)
                  Boot mode: Normal

                  Running processes:
                  C:\Windows\system32\Dwm.exe
                  C:\Windows\system32\runonce.exe
                  C:\Windows\system32\cmd.exe
                  C:\Windows\system32\taskeng.exe
                  C:\Windows\explorer.exe
                  C:\Windows\system32\wuauclt.exe
                  C:\Program Files\WinZip\WZQKPICK.EXE
                  C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
                  C:\Program Files\Microsoft Office\Office12\WINWORD.EXE
                  C:\Program Files\Microsoft\Office Live\OfficeLiveSignIn.exe
                  C:\Program Files\Internet Explorer\iexplore.exe
                  C:\Program Files\Windows Live\Toolbar\wltuser.exe
                  C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                  C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                  C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
                  C:\Users\ginie\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\KX0SNKKM\RSIT[1].exe
                  C:\Program Files\Trend Micro\HijackThis\ginie.exe

                  R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.fr
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.fr
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
                  R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
                  R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
                  R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
                  R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer
                  R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                  R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\Program Files\OrangeHSS\SearchURLHook\SearchPageURL.dll
                  O1 - Hosts: ::1 localhost
                  O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                  O2 - BHO: &IE Help - {35A5B43B-CB8A-49CA-A9F4-D3B308D2E3CC} - C:\Windows\System32\iehelpmod.dll (file missing)
                  O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
                  O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
                  O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                  O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
                  O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.5.4723.1820\swg.dll
                  O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
                  O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
                  O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
                  O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
                  O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
                  O4 - HKLM\..\Run: [KeNotify] C:\Program Files\TOSHIBA\Utilities\KeNotify.exe
                  O4 - HKLM\..\Run: [SVPWUTIL] C:\Program Files\TOSHIBA\Utilities\SVPWUTIL.exe SVPwUTIL
                  O4 - HKLM\..\Run: [HWSetup] \HWSetup.exe hwSetUP
                  O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
                  O4 - HKLM\..\Run: [TPwrMain] %ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE
                  O4 - HKLM\..\Run: [HSON] %ProgramFiles%\TOSHIBA\TBS\HSON.exe
                  O4 - HKLM\..\Run: [SmoothView] %ProgramFiles%\Toshiba\SmoothView\SmoothView.exe
                  O4 - HKLM\..\Run: [00TCrdMain] %ProgramFiles%\TOSHIBA\FlashCards\TCrdMain.exe
                  O4 - HKLM\..\Run: [NDSTray.exe] NDSTray.exe
                  O4 - HKLM\..\Run: [Desktop SMS] C:\Program Files\IDM\Desktop SMS\DesktopSMS.exe /auto
                  O4 - HKLM\..\Run: [topi] C:\Program Files\TOSHIBA\Toshiba Online Product Information\topi.exe -startup
                  O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
                  O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
                  O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
                  O4 - HKLM\..\Run: [Camera Assistant Software] "C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe"
                  O4 - HKLM\..\Run: [SynTPStart] C:\Program Files\Synaptics\SynTP\SynTPStart.exe
                  O4 - HKLM\..\Run: [Toshiba Registration] C:\Program Files\Toshiba\Registration\ToshibaRegistration.exe
                  O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
                  O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
                  O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
                  O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
                  O4 - HKLM\..\Run: [ORAHSSSessionManager] C:\Program Files\OrangeHSS\SessionManager\SessionManager.exe
                  O4 - HKLM\..\Run: [Easy-PrintToolBox] C:\Program Files\Canon\Easy-PrintToolBox\BJPSMAIN.EXE /logon
                  O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe"
                  O4 - HKLM\..\Run: [sysldtray] C:\Windows\ld15.exe
                  O4 - HKLM\..\Run: [sysfbtray] C:\Windows\freddy70.exe
                  O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
                  O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
                  O4 - HKLM\..\Run: [OpwareSE4] "C:\Program Files\ScanSoft\OmniPageSE4\OpwareSE4.exe"
                  O4 - HKLM\..\Run: [avast5] C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe /nogui
                  O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
                  O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
                  O4 - HKCU\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
                  O4 - HKCU\..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe
                  O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
                  O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
                  O4 - HKCU\..\Run: [BlazeServoTool] "C:\Program Files\BlazeVideo\BlazeDTV 2.5a\MediaDetector.exe"
                  O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
                  O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
                  O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
                  O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
                  O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
                  O4 - Startup: OneNote 2007 - Capture d'écran et lancement.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
                  O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
                  O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
                  O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
                  O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
                  O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
                  O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
                  O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
                  O9 - Extra button: eBay - Achetez, Vendez - {76577871-04EC-495E-A12B-91F7C3600AFA} - https://www.ebay.fr (file missing)
                  O9 - Extra button: Amazon.fr - {8A918C1D-E123-4E36-B562-5C1519E434CE} - https://www.amazon.fr/exec/obidos/subst/home/home.html/262-6263521-6325360?_encoding=UTF8&link_code=hom&tag=Toshibafrbholink-21 (file missing)
                  O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
                  O9 - Extra button: eBay - {C08CAF1D-C0A3-40D5-9970-06D067EAC017} - http://www.webtip.ch/cgi-bin/toshiba/tracker_url.pl?FR (file missing)
                  O13 - Gopher Prefix:
                  O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe
                  O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
                  O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
                  O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
                  O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
                  O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom SA - C:\PROGRA~1\COMMON~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
                  O23 - Service: Service Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
                  O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                  O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
                  O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
                  O23 - Service: PIXMA Extended Survey Program (IJPLMSVC) - Unknown owner - C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE
                  O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
                  O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
                  O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
                  O23 - Service: Planificateur LiveUpdate automatique - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
                  O23 - Service: TOSHIBA Optical Disc Drive Service (TODDSrv) - TOSHIBA Corporation - C:\Windows\system32\TODDSrv.exe
                  O23 - Service: TOSHIBA Power Saver (TosCoSrv) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe
                  O23 - Service: TOSHIBA Bluetooth Service - Unknown owner - c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe (file missing)
                  O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
                  0
                  1. Contributeur sécurité
                    tu as sauté une étape car j'ai pas le rapport de malwarebytes demandé avant le nouveau RSIT !! tu fais malwarebytes et après tu postes le nouveau RSIT , merci
                    0
                    1. Ah ah !! Moi j'ai tout lancé en même temps. Donc je le refais plus tard ok
                      0
                      1. Contributeur sécurité
                        ok , mais ne jamais lancer plusieur outils de désinfection en même temps tu risque de mettre le pc en saturation et le faire buger ou planter , donc tu fais l'examen complet avec malwarebytes , tu postes le rapport et seulement après tu fais le nouveau RSIT car la celui ci montre des chose que normalement malwarebytes devrait supprimer , donc d'ou l'interêt de le faire après !!!

                        sinon, consernant le boulet c'était juste pour dire que toi si tu est bille moi étant plus gros 90 k je suis donc dans la catégorie suppérieur !! lol !! c'était de l'humour !!
                        0
                        1. J'avais bien compris l'humour !
                          Je prends note pour les processus de désinfection à faire séparément , merci.
                          0
                          1. Voilà le rapport malwarebytes :

                            (je viens de re-avoir le message d'avast quend l'ordi s'est rallmumé comme quoi win32-alureon est détecté...., ca n'a donc pas marché je suppose...)

                            Malwarebytes' Anti-Malware 1.44
                            Version de la base de données: 3731
                            Windows 6.0.6000
                            Internet Explorer 7.0.6000.16982

                            12/02/2010 23:26:41
                            mbam-log-2010-02-12 (23-26-41).txt

                            Type de recherche: Examen complet (C:\|E:\|F:\|)
                            Eléments examinés: 252148
                            Temps écoulé: 1 hour(s), 16 minute(s), 4 second(s)

                            Processus mémoire infecté(s): 0
                            Module(s) mémoire infecté(s): 0
                            Clé(s) du Registre infectée(s): 6
                            Valeur(s) du Registre infectée(s): 3
                            Elément(s) de données du Registre infecté(s): 0
                            Dossier(s) infecté(s): 2
                            Fichier(s) infecté(s): 22

                            Processus mémoire infecté(s):
                            (Aucun élément nuisible détecté)

                            Module(s) mémoire infecté(s):
                            (Aucun élément nuisible détecté)

                            Clé(s) du Registre infectée(s):
                            HKEY_CLASSES_ROOT\CLSID\{35a5b43b-cb8a-49ca-a9f4-d3b308d2e3cc} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
                            HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{35a5b43b-cb8a-49ca-a9f4-d3b308d2e3cc} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
                            HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{35a5b43b-cb8a-49ca-a9f4-d3b308d2e3cc} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
                            HKEY_LOCAL_MACHINE\System\CurrentControlSet\Servises (Malware.Trace) -> Quarantined and deleted successfully.
                            HKEY_LOCAL_MACHINE\System\CurrentControlSet\Enum\Root\LEGACY_FIO32 (Worm.KoobFace) -> Quarantined and deleted successfully.
                            HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\SfX (Rootkit.Agent) -> Quarantined and deleted successfully.

                            Valeur(s) du Registre infectée(s):
                            HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\desktop sms (Worm.P2P) -> Quarantined and deleted successfully.
                            HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\sysfbtray (Worm.KoobFace) -> Quarantined and deleted successfully.
                            HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\sysldtray (Backdoor.Bot) -> Quarantined and deleted successfully.

                            Elément(s) de données du Registre infecté(s):
                            (Aucun élément nuisible détecté)

                            Dossier(s) infecté(s):
                            C:\Program Files\Common Files\CSUninstall (Rogue.CyberSecurity) -> Quarantined and deleted successfully.
                            C:\ProgramData\Microsoft\Windows\Start Menu\CS (Rogue.CyberSecurity) -> Quarantined and deleted successfully.

                            Fichier(s) infecté(s):
                            C:\Program Files\Common Files\CSUninstall\Uninstall.lnk (Rogue.CyberSecurity) -> Quarantined and deleted successfully.
                            C:\ProgramData\Microsoft\Windows\Start Menu\CS\Computer Scan.lnk (Rogue.CyberSecurity) -> Quarantined and deleted successfully.
                            C:\ProgramData\Microsoft\Windows\Start Menu\CS\Cyber Security.lnk (Rogue.CyberSecurity) -> Quarantined and deleted successfully.
                            C:\ProgramData\Microsoft\Windows\Start Menu\CS\Help.lnk (Rogue.CyberSecurity) -> Quarantined and deleted successfully.
                            C:\ProgramData\Microsoft\Windows\Start Menu\CS\Registration.lnk (Rogue.CyberSecurity) -> Quarantined and deleted successfully.
                            C:\ProgramData\Microsoft\Windows\Start Menu\CS\Security Center.lnk (Rogue.CyberSecurity) -> Quarantined and deleted successfully.
                            C:\ProgramData\Microsoft\Windows\Start Menu\CS\Settings.lnk (Rogue.CyberSecurity) -> Quarantined and deleted successfully.
                            C:\ProgramData\Microsoft\Windows\Start Menu\CS\Update.lnk (Rogue.CyberSecurity) -> Quarantined and deleted successfully.
                            C:\Windows\bx4657.dat (KoobFace.Trace) -> Quarantined and deleted successfully.
                            C:\Windows\bk20856.dat (KoobFace.Trace) -> Quarantined and deleted successfully.
                            C:\Windows\010112010146116101.xxe (KoobFace.Trace) -> Quarantined and deleted successfully.
                            C:\Windows\0101120101464855.xxe (KoobFace.Trace) -> Quarantined and deleted successfully.
                            C:\Windows\0101120101465050.xxe (KoobFace.Trace) -> Quarantined and deleted successfully.
                            C:\Windows\0101120101465249.xxe (KoobFace.Trace) -> Quarantined and deleted successfully.
                            C:\Windows\0101120101465349.xxe (KoobFace.Trace) -> Quarantined and deleted successfully.
                            C:\Windows\0101120101465649.xxe (KoobFace.Trace) -> Quarantined and deleted successfully.
                            C:\Windows\hpm2.dat (KoobFace.Trace) -> Quarantined and deleted successfully.
                            C:\Windows\bk23567.dat (KoobFace.Trace) -> Quarantined and deleted successfully.
                            C:\Windows\mmsmark2.dat (KoobFace.Trace) -> Quarantined and deleted successfully.
                            C:\Windows\tgm2.dat (KoobFace.Trace) -> Quarantined and deleted successfully.
                            C:\Users\ginie\Desktop\Cyber Security.lnk (Rogue.CyberSecurity) -> Quarantined and deleted successfully.
                            C:\Users\ginie\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\CS.lnk (Rogue.CyberSecurity) -> Quarantined and deleted successfully.

                            Je refais RSIT
                            0
                            1. Voilà pour RSIT :

                              Logfile of random's system information tool 1.06 (written by random/random)
                              Run by ginie at 2010-02-12 23:36:01
                              Microsoft® Windows Vista™ Édition Familiale Premium
                              System drive C: has 5 GB (7%) free of 76 GB
                              Total RAM: 2038 MB (48% free)

                              Logfile of Trend Micro HijackThis v2.0.2
                              Scan saved at 23:36:05, on 12/02/2010
                              Platform: Windows Vista (WinNT 6.00.1904)
                              MSIE: Internet Explorer v7.00 (7.00.6000.16982)
                              Boot mode: Normal

                              Running processes:
                              C:\Windows\system32\Dwm.exe
                              C:\Windows\Explorer.EXE
                              C:\Program Files\Windows Defender\MSASCui.exe
                              C:\Program Files\TOSHIBA\Utilities\KeNotify.exe
                              C:\Windows\RtHDVCpl.exe
                              C:\Windows\system32\taskeng.exe
                              C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe
                              C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe
                              C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe
                              C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe
                              C:\Program Files\TOSHIBA\Toshiba Online Product Information\TOPI.exe
                              C:\Windows\System32\igfxtray.exe
                              C:\Windows\system32\igfxsrvc.exe
                              C:\Windows\System32\hkcmd.exe
                              C:\Windows\System32\igfxpers.exe
                              C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe
                              C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
                              C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
                              C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe
                              C:\Program Files\Java\jre6\bin\jusched.exe
                              C:\Program Files\ScanSoft\OmniPageSE4\OpWareSE4.exe
                              C:\Program Files\Alwil Software\Avast5\AvastUI.exe
                              C:\Program Files\Windows Sidebar\sidebar.exe
                              C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe
                              C:\Windows\ehome\ehtray.exe
                              C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                              C:\Program Files\Camera Assistant Software for Toshiba\CEC_MAIN.exe
                              C:\Program Files\BlazeVideo\BlazeDTV 2.5a\MediaDetector.exe
                              C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                              C:\Program Files\Windows Media Player\wmpnscfg.exe
                              C:\Program Files\WinZip\WZQKPICK.EXE
                              C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
                              C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                              C:\Windows\ehome\ehmsas.exe
                              C:\PROGRA~1\COMMON~1\France Telecom\Shared Modules\AlertModule\0\AlertModule.exe
                              C:\Program Files\Synaptics\SynTP\SynToshiba.exe
                              C:\Program Files\OrangeHSS\systray\systrayapp.exe
                              C:\Program Files\TOSHIBA\ConfigFree\CFSwMgr.exe
                              C:\Program Files\Windows Live\Contacts\wlcomm.exe
                              C:\Program Files\Microsoft Office\Office12\WINWORD.EXE
                              C:\Program Files\Microsoft\Office Live\OfficeLiveSignIn.exe
                              C:\Program Files\Internet Explorer\iexplore.exe
                              C:\Program Files\Windows Live\Toolbar\wltuser.exe
                              C:\Windows\system32\wuauclt.exe
                              C:\Users\ginie\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\KX0SNKKM\RSIT[1].exe
                              C:\Program Files\Trend Micro\HijackThis\ginie.exe

                              R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.fr
                              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.fr
                              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
                              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
                              R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/
                              R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
                              R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
                              R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer
                              R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                              R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\Program Files\OrangeHSS\SearchURLHook\SearchPageURL.dll
                              O1 - Hosts: ::1 localhost
                              O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                              O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
                              O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
                              O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                              O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
                              O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.5.4723.1820\swg.dll
                              O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
                              O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
                              O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
                              O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
                              O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
                              O4 - HKLM\..\Run: [KeNotify] C:\Program Files\TOSHIBA\Utilities\KeNotify.exe
                              O4 - HKLM\..\Run: [SVPWUTIL] C:\Program Files\TOSHIBA\Utilities\SVPWUTIL.exe SVPwUTIL
                              O4 - HKLM\..\Run: [HWSetup] \HWSetup.exe hwSetUP
                              O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
                              O4 - HKLM\..\Run: [TPwrMain] %ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE
                              O4 - HKLM\..\Run: [HSON] %ProgramFiles%\TOSHIBA\TBS\HSON.exe
                              O4 - HKLM\..\Run: [SmoothView] %ProgramFiles%\Toshiba\SmoothView\SmoothView.exe
                              O4 - HKLM\..\Run: [00TCrdMain] %ProgramFiles%\TOSHIBA\FlashCards\TCrdMain.exe
                              O4 - HKLM\..\Run: [NDSTray.exe] NDSTray.exe
                              O4 - HKLM\..\Run: [topi] C:\Program Files\TOSHIBA\Toshiba Online Product Information\topi.exe -startup
                              O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
                              O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
                              O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
                              O4 - HKLM\..\Run: [Camera Assistant Software] "C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe"
                              O4 - HKLM\..\Run: [SynTPStart] C:\Program Files\Synaptics\SynTP\SynTPStart.exe
                              O4 - HKLM\..\Run: [Toshiba Registration] C:\Program Files\Toshiba\Registration\ToshibaRegistration.exe
                              O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
                              O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
                              O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
                              O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
                              O4 - HKLM\..\Run: [ORAHSSSessionManager] C:\Program Files\OrangeHSS\SessionManager\SessionManager.exe
                              O4 - HKLM\..\Run: [Easy-PrintToolBox] C:\Program Files\Canon\Easy-PrintToolBox\BJPSMAIN.EXE /logon
                              O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe"
                              O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
                              O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
                              O4 - HKLM\..\Run: [OpwareSE4] "C:\Program Files\ScanSoft\OmniPageSE4\OpwareSE4.exe"
                              O4 - HKLM\..\Run: [avast5] C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe /nogui
                              O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
                              O4 - HKCU\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
                              O4 - HKCU\..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe
                              O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
                              O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
                              O4 - HKCU\..\Run: [BlazeServoTool] "C:\Program Files\BlazeVideo\BlazeDTV 2.5a\MediaDetector.exe"
                              O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
                              O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
                              O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
                              O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
                              O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
                              O4 - Startup: OneNote 2007 - Capture d'écran et lancement.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
                              O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
                              O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
                              O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
                              O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
                              O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
                              O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
                              O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
                              O9 - Extra button: eBay - Achetez, Vendez - {76577871-04EC-495E-A12B-91F7C3600AFA} - http://rover.ebay.com/rover/1/709-44555-9400-3/4 (file missing)
                              O9 - Extra button: Amazon.fr - {8A918C1D-E123-4E36-B562-5C1519E434CE} - http://www.amazon.fr/exec/obidos/redirect-home?tag=Toshibafrbholink-21&site=home (file missing)
                              O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
                              O9 - Extra button: eBay - {C08CAF1D-C0A3-40D5-9970-06D067EAC017} - http://www.webtip.ch/cgi-bin/toshiba/tracker_url.pl?FR (file missing)
                              O13 - Gopher Prefix:
                              O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe
                              O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
                              O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
                              O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
                              O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
                              O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom SA - C:\PROGRA~1\COMMON~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
                              O23 - Service: Service Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
                              O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                              O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
                              O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
                              O23 - Service: PIXMA Extended Survey Program (IJPLMSVC) - Unknown owner - C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE
                              O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
                              O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
                              O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
                              O23 - Service: Planificateur LiveUpdate automatique - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
                              O23 - Service: TOSHIBA Optical Disc Drive Service (TODDSrv) - TOSHIBA Corporation - C:\Windows\system32\TODDSrv.exe
                              O23 - Service: TOSHIBA Power Saver (TosCoSrv) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe
                              O23 - Service: TOSHIBA Bluetooth Service - Unknown owner - c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe (file missing)
                              O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
                              0
                              1. Contributeur sécurité
                                ok cela me semble pas mal , mais tu vas désinstaller norton convenablement avec cet outil http://service1.symantec.com/SUPPORT/INTER/tsgeninfointl.nsf/fr_docid/20050414110429924

                                quand tu auras fini il t'ouvrira une page comment réinstaller un produit symantec tu fermes la fenêtre

                                et puis tu fais cela :

                                1) Desactives la protection residente de ton antivirus et ton parefeu et anti-spyware si present , le temps du scan

                                passes List&Kill'em

                                télécharges le sur le bureau : http://sd-1.archive-host.com/membres/up/829108531491024/List_Killem_Install.exe

                                il ne demande pas d'installation tu doubles cliques dessus " pour vista clique droit et en tant que administrateur "

                                tu mets f pour français et valides avec entrée

                                tu choisis 1= Mode Recherche et entrée tu le laisse travailler et tu postes le rapport

                                il est sinon conservé à la racine du disque système

                                2) Desactives la protection residente de ton antivirus et ton parefeu et anti-spyware si present , le temps du scan

                                Relances List&Kill'em comme tu as fait pour l'option 1 (soit en clic droit pour vista),

                                mais cette fois-ci :

                                choisis l'option 2 = Mode Destruction

                                laisse travailler l'outil

                                apres les verifications , un rapport va s'ouvrir.

                                ferme-le.

                                un deuxieme rapport va s'ouvrir ,

                                colle son contenu dans ta reponse

                                C:\Kill'em.txt

                                0
                                1. Je ne sais pas si c'est normal, la procédure est assez longue... Le scan est bloqué à 30% du processus depuis une demi heure. Planté ou normal ? J'en sais trop rien, je pense arrêter et reprendre demain, possible ?
                                  0
                                  1. Contributeur sécurité
                                    ok si problème tu fais directement l'option 2 mais en mode sans echec
                                    0
                                    1. rapport de l'option 1 mode recherche :

                                      List'em by g3n-h@ckm@n 1.2.5.0

                                      User : ginie (Administrateurs)
                                      Update on 08/02/2010 by g3n-h@ckm@n ::::: 15.30
                                      Start at: 10:26:07 | 13/02/2010
                                      Contact : https://forums.commentcamarche.net/forum/virus-securite-7

                                      Intel(R) Pentium(R) Dual CPU T2310 @ 1.46GHz
                                      Microsoft® Windows Vista™ Édition Familiale Premium (6.0.6000 32-bit) #
                                      Internet Explorer 7.0.6000.16982
                                      Windows Firewall Status : Disabled
                                      AV : Antivirus BitDefender 12.0 [ (!) Disabled | (!) Outdated ]
                                      AV : avast! Antivirus 5.0.83886476 [ Enabled | Updated ]

                                      C:\ -> Disque fixe local | 74,52 Go (4,36 Go free) [Vista] | NTFS
                                      E:\ -> Disque fixe local | 73,06 Go (72,88 Go free) [Data] | NTFS
                                      F:\ -> Disque CD-ROM

                                      ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Processes running

                                      C:\Windows\System32\smss.exe
                                      C:\Windows\system32\csrss.exe
                                      C:\Windows\system32\wininit.exe
                                      C:\Windows\system32\csrss.exe
                                      C:\Windows\system32\services.exe
                                      C:\Windows\system32\lsass.exe
                                      C:\Windows\system32\lsm.exe
                                      C:\Windows\system32\winlogon.exe
                                      C:\Windows\system32\svchost.exe
                                      C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
                                      C:\Windows\system32\svchost.exe
                                      C:\Windows\System32\svchost.exe
                                      C:\Windows\System32\svchost.exe
                                      C:\Windows\System32\svchost.exe
                                      C:\Windows\system32\svchost.exe
                                      C:\Windows\system32\AUDIODG.EXE
                                      C:\Windows\system32\SLsvc.exe
                                      C:\Windows\system32\svchost.exe
                                      C:\Windows\system32\svchost.exe
                                      C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
                                      C:\Windows\System32\spoolsv.exe
                                      C:\Windows\system32\svchost.exe
                                      C:\Windows\system32\agrsmsvc.exe
                                      C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
                                      C:\PROGRA~1\COMMON~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
                                      C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
                                      C:\Program Files\Google\Update\GoogleUpdate.exe
                                      C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE
                                      C:\Windows\system32\svchost.exe
                                      C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
                                      C:\Windows\system32\svchost.exe
                                      C:\Windows\system32\TODDSrv.exe
                                      C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe
                                      C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
                                      C:\Windows\System32\svchost.exe
                                      C:\Windows\system32\SearchIndexer.exe
                                      C:\Windows\system32\taskeng.exe
                                      C:\Windows\system32\Dwm.exe
                                      C:\Windows\system32\taskeng.exe
                                      C:\Windows\Explorer.EXE
                                      C:\Program Files\Windows Defender\MSASCui.exe
                                      C:\Program Files\TOSHIBA\Utilities\KeNotify.exe
                                      C:\Windows\RtHDVCpl.exe
                                      C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe
                                      C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe
                                      C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe
                                      C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe
                                      C:\Program Files\TOSHIBA\Toshiba Online Product Information\TOPI.exe
                                      C:\Windows\System32\igfxtray.exe
                                      C:\Windows\System32\hkcmd.exe
                                      C:\Windows\System32\igfxpers.exe
                                      C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe
                                      C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
                                      C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe
                                      C:\Program Files\Java\jre6\bin\jusched.exe
                                      C:\Program Files\ScanSoft\OmniPageSE4\OpWareSE4.exe
                                      C:\Program Files\Alwil Software\Avast5\AvastUI.exe
                                      C:\Program Files\Windows Sidebar\sidebar.exe
                                      C:\Windows\system32\igfxsrvc.exe
                                      C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe
                                      C:\Windows\ehome\ehtray.exe
                                      C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                                      C:\Program Files\BlazeVideo\BlazeDTV 2.5a\MediaDetector.exe
                                      C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                                      C:\Program Files\Windows Media Player\wmpnscfg.exe
                                      C:\Program Files\WinZip\WZQKPICK.EXE
                                      C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
                                      C:\Program Files\Camera Assistant Software for Toshiba\CEC_MAIN.exe
                                      C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                                      C:\Windows\ehome\ehmsas.exe
                                      C:\Program Files\Windows Media Player\wmpnetwk.exe
                                      C:\Program Files\Synaptics\SynTP\SynToshiba.exe
                                      C:\Program Files\TOSHIBA\ConfigFree\CFSwMgr.exe
                                      C:\PROGRA~1\COMMON~1\France Telecom\Shared Modules\AlertModule\0\AlertModule.exe
                                      C:\Program Files\OrangeHSS\systray\systrayapp.exe
                                      C:\Windows\system32\wuauclt.exe
                                      C:\Program Files\Windows Live\Contacts\wlcomm.exe
                                      C:\Program Files\Internet Explorer\iexplore.exe
                                      C:\Program Files\Windows Live\Toolbar\wltuser.exe
                                      C:\Windows\system32\taskeng.exe
                                      C:\Windows\system32\SearchProtocolHost.exe
                                      C:\Program Files\List_Kill'em\List_Kill'em.scr
                                      C:\Windows\system32\conime.exe
                                      C:\Windows\system32\SearchFilterHost.exe
                                      C:\Windows\system32\cmd.exe
                                      C:\Windows\system32\wbem\wmiprvse.exe
                                      C:\Users\ginie\AppData\Local\Temp\97BC.tmp\pv.exe

                                      ======================
                                      Keys "Run"
                                      ======================
                                      [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                                      Sidebar REG_SZ C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
                                      WindowsWelcomeCenter REG_SZ rundll32.exe oobefldr.dll,ShowWelcomeCenter
                                      TOSCDSPD REG_SZ C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe
                                      ehTray.exe REG_SZ C:\Windows\ehome\ehTray.exe
                                      MsnMsgr REG_SZ "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
                                      BlazeServoTool REG_SZ "C:\Program Files\BlazeVideo\BlazeDTV 2.5a\MediaDetector.exe"
                                      swg REG_SZ "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
                                      WMPNSCFG REG_SZ C:\Program Files\Windows Media Player\WMPNSCFG.exe

                                      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                                      Windows Defender REG_EXPAND_SZ %ProgramFiles%\Windows Defender\MSASCui.exe -hide
                                      KeNotify REG_SZ C:\Program Files\TOSHIBA\Utilities\KeNotify.exe
                                      SVPWUTIL REG_SZ C:\Program Files\TOSHIBA\Utilities\SVPWUTIL.exe SVPwUTIL
                                      HWSetup REG_SZ \HWSetup.exe hwSetUP
                                      RtHDVCpl REG_SZ RtHDVCpl.exe
                                      TPwrMain REG_EXPAND_SZ %ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE
                                      HSON REG_EXPAND_SZ %ProgramFiles%\TOSHIBA\TBS\HSON.exe
                                      SmoothView REG_EXPAND_SZ %ProgramFiles%\Toshiba\SmoothView\SmoothView.exe
                                      00TCrdMain REG_EXPAND_SZ %ProgramFiles%\TOSHIBA\FlashCards\TCrdMain.exe
                                      NDSTray.exe REG_SZ NDSTray.exe
                                      topi REG_SZ C:\Program Files\TOSHIBA\Toshiba Online Product Information\topi.exe -startup
                                      IgfxTray REG_SZ C:\Windows\system32\igfxtray.exe
                                      HotKeysCmds REG_SZ C:\Windows\system32\hkcmd.exe
                                      Persistence REG_SZ C:\Windows\system32\igfxpers.exe
                                      Camera Assistant Software REG_SZ "C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe"
                                      SynTPStart REG_SZ C:\Program Files\Synaptics\SynTP\SynTPStart.exe
                                      Toshiba Registration REG_SZ C:\Program Files\Toshiba\Registration\ToshibaRegistration.exe
                                      IAAnotif REG_SZ C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
                                      Adobe Reader Speed Launcher REG_SZ "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
                                      QuickTime Task REG_SZ "C:\Program Files\QuickTime\QTTask.exe" -atboottime
                                      ORAHSSSessionManager REG_SZ C:\Program Files\OrangeHSS\SessionManager\SessionManager.exe
                                      Easy-PrintToolBox REG_SZ C:\Program Files\Canon\Easy-PrintToolBox\BJPSMAIN.EXE /logon
                                      Adobe Photo Downloader REG_SZ "C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe"
                                      SunJavaUpdateSched REG_SZ "C:\Program Files\Java\jre6\bin\jusched.exe"
                                      SSBkgdUpdate REG_SZ "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
                                      OpwareSE4 REG_SZ "C:\Program Files\ScanSoft\OmniPageSE4\OpwareSE4.exe"
                                      avast5 REG_SZ C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe /nogui

                                      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices]

                                      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]

                                      =====================
                                      Other Keys
                                      =====================
                                      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
                                      ConsentPromptBehaviorAdmin REG_DWORD 0 (0x0)
                                      ConsentPromptBehaviorUser REG_DWORD 1 (0x1)
                                      EnableInstallerDetection REG_DWORD 1 (0x1)
                                      EnableLUA REG_DWORD 0 (0x0)
                                      EnableSecureUIAPaths REG_DWORD 1 (0x1)
                                      EnableVirtualization REG_DWORD 1 (0x1)
                                      PromptOnSecureDesktop REG_DWORD 1 (0x1)
                                      ValidateAdminCodeSignatures REG_DWORD 0 (0x0)
                                      dontdisplaylastusername REG_DWORD 0 (0x0)
                                      legalnoticecaption REG_SZ
                                      legalnoticetext REG_SZ
                                      scforceoption REG_DWORD 0 (0x0)
                                      shutdownwithoutlogon REG_DWORD 1 (0x1)
                                      undockwithoutlogon REG_DWORD 1 (0x1)
                                      FilterAdministratorToken REG_DWORD 0 (0x0)

                                      ===============
                                      [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
                                      NoDriveAutoRun REG_DWORD 255 (0xff)
                                      NoDriveTypeAutoRun REG_DWORD 255 (0xff)
                                      HonorAutoRunSetting REG_DWORD 0 (0x0)

                                      ===============
                                      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
                                      NoDriveAutoRun REG_DWORD 255 (0xff)
                                      NoDriveTypeAutoRun REG_DWORD 255 (0xff)
                                      HonorAutoRunSetting REG_DWORD 0 (0x0)

                                      ===============
                                      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
                                      AppInit_DLLS REG_SZ

                                      ===============
                                      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
                                      ReportBootOk REG_SZ 1
                                      Shell REG_SZ explorer.exe
                                      Userinit REG_SZ C:\Windows\system32\userinit.exe,
                                      VmApplet REG_SZ rundll32 shell32,Control_RunDLL "sysdm.cpl"
                                      AutoRestartShell REG_DWORD 1 (0x1)
                                      LegalNoticeCaption REG_SZ
                                      LegalNoticeText REG_SZ
                                      PowerdownAfterShutdown REG_SZ 0
                                      ShutdownWithoutLogon REG_SZ 0
                                      cachedlogonscount REG_SZ 10
                                      forceunlocklogon REG_DWORD 0 (0x0)
                                      passwordexpirywarning REG_DWORD 14 (0xe)
                                      Background REG_SZ 0 0 0
                                      DebugServerCommand REG_SZ no
                                      WinStationsDisabled REG_SZ 0
                                      DisableCAD REG_DWORD 1 (0x1)
                                      scremoveoption REG_SZ 0
                                      ShutdownFlags REG_DWORD 43 (0x2b)

                                      ===============
                                      [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\igfxcui]

                                      ===============
                                      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]

                                      ===============
                                      [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
                                      C:\Program Files\OrangeHSS\Connectivity\ConnectivityManager.exe REG_SZ C:\Program Files\OrangeHSS\Connectivity\ConnectivityManager.exe:*:enabled:CSS

                                      [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

                                      ===============
                                      ActivX controls
                                      ===============

                                      ===============
                                      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}
                                      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{26923b43-4d38-484f-9b9e-de460746276c}
                                      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}
                                      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{08B0E5C0-4FCB-11CF-AAA5-00401C608500}
                                      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{2179C5D3-EBFF-11CF-B6FD-00AA00B4E220}
                                      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{22d6f312-b0f6-11d0-94ab-0080c74c7e95}
                                      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}
                                      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{3af36230-a269-11d1-b5bf-0000f8051515}
                                      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}
                                      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA848-CC51-11CF-AAFA-00AA00B6015C}
                                      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA855-CC51-11CF-AAFA-00AA00B6015F}
                                      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{45ea75a0-a269-11d1-b5bf-0000f8051515}
                                      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{4f645220-306d-11d2-995d-00c04f98bbc9}
                                      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{5fd399c0-a70a-11d1-9948-00c04f98bbc9}
                                      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{630b1da0-b465-11d1-9948-00c04f98bbc9}
                                      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}
                                      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{6fab99d0-bab8-11d1-994a-00c04f98bbc9}
                                      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{7790769C-0471-11d2-AF11-00C04FA35D02}
                                      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{7C028AF8-F614-47B3-82DA-BA94E41B1089}
                                      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{89820200-ECBD-11cf-8B85-00AA005B4340}
                                      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{89820200-ECBD-11cf-8B85-00AA005B4383}
                                      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{89B4C1CD-B018-4511-B0A1-5476DBF70820}
                                      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{9381D8F2-0288-11D0-9501-00AA00B911A5}
                                      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{C6BAF60B-6E91-453F-BFF9-D3789CFEFCDD}
                                      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{C9E9A340-D1F1-11D0-821E-444553540600}
                                      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{CDD7975E-60F8-41d5-8149-19E51D6F71D0}
                                      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{D27CDB6E-AE6D-11CF-96B8-444553540000}
                                      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{de5aed00-a4bf-11d1-9948-00c04f98bbc9}
                                      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{E92B03AB-B707-11d2-9CBD-0000F87A369E}

                                      ==============
                                      BHO :
                                      ======
                                      [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
                                      [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{5C255C8A-E604-49b4-9D64-90988571CECB}]
                                      [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{6EBF7485-159F-4bff-A14F-B9E3AAC4465B}]
                                      [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
                                      [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
                                      [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
                                      [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
                                      [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{E15A8DC0-8516-42A1-81EA-DC94EC1ACF10}]

                                      ================
                                      Internet Explorer :
                                      ================
                                      [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
                                      Start Page REG_SZ https://www.msn.com/fr-fr

                                      [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
                                      Start Page REG_SZ http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome

                                      ========
                                      Services
                                      ========
                                      [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services]

                                      Ndisuio : 0x3 ( OK = 3 )
                                      EapHost : 0x3 ( OK = 2 )
                                      Wlansvc : 0x2 ( OK = 2 )
                                      SharedAccess : 0x3 ( OK = 2 )
                                      windefend : 0x2 ( OK = 2 )
                                      wuauserv : 0x2 ( OK = 2 )
                                      wscsvc : 0x2 ( OK = 2 )

                                      =========
                                      Atapi.sys
                                      =========

                                      %%%% HASHDEEP-1.0
                                      %%%% size,md5,sha256,filename
                                      ## Invoked from: C:\Users\ginie\AppData\Local\Temp\97BC.tmp
                                      ## C:\> hashdeep C:\Windows\System32\Drivers\atapi.sys
                                      ##
                                      21560,b35cfcef838382ab6490b321c87edf17,a13985b87b5918d123072c7128e12dc28b0fcfd68383afa6e1da72a25bd781e0,C:\Windows\System32\Drivers\atapi.sys

                                      Sources
                                      =======

                                      C:\Windows\SoftwareDistribution\Download\b1d48c0a5500e900499764daaa6a0385\x86_mshdc.inf_31bf3856ad364e35_6.0.6001.18000_none_dd38281a2189ce9c\atapi.sys
                                      C:\Windows\System32\drivers\atapi.sys
                                      C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_7de13c21\atapi.sys
                                      C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_c6c2e699\atapi.sys
                                      C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6000.16632_none_db337a442479c42c\atapi.sys
                                      C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6000.20757_none_dbac78a93da31a8b\atapi.sys

                                      Référence :
                                      ==========

                                      Win XP_32b : a64013e98426e1877cb653685c5c0009
                                      Win XP_SP2_32b : CDFE4411A69C224BD1D11B2DA92DAC51
                                      Win XP_SP3_32b : 9F3A2F5AA6875C72BF062C712CFA2674
                                      Vista_32b : e03e8c99d15d0381e02743c36afc7c6f
                                      Vista_SP1_32b : 2d9c903dc76a66813d350a562de40ed9
                                      Vista_SP2_32b : 1F05B78AB91C9075565A9D8A4B880BC4
                                      Vista_SP2_64b : 1898FAE8E07D97F2F6C2D5326C633FAC
                                      Windows 7_32b : 80C40F7FDFC376E4C5FEEC28B41C119E
                                      Windows 7_64b : 02062C0B390B7729EDC9E69C680A6F3C

                                      =======
                                      Drive :
                                      =======

                                      D‚fragmenteur de disque Windows
                                      Copyright (c) 2006 Microsoft Corp.

                                      Rapport d'analyse pour le volume C: Vista

                                      Taille du volume = 74.52 Go
                                      Espace libre = 4.38 Go
                                      tendue d'espace libre la plus grande = 190 Mo
                                      Pourcentage de fragmentation des fichiers = 3 %

                                      Remarqueÿ: sur les volumes NTFS, les fragments de fichiers de plus de 64ÿMo ne sont pas inclus dans les statistiques de fragmentation.

                                      Il n'est pas n‚cessaire de d‚fragmenter ce volume.

                                      ¤¤¤¤¤¤¤¤¤¤ Files/folders :

                                      Present !! : C:\Windows\System32\drivers\etc\hosts.msn
                                      Present !! : C:\Users\ginie\Local Settings\Temp\00.IFO
                                      Present !! : C:\Users\ginie\Local Settings\Temp\01.IFO
                                      Present !! : C:\Users\ginie\Local Settings\Temp\reg.xml
                                      Present !! : C:\Users\ginie\Local Settings\Temp\WAB.log
                                      Present !! : C:\Users\ginie\LOCAL Settings\Temp\igraal.exe
                                      Present !! : C:\Users\ginie\LOCAL Settings\Temp\ose00000.exe
                                      Present !! : C:\Users\ginie\LOCAL Settings\Temp\QuickZip-5.0.0.10-Beta.exe
                                      Present !! : C:\Users\ginie\LOCAL Settings\Temp\album9005402838156912197.dat

                                      ¤¤¤¤¤¤¤¤¤¤ Keys :

                                      Present !! : HKLM\SYSTEM\ControlSet002\Services\SfX
                                      Present !! : HKLM\SYSTEM\ControlSet003\Services\SfX
                                      Present !! : HKLM\SYSTEM\ControlSet004\Services\SfX

                                      ============

                                      catchme 0.3.1398.3 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
                                      Rootkit scan 2010-02-13 11:51:03
                                      Windows 6.0.6000 NTFS

                                      scanning hidden processes ...

                                      scanning hidden services & system hive ...

                                      scanning hidden registry entries ...

                                      scanning hidden files ...

                                      scan completed successfully
                                      hidden processes: 0
                                      hidden services: 0
                                      hidden files: 0

                                      Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

                                      device: opened successfully
                                      user: MBR read successfully
                                      called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys acpi.sys hal.dll iaStor.sys >>UNKNOWN [0x87554F61]<<
                                      kernel: MBR read successfully
                                      user & kernel MBR OK

                                      ==========
                                      Programs
                                      ==========

                                      Adobe
                                      Alwil Software
                                      Apple Software Update
                                      Atheros
                                      BitDefender
                                      BlazeVideo
                                      Camera Assistant Software for Toshiba
                                      Canon
                                      CanonBJ
                                      Common Files
                                      CS
                                      desktop.ini
                                      DivX
                                      eMule
                                      Fichiers communs
                                      Google
                                      IDM
                                      InstallShield Installation Information
                                      Intel
                                      Internet Explorer
                                      InterVideo
                                      Java
                                      K-Lite Codec Pack
                                      List_Kill'em
                                      ltmoh
                                      Malwarebytes' Anti-Malware
                                      Microsoft
                                      Microsoft CAPICOM 2.1.0.2
                                      Microsoft Games
                                      Microsoft Office
                                      Microsoft Silverlight
                                      Microsoft SQL Server Compact Edition
                                      Microsoft Sync Framework
                                      Microsoft Works
                                      Microsoft.NET
                                      Movie Maker
                                      MSBuild
                                      MSN
                                      MSXML 4.0
                                      My Company Name
                                      myphotobook
                                      OrangeHSS
                                      QuickTime
                                      Realtek
                                      Reference Assemblies
                                      ScanSoft
                                      Securitoo
                                      Sony Ericsson
                                      Synaptics
                                      TOSHIBA
                                      trend micro
                                      Ulead Systems
                                      Uninstall Information
                                      Windows Calendar
                                      Windows Collaboration
                                      Windows Defender
                                      Windows Journal
                                      Windows Live
                                      Windows Live SkyDrive
                                      Windows Mail
                                      Windows Media Components
                                      Windows Media Player
                                      Windows NT
                                      Windows Photo Gallery
                                      Windows Sidebar
                                      WinRAR
                                      WinZip

                                      ============
                                      Drive C:
                                      ============

                                      $Recycle.Bin
                                      autoexec.bat
                                      autorun.inf
                                      Boot
                                      bootmgr
                                      BOOTSECT.BAK
                                      config.sys
                                      Documents and Settings
                                      Intel
                                      IO.SYS
                                      Kill'em
                                      List'em.txt
                                      MSDOS.SYS
                                      MSOCache
                                      pagefile.sys
                                      Program Files
                                      ProgramData
                                      RHDSetup.log
                                      rsit
                                      SWSTAMP.TXT
                                      System Volume Information
                                      Toshiba
                                      UsbFix
                                      UsbFix.txt
                                      UsbFix_Upload_Me_PC-de-ginie.zip
                                      Users
                                      Windows
                                      _wdsuef.dmp

                                      ¤¤¤¤¤¤¤¤¤¤ Cracks | Keygens | Serials

                                      ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤( EOF )¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤

                                      End of scan : 12:13:40,95
                                      0
                                      1. Pour info : le virus est encore détecté par avast, et même window defender se lance maintenant. Je lance la manip 2.
                                        0
                                        1. voilà le rapport de la 2ème manip :

                                          Kill'em by g3n-h@ckm@n 1.2.5.0

                                          User : ginie (Administrateurs)
                                          Update on 08/02/2010 by g3n-h@ckm@n ::::: 15.30
                                          Start at: 12:24:24 | 13/02/2010
                                          Contact : https://forums.commentcamarche.net/forum/virus-securite-7

                                          Intel(R) Pentium(R) Dual CPU T2310 @ 1.46GHz
                                          Microsoft® Windows Vista™ Édition Familiale Premium (6.0.6000 32-bit) #
                                          Internet Explorer 7.0.6000.16982
                                          Windows Firewall Status : Disabled
                                          AV : Antivirus BitDefender 12.0 [ (!) Disabled | (!) Outdated ]
                                          AV : avast! Antivirus 5.0.83886476 [ Enabled | Updated ]

                                          C:\ -> Disque fixe local | 74,52 Go (4,7 Go free) [Vista] | NTFS
                                          E:\ -> Disque fixe local | 73,06 Go (72,88 Go free) [Data] | NTFS
                                          F:\ -> Disque CD-ROM

                                          ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Processes running

                                          C:\Windows\System32\smss.exe
                                          C:\Windows\system32\csrss.exe
                                          C:\Windows\system32\wininit.exe
                                          C:\Windows\system32\csrss.exe
                                          C:\Windows\system32\services.exe
                                          C:\Windows\system32\lsass.exe
                                          C:\Windows\system32\lsm.exe
                                          C:\Windows\system32\winlogon.exe
                                          C:\Windows\system32\svchost.exe
                                          C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
                                          C:\Windows\system32\svchost.exe
                                          C:\Windows\System32\svchost.exe
                                          C:\Windows\System32\svchost.exe
                                          C:\Windows\System32\svchost.exe
                                          C:\Windows\system32\svchost.exe
                                          C:\Windows\system32\AUDIODG.EXE
                                          C:\Windows\system32\SLsvc.exe
                                          C:\Windows\system32\svchost.exe
                                          C:\Windows\system32\svchost.exe
                                          C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
                                          C:\Windows\System32\spoolsv.exe
                                          C:\Windows\system32\svchost.exe
                                          C:\Windows\system32\agrsmsvc.exe
                                          C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
                                          C:\PROGRA~1\COMMON~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
                                          C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
                                          C:\Program Files\Google\Update\GoogleUpdate.exe
                                          C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE
                                          C:\Windows\system32\svchost.exe
                                          C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
                                          C:\Windows\system32\svchost.exe
                                          C:\Windows\system32\TODDSrv.exe
                                          C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe
                                          C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
                                          C:\Windows\System32\svchost.exe
                                          C:\Windows\system32\SearchIndexer.exe
                                          C:\Windows\system32\taskeng.exe
                                          C:\Windows\system32\Dwm.exe
                                          C:\Windows\system32\taskeng.exe
                                          C:\Windows\Explorer.EXE
                                          C:\Program Files\TOSHIBA\Utilities\KeNotify.exe
                                          C:\Windows\RtHDVCpl.exe
                                          C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe
                                          C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe
                                          C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe
                                          C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe
                                          C:\Program Files\TOSHIBA\Toshiba Online Product Information\TOPI.exe
                                          C:\Windows\System32\igfxtray.exe
                                          C:\Windows\System32\hkcmd.exe
                                          C:\Windows\System32\igfxpers.exe
                                          C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe
                                          C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
                                          C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe
                                          C:\Program Files\Java\jre6\bin\jusched.exe
                                          C:\Program Files\ScanSoft\OmniPageSE4\OpWareSE4.exe
                                          C:\Program Files\Alwil Software\Avast5\AvastUI.exe
                                          C:\Program Files\Windows Sidebar\sidebar.exe
                                          C:\Windows\system32\igfxsrvc.exe
                                          C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe
                                          C:\Windows\ehome\ehtray.exe
                                          C:\Program Files\BlazeVideo\BlazeDTV 2.5a\MediaDetector.exe
                                          C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                                          C:\Program Files\Windows Media Player\wmpnscfg.exe
                                          C:\Program Files\WinZip\WZQKPICK.EXE
                                          C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
                                          C:\Program Files\Camera Assistant Software for Toshiba\CEC_MAIN.exe
                                          C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                                          C:\Windows\ehome\ehmsas.exe
                                          C:\Program Files\Windows Media Player\wmpnetwk.exe
                                          C:\Program Files\Synaptics\SynTP\SynToshiba.exe
                                          C:\Program Files\TOSHIBA\ConfigFree\CFSwMgr.exe
                                          C:\PROGRA~1\COMMON~1\France Telecom\Shared Modules\AlertModule\0\AlertModule.exe
                                          C:\Program Files\OrangeHSS\systray\systrayapp.exe
                                          C:\Windows\system32\wuauclt.exe
                                          C:\Program Files\Windows Live\Toolbar\wltuser.exe
                                          C:\Windows\system32\conime.exe
                                          C:\Windows\system32\SearchProtocolHost.exe
                                          C:\Windows\system32\SearchFilterHost.exe
                                          C:\Program Files\List_Kill'em\List_Kill'em.scr
                                          C:\Windows\system32\cmd.exe
                                          C:\Windows\system32\wbem\wmiprvse.exe
                                          C:\Users\ginie\AppData\Local\Temp\A14F.tmp\ERUNT.EXE
                                          C:\Users\ginie\AppData\Local\Temp\A14F.tmp\pv.exe

                                          Detections :
                                          ==========

                                          ¤¤¤¤¤¤¤¤¤¤ Files/folders :

                                          Quarantined & Deleted !! : C:\Windows\System32\drivers\etc\hosts.msn
                                          Quarantined & Deleted !! : C:\Users\ginie\Local Settings\Temp\00.IFO
                                          Quarantined & Deleted !! : C:\Users\ginie\Local Settings\Temp\01.IFO
                                          Quarantined & Deleted !! : C:\Users\ginie\Local Settings\Temp\reg.xml
                                          Quarantined & Deleted !! : C:\Users\ginie\Local Settings\Temp\WAB.log
                                          Quarantined & Deleted !! : C:\Users\ginie\LOCAL Settings\Temp\igraal.exe
                                          Quarantined & Deleted !! : C:\Users\ginie\LOCAL Settings\Temp\ose00000.exe
                                          Quarantined & Deleted !! : C:\Users\ginie\LOCAL Settings\Temp\QuickZip-5.0.0.10-Beta.exe
                                          Quarantined & Deleted !! : C:\Users\ginie\LOCAL Settings\Temp\album9005402838156912197.dat

                                          ==============
                                          host file OK !
                                          ==============

                                          ========
                                          Registry
                                          ========

                                          Deleted : HKLM\SYSTEM\ControlSet002\Services\SfX
                                          Deleted : HKLM\SYSTEM\ControlSet003\Services\SfX
                                          Deleted : HKLM\SYSTEM\ControlSet004\Services\SfX
                                          ========
                                          Services
                                          =========

                                          Ndisuio : Start = 3
                                          EapHost : Start = 2
                                          Wlansvc : Start = 2
                                          SharedAccess : Start = 2
                                          windefend : Start = 2
                                          wuauserv : Start = 2
                                          wscsvc : Start = 2

                                          ============
                                          Disk Cleaned
                                          ============

                                          =================
                                          anti-ver blaster : OK !!
                                          =================

                                          ================
                                          Prefetch cleaned
                                          ================

                                          ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤( EOF )¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
                                          0
                                          • 1
                                          • 2
                                          • 3