Disque dur

bonjours a plusieurs reprise j'ai tenté de verifié l'intégralité du volume de mon disque dur après redémarrage le conteur de 10 seconde s'affiche en proposant d'attendre le débit des seconde ou de taper sur une touche pour sauter la vérification du disque !! problème les secondes ne bouge pas et reste a 10 j'ai attendu jusqu'a 30 mn mais rien ne se produit donc je fini par sauter l'analyse !! j'ai fait un scan avec avast puis Mawarebyte's anti- malware , une defragmentation, un nettoyage du disque!! sachant aussi que mon curseur se met a clignoter en connection et hors connection et me plante la page sur laquelle je travail il faut souvent que je retente a plusieur reprise pour taper un message de plus j'ai skype et msn les conversation vidéo ne tiennent pas plus d'une minute après ça coupe ......si vous connaissez la solution a mes problèmes ça serait super car j'ai déjà tenté pas mal de chose s'en succés!! merci d'avance

7 réponses

Résumé de la discussion

Le fil décrit des symptômes de dysfonctionnement au démarrage, avec une vérification du volume du disque dur bloquée à 10 secondes et un curseur qui clignote, des plantages lors des conversations Skype ou MSN. Plusieurs réponses recommandent des analyses antivirus et anti-malware (Avast, Malwarebytes) et l’utilisation d’outils de nettoyage (ToolsCleaner, HijackThis, RSIT) pour détecter et supprimer des programmes malveillants ou des comportements suspects. Les conseils préconisent de mettre à jour et lancer un scan complet, puis de vérifier les rapports et supprimer les éléments détectés, avec redémarrage si nécessaire. Des rapports détaillent les éléments trouvés dans les répertoires et le registre, aidant à cibler les actions sur les navigateurs, les processus et les programmes de démarrage.

Bobot (l’IA à votre service)
  1. Contributeur sécurité
    salut
    Télécharge ici :

    http://images.malwareremoval.com/random/RSIT.exe

    random's system information tool (RSIT) par andom/random et sauvegarde-le sur le Bureau.

    Double-clique sur RSIT.exe afin de lancer RSIT.

    Clique Continue à l'écran Disclaimer.

    Si l'outil HijackThis (version à jour) n'est pas présent ou non détecté sur l'ordinateur, RSIT le téléchargera (autorise l'accès dans ton pare-feu, si demandé) et tu devras accepter la licence.

    Lorsque l'analyse sera terminée, deux fichiers texte s'ouvriront.

    Poste le contenu de log.txt (<<qui sera affiché)
    ainsi que de info.txt (<<qui sera réduit dans la Barre des Tâches).

    NB : Les rapports sont sauvegardés dans le dossier C:\rsit

    Tutoriel pour t'aider

    https://forum.pcastuces.com/randoms_system_information_tool_rsit-f31s31.htm
    1. voici le résultat du scan (merci pour ton intervention)

      Logfile of random's system information tool 1.06 (written by random/random)
      Run by virginie at 2010-03-26 20:16:56
      Microsoft® Windows Vista(TM) Édition Familiale Basique Service Pack 2
      System drive C: has 28 GB (39%) free of 71 GB
      Total RAM: 1976 MB (47% free)

      Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 20:17:17, on 26/03/2010
      Platform: Windows Vista SP2 (WinNT 6.00.1906)
      MSIE: Internet Explorer v8.00 (8.00.6001.18882)
      Boot mode: Normal

      Running processes:
      C:\Windows\system32\Dwm.exe
      C:\Windows\Explorer.EXE
      C:\Program Files\Windows Defender\MSASCui.exe
      C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
      C:\Windows\System32\igfxtray.exe
      C:\Windows\System32\hkcmd.exe
      C:\Windows\System32\igfxpers.exe
      C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
      C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
      C:\Program Files\Java\jre6\bin\jusched.exe
      C:\Program Files\Alwil Software\Avast5\AvastUI.exe
      C:\Windows\System32\p2phost.exe
      C:\Program Files\Windows Live\Messenger\msnmsgr.exe
      C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
      C:\Program Files\Skype\Phone\Skype.exe
      C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
      C:\Windows\system32\taskeng.exe
      C:\Windows\system32\igfxsrvc.exe
      C:\Program Files\Skype\Plugin Manager\skypePM.exe
      C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
      C:\Windows\system32\wbem\unsecapp.exe
      C:\Program Files\Windows Media Player\wmpnscfg.exe
      C:\Windows\system32\taskeng.exe
      C:\Users\virginie\AppData\Local\Google\Chrome\Application\chrome.exe
      C:\Users\virginie\AppData\Local\Google\Chrome\Application\chrome.exe
      C:\Users\virginie\AppData\Local\Google\Chrome\Application\chrome.exe
      C:\Users\virginie\Documents\Downloads\RSIT.exe
      C:\Windows\system32\SearchFilterHost.exe
      C:\Program Files\trend micro\virginie.exe

      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.acer-group.com/selection.html?b=ACEW&l=040c&s=2&o=vb32&d=0309&m=emg520
      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.theprizeday.com/today.php
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.acer-group.com/selection.html?b=ACEW&l=040c&s=2&o=vb32&d=0309&m=emg520
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.tropal.net/
      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
      R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
      O1 - Hosts: ::1 localhost
      O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
      O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
      O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
      O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live ID - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
      O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
      O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.5.4723.1820\swg.dll
      O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
      O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
      O3 - Toolbar: SYSTRAN Web Translator 5.0 - {A5899B52-3AF9-4F56-85FE-AD7B3BE8490F} - C:\Program Files\SYSTRAN\5.0\Personal\IEPlugIn.dll
      O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
      O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
      O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
      O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
      O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
      O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
      O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
      O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
      O4 - HKLM\..\Run: [WarReg_PopUp] C:\Program Files\eMachines\WR_PopUp\WarReg_PopUp.exe
      O4 - HKLM\..\Run: [QuickTime Plugin Install] C:\Program Files\QuickTime\Plugins\DeleteMe1.exe
      O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
      O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
      O4 - HKLM\..\Run: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe
      O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
      O4 - HKLM\..\Run: [avast5] C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe /nogui
      O4 - HKCU\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
      O4 - HKCU\..\Run: [CollaborationHost] C:\Windows\system32\p2phost.exe -s
      O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
      O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
      O4 - HKCU\..\Run: [Google Update] "C:\Users\virginie\AppData\Local\Google\Update\GoogleUpdate.exe" /c
      O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
      O4 - HKCU\..\Run: [Uniblue RegistryBooster 2] c:\program files\uniblue\registrybooster 2\StartRegistryBooster.exe
      O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
      O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
      O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
      O4 - Startup: OneNote 2007 - Capture d'écran et lancement.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
      O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
      O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
      O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
      O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
      O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
      O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
      O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
      O13 - Gopher Prefix:
      O16 - DPF: CabBuilder - http://kiw.imgag.com/imgag/kiw/toolbar/download/InstallerControl.cab
      O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/MessengerGamesContent/GameContent/fr/uno1/GAME_UNO1.cab
      O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
      O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
      O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
      O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
      O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
      O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
      O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
      O23 - Service: Empowering Technology Service (ETService) - Unknown owner - C:\Program Files\EMACHINES\eMachines Recovery Management\Service\ETService.exe
      O23 - Service: Google Desktop Manager 5.9.911.3589 (GoogleDesktopManager-110309-193829) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
      O23 - Service: Service Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
      O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
      O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
      O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
      1. 2ème rapport

        info.txt logfile of random's system information tool 1.06 2010-03-26 20:17:23

        ======Uninstall list======

        -->"C:\Program Files\InstallShield Installation Information\{8F1B6239-FEA0-450A-A950-B05276CE177C}\setup.exe" -runfromtemp -l0x040c -removeonly
        Acrobat.com-->C:\Program Files\Common Files\Adobe AIR\Versions\1.0\Adobe AIR Application Installer.exe -uninstall com.adobe.mauby 4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
        Acrobat.com-->MsiExec.exe /I{77DCDCE3-2DED-62F3-8154-05E745472D07}
        Adobe AIR-->C:\Program Files\Common Files\Adobe AIR\Versions\1.0\Adobe AIR Updater.exe -arp:uninstall
        Adobe AIR-->MsiExec.exe /I{00203668-8170-44A0-BE44-B632FA4D780F}
        Adobe Flash Player 10 ActiveX-->C:\Windows\system32\Macromed\Flash\uninstall_activeX.exe
        Adobe Flash Player 10 Plugin-->C:\Windows\system32\Macromed\Flash\uninstall_plugin.exe
        Adobe Flash Player 9 ActiveX-->C:\Windows\system32\Macromed\Flash\UninstFl.exe -q
        Adobe Reader 9.2-->MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A92000000001}
        ADS Tech Master Installer V3.5-->C:\PROGRA~1\ADSTech\UNWISE.EXE C:\PROGRA~1\ADSTech\INSTALL.LOG
        ADS Tech V3.5 DVD Xpress CapWiz-->C:\PROGRA~1\ADSTEC~1\UNWISE.EXE C:\PROGRA~1\ADSTEC~1\INSTALL.LOG
        Apple Application Support-->MsiExec.exe /I{3FA365DF-2D68-45ED-8F83-8C8A33E65143}
        Apple Software Update-->MsiExec.exe /I{6956856F-B6B3-4BE0-BA0B-8F495BE32033}
        Assistant de connexion Windows Live ID-->MsiExec.exe /X{10A44844-4465-456E-8C97-80BDD4F68845}
        avast! Free Antivirus-->C:\Program Files\Alwil Software\Avast5\aswRunDll.exe "C:\Program Files\Alwil Software\Avast5\Setup\setiface.dll" RunSetup
        Bonjour-->MsiExec.exe /I{07287123-B8AC-41CE-8346-3D777245C35B}
        Broadcom Gigabit Integrated Controller-->MsiExec.exe /X{F870B987-18BC-45FC-9BE8-35C02DCDA10F}
        Codeur Windows Media Série 9-->msiexec.exe /I {E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}
        Codeur Windows Media Série 9-->MsiExec.exe /I{E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}
        Dessinateur Studio-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{843FF85B-ACD5-4E9E-8F82-5E6D5C4105D6}\SETUP.EXE"
        DivX Plus Web Player-->C:\Program Files\DivX\DivXWebPlayerUninstall.exe /PLUGIN
        eMachines Recovery Management-->"C:\Program Files\InstallShield Installation Information\{7F811A54-5A09-4579-90E1-C93498E230D9}\setup.exe" -runfromtemp -l0x040c -removeonly
        eMachines ScreenSaver-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{79DD56FC-DB8B-47F5-9C80-78B62E05F9BC}\setup.exe" -l0x9 -removeonly
        eMachines-->"C:\Program Files\Oberon Media\eMachines\Uninstall.exe" "C:\Program Files\Oberon Media\eMachines\install.log"
        Favorit-->c:\users\virginie\appdata\local\qsvybea.bat
        Galerie de photos Windows Live-->MsiExec.exe /X{B131E59D-202C-43C6-84C9-68F0C37541F1}
        Google Desktop-->C:\Program Files\Google\Google Desktop Search\GoogleDesktopSetup.exe -uninstall
        Google Toolbar for Internet Explorer-->"C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarManager_E85CDE7661A53A6A.exe" /uninstall
        Google Toolbar for Internet Explorer-->MsiExec.exe /I{18455581-E099-4BA8-BC6B-F34B2F06600C}
        Google Update Helper-->MsiExec.exe /I{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}
        HijackThis 2.0.2-->"C:\Program Files\trend micro\HijackThis.exe" /uninstall
        Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)-->C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall /qb+ REBOOTPROMPT=""
        Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)-->C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {A7EEA2F2-BFCD-4A54-A575-7B81A786E658} /qb+ REBOOTPROMPT=""
        Installation Windows Live-->C:\Program Files\Windows Live\Installer\wlarp.exe
        Installation Windows Live-->MsiExec.exe /I{46ABBC54-1872-4AA3-95E2-F2C063A63F31}
        Intel(R) Graphics Media Accelerator Driver-->C:\Windows\system32\igxpun.exe -uninstall
        Intel® Matrix Storage Manager-->C:\Program Files\Intel\Intel Matrix Storage Manager\Uninstall\imsmudlg.exe -uninstall
        Java(TM) 6 Update 17-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216017FF}
        Junk Mail filter update-->MsiExec.exe /I{E2DFE069-083E-4631-9B6C-43C48E991DE5}
        Malwarebytes' Anti-Malware-->"C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
        Microsoft .NET Framework 3.5 Language Pack SP1 - fra-->MsiExec.exe /I{3E31821C-7917-367E-938E-E65FC413EA31}
        Microsoft .NET Framework 3.5 SP1-->C:\Windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setup.exe
        Microsoft .NET Framework 3.5 SP1-->MsiExec.exe /I{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}
        Microsoft Choice Guard-->MsiExec.exe /X{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}
        Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0016-040C-0000-0000000FF1CE} /uninstall {AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
        Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0018-040C-0000-0000000FF1CE} /uninstall {AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
        Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001B-040C-0000-0000000FF1CE} /uninstall {AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
        Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-006E-040C-0000-0000000FF1CE} /uninstall {B165D3C2-40AE-4D39-86F7-E5C87C4264C0}
        Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-00A1-040C-0000-0000000FF1CE} /uninstall {AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
        Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}
        Microsoft Office Excel MUI (French) 2007-->MsiExec.exe /X{90120000-0016-040C-0000-0000000FF1CE}
        Microsoft Office Home and Student 2007-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE12\Office Setup Controller\setup.exe" /uninstall HOMESTUDENTR /dll OSETUP.DLL
        Microsoft Office Home and Student 2007-->MsiExec.exe /X{91120000-002F-0000-0000-0000000FF1CE}
        Microsoft Office Live Add-in 1.4-->MsiExec.exe /I{AE3CF174-872C-46C6-B9F6-C0593F3BC7B8}
        Microsoft Office OneNote MUI (French) 2007-->MsiExec.exe /X{90120000-00A1-040C-0000-0000000FF1CE}
        Microsoft Office PowerPoint MUI (French) 2007-->MsiExec.exe /X{90120000-0018-040C-0000-0000000FF1CE}
        Microsoft Office PowerPoint Viewer 2007 (French)-->MsiExec.exe /X{95120000-00AF-040C-0000-0000000FF1CE}
        Microsoft Office Proof (Arabic) 2007-->MsiExec.exe /X{90120000-001F-0401-0000-0000000FF1CE}
        Microsoft Office Proof (Dutch) 2007-->MsiExec.exe /X{90120000-001F-0413-0000-0000000FF1CE}
        Microsoft Office Proof (English) 2007-->MsiExec.exe /X{90120000-001F-0409-0000-0000000FF1CE}
        Microsoft Office Proof (French) 2007-->MsiExec.exe /X{90120000-001F-040C-0000-0000000FF1CE}
        Microsoft Office Proof (German) 2007-->MsiExec.exe /X{90120000-001F-0407-0000-0000000FF1CE}
        Microsoft Office Proof (Spanish) 2007-->MsiExec.exe /X{90120000-001F-0C0A-0000-0000000FF1CE}
        Microsoft Office Proofing (French) 2007-->MsiExec.exe /X{90120000-002C-040C-0000-0000000FF1CE}
        Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0401-0000-0000000FF1CE} /uninstall {14809F99-C601-4D4A-9391-F1E8FAA964C5}
        Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0407-0000-0000000FF1CE} /uninstall {A0516415-ED61-419A-981D-93596DA74165}
        Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0409-0000-0000000FF1CE} /uninstall {ABDDE972-355B-4AF1-89A8-DA50B7B5C045}
        Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-040C-0000-0000000FF1CE} /uninstall {F580DDD5-8D37-4998-968E-EBB76BB86787}
        Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0413-0000-0000000FF1CE} /uninstall {D66D5A44-E480-4BA4-B4F2-C554F6B30EBB}
        Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0C0A-0000-0000000FF1CE} /uninstall {187308AB-5FA7-4F14-9AB9-D290383A10D9}
        Microsoft Office Shared MUI (French) 2007-->MsiExec.exe /X{90120000-006E-040C-0000-0000000FF1CE}
        Microsoft Office Suite Activation Assistant-->MsiExec.exe /X{E50AE784-FABE-46DA-A1F8-7B6B56DCB22E}
        Microsoft Office Word MUI (French) 2007-->MsiExec.exe /X{90120000-001B-040C-0000-0000000FF1CE}
        Microsoft Search Enhancement Pack-->MsiExec.exe /X{4CBA3D4C-8F51-4D60-B27E-F6B641C571E7}
        Microsoft Silverlight-->MsiExec.exe /X{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
        Microsoft SQL Server 2005 Compact Edition [ENU]-->MsiExec.exe /I{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}
        Microsoft Sync Framework Runtime Native v1.0 (x86)-->MsiExec.exe /I{8A74E887-8F0F-4017-AF53-CBA42211AAA5}
        Microsoft Sync Framework Services Native v1.0 (x86)-->MsiExec.exe /I{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}
        Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053-->MsiExec.exe /X{770657D0-A123-3C07-8E44-1C83EC895118}
        Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
        Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{A49F249F-0C91-497F-86DF-B2585E8E76B7}
        Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148-->MsiExec.exe /X{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}
        Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17-->MsiExec.exe /X{9A25302D-30C0-39D9-BD6F-21E6EC160475}
        Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148-->MsiExec.exe /X{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}
        Microsoft Works-->MsiExec.exe /I{0214A441-A4AB-43A8-8DEF-2F73C5364673}
        Mise à jour Microsoft Office Excel 2007 Help (KB963678)-->msiexec /package {90120000-0016-040C-0000-0000000FF1CE} /uninstall {B761869A-B85C-40E2-994C-A1CE78AC8F2C}
        Mise à jour Microsoft Office Powerpoint 2007 Help (KB963669)-->msiexec /package {90120000-0018-040C-0000-0000000FF1CE} /uninstall {C3DCA38E-005E-41BA-A52A-7C3429F351C3}
        Mise à jour Microsoft Office Word 2007 Help (KB963665)-->msiexec /package {90120000-001B-040C-0000-0000000FF1CE} /uninstall {81536A04-DBFB-4DB3-978F-0F284590C223}
        Module de compatibilité pour Microsoft Office System 2007-->MsiExec.exe /X{90120000-0020-040C-0000-0000000FF1CE}
        Module linguistique Microsoft .NET Framework 3.5 SP1- fra-->C:\Windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 Language Pack SP1 - fra\setup.exe
        Mozilla Firefox (3.6.2pre)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
        MSVCRT-->MsiExec.exe /I{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}
        MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
        MSXML 4.0 SP2 (KB973688)-->MsiExec.exe /I{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}
        Mystery Solitaire - Secret Island-->"C:\Program Files\eMachines GameZone\Mystery Solitaire - Secret Island\Uninstall.exe" "C:\Program Files\eMachines GameZone\Mystery Solitaire - Secret Island\install.log"
        Nathan Mathématiques CP-->C:\Program Files\Nathan\Mathematiques CP\Uninstal.exe
        OGA Notifier 2.0.0048.0-->MsiExec.exe /I{B2544A03-10D0-4E5E-BA69-0362FFC20D18}
        Outil de téléchargement Windows Live-->MsiExec.exe /I{205C6BDD-7B73-42DE-8505-9A093F35A238}
        Outlook Express Quick Backup-->C:\WINDOWS\st6unst.exe -n "C:\Program Files\Outlook Express Quick Backup\ST6UNST.LOG"
        QuickTime-->MsiExec.exe /I{1451DE6B-ABE1-4F62-BE9A-B363A17588A2}
        Security Update for 2007 Microsoft Office System (KB969559)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {69F52148-9BF6-4CDC-BF76-103DEAF3DD08}
        Security Update for 2007 Microsoft Office System (KB978380)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {667A88D1-0369-4070-A62A-70672D68A9BF}
        Security Update for Microsoft Office Excel 2007 (KB978382)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {6DE3DABF-0203-426B-B330-7287D1003E86}
        Security Update for Microsoft Office PowerPoint 2007 (KB957789)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {7559E742-FF9F-4FAE-B279-008ED296CB4D}
        Security Update for Microsoft Office system 2007 (972581)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {3D019598-7B59-447A-80AE-815B703B84FF}
        Security Update for Microsoft Office system 2007 (KB969613)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {5ECEB317-CBE9-4E08-AB10-756CB6F0FB6C}
        Security Update for Microsoft Office system 2007 (KB974234)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {FCD742B9-7A55-44BC-A776-F795F21FEDDC}
        Security Update for Microsoft Office Visio Viewer 2007 (KB973709)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {71127777-8B2C-4F97-AF7A-6CF8CAC8224D}
        Security Update for Windows Media Encoder (KB954156)-->msiexec.exe /I {E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E} MSIPATCHREMOVE={E836F1B7-43FB-46B0-A0D9-E4D2A5951659} /qb
        Skype web features-->MsiExec.exe /I{541DEAC0-5F3D-45E6-B7CB-94ECF3B96748}
        Skype(TM) 4.1-->MsiExec.exe /X{D103C4BA-F905-437A-8049-DB24763BBE36}
        SoftwareUpdate 1.0-->"C:\Users\virginie\AppData\Roaming\eoRezo\SoftwareUpdate\unins000.exe"
        Synaptics Pointing Device Driver-->rundll32.exe "%ProgramFiles%\Synaptics\SynTP\SynISDLL.dll",standAloneUninstall
        SYSTRAN Web Translator 5.0-->MsiExec.exe /I{E0B38894-0E4D-4AE1-B17E-CFBC3692E86A}
        Ulead Straight-to-Disc SDK-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{8D2C1E44-7685-4D05-8342-B0DC6422FA47}\setup.exe" -l0x9
        Update for 2007 Microsoft Office System (KB967642)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {C444285D-5E4F-48A4-91DD-47AAAA68E92D}
        Update for 2007 Microsoft Office System (KB977724)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {CC0E469C-5006-48B9-BBDC-D11B562499B4}
        Update for Microsoft .NET Framework 3.5 SP1 (KB963707)-->C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {B2AE9C82-DC7B-3641-BFC8-87275C4F3607} /qb+ REBOOTPROMPT=""
        Update for Microsoft Office InfoPath 2007 (KB976416)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {432C5EE4-8096-4FF1-95E1-65219365DFF7}
        Update for Microsoft Office Word 2007 (KB974561)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {0CDDBAA2-2111-4A0E-A1B0-76C40C635331}
        VC80CRTRedist - 8.0.50727.4053-->MsiExec.exe /I{5EE7D259-D137-4438-9A5F-42F432EC0421}
        VLC media player 0.9.9-->C:\Program Files\VideoLAN\VLC\uninstall.exe
        Windows Live Call-->MsiExec.exe /I{82C7B308-0BDD-49D8-8EA5-9CD3A3F9DF41}
        Windows Live Communications Platform-->MsiExec.exe /I{3B4E636E-9D65-4D67-BA61-189800823F52}
        Windows Live Contrôle parental-->MsiExec.exe /X{D5D81435-B8DE-4CAF-867F-7998F2B92CFC}
        Windows Live FolderShare-->MsiExec.exe /X{2075CB0A-D26F-4DAA-B424-5079296B43BA}
        Windows Live Mail-->MsiExec.exe /I{5DD76286-9BE7-4894-A990-E905E91AC818}
        Windows Live Messenger-->MsiExec.exe /X{770F1BEC-2871-4E70-B837-FB8525FFA3B1}
        Windows Live Toolbar-->MsiExec.exe /X{F7D27C70-90F5-49B9-B188-0A133C0CE353}
        Windows Live Writer-->MsiExec.exe /X{4634B21A-CC07-4396-890C-2B8168661FEA}
        Windows Media Player Firefox Plugin-->MsiExec.exe /I{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}

        ======Security center information======

        AS: Windows Defender

        ======System event log======

        Computer Name: PC-de-virginie
        Event Code: 4001
        Message: Le Service d'autoconfiguration WLAN s'est arrêté correctement.

        Record Number: 120662
        Source Name: Microsoft-Windows-WLAN-AutoConfig
        Time Written: 20091112013119.640266-000
        Event Type: Avertissement
        User: AUTORITE NT\SYSTEM

        Computer Name: PC-de-virginie
        Event Code: 10002
        Message: Le module d'extensibilité WLAN s'est arrêté.

        Chemin d'accès du module : C:\Windows\System32\bcmihvsrv.dll

        Record Number: 120658
        Source Name: Microsoft-Windows-WLAN-AutoConfig
        Time Written: 20091112013117.487466-000
        Event Type: Avertissement
        User: AUTORITE NT\SYSTEM

        Computer Name: PC-de-virginie
        Event Code: 2505
        Message: Le serveur n'a pas pu se lier au transport \Device\NetbiosSmb car un autre ordinateur du réseau porte le même nom. Le serveur n'a pas pu démarrer.
        Record Number: 120625
        Source Name: Server
        Time Written: 20091111233844.000000-000
        Event Type: Erreur
        User:

        Computer Name: PC-de-virginie
        Event Code: 7026
        Message: Le pilote de démarrage système ou d'amorçage suivant n'a pas pu se charger :
        PxHelp20
        Record Number: 120576
        Source Name: Service Control Manager
        Time Written: 20091111174657.000000-000
        Event Type: Erreur
        User:

        Computer Name: PC-de-virginie
        Event Code: 7000
        Message: Le service ADS DVD Xpress B n'a pas pu démarrer en raison de l'erreur :
        Le service ne peut pas être démarré parce qu'il est désactivé ou qu'aucun périphérique activé ne lui est associé.
        Record Number: 120502
        Source Name: Service Control Manager
        Time Written: 20091111174657.000000-000
        Event Type: Erreur
        User:

        =====Application event log=====

        Computer Name: PC-de-virginie
        Event Code: 33
        Message: La création du contexte d'activation a échoué pour « C:\Windows\Installer\{0214A441-A4AB-43A8-8DEF-2F73C5364673}\WksCal.exe ». Assembly dépendant msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0" introuvable. Utilisez sxstrace.exe pour un diagnostic détaillé.
        Record Number: 782
        Source Name: SideBySide
        Time Written: 20090607171619.000000-000
        Event Type: Erreur
        User:

        Computer Name: PC-de-virginie
        Event Code: 33
        Message: La création du contexte d'activation a échoué pour « C:\Windows\Installer\{0214A441-A4AB-43A8-8DEF-2F73C5364673}\wksdb.exe ». Assembly dépendant msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0" introuvable. Utilisez sxstrace.exe pour un diagnostic détaillé.
        Record Number: 781
        Source Name: SideBySide
        Time Written: 20090607171619.000000-000
        Event Type: Erreur
        User:

        Computer Name: PC-de-virginie
        Event Code: 33
        Message: La création du contexte d'activation a échoué pour « C:\Windows\Installer\{0214A441-A4AB-43A8-8DEF-2F73C5364673}\wksdb.exe ». Assembly dépendant msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0" introuvable. Utilisez sxstrace.exe pour un diagnostic détaillé.
        Record Number: 780
        Source Name: SideBySide
        Time Written: 20090607171619.000000-000
        Event Type: Erreur
        User:

        Computer Name: PC-de-virginie
        Event Code: 1008
        Message: Le service Windows Search tente de supprimer l'ancien catalogue.

        Record Number: 751
        Source Name: Microsoft-Windows-Search
        Time Written: 20090607000825.000000-000
        Event Type: Avertissement
        User:

        Computer Name: WIN-VHOZM2H90ZV
        Event Code: 10
        Message: Le filtre d'événement avec la requête « SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99 » n'a pas pu être réactivé dans l'espace de noms « //./root/CIMV2 » à cause de l'erreur 0x80041003. Les événements ne peuvent pas être délivrés à travers ce filtre tant que le problème ne sera pas corrigé.
        Record Number: 731
        Source Name: Microsoft-Windows-WMI
        Time Written: 20090312231632.000000-000
        Event Type: Erreur
        User:

        =====Security event log=====

        Computer Name: PC-de-virginie
        Event Code: 4672
        Message: Privilèges spéciaux attribués à la nouvelle ouverture de session.

        Sujet :
        ID de sécurité : S-1-5-18
        Nom du compte : SYSTEM
        Domaine du compte : AUTORITE NT
        ID d'ouverture de session : 0x3e7

        Privilèges : SeAssignPrimaryTokenPrivilege
        SeTcbPrivilege
        SeSecurityPrivilege
        SeTakeOwnershipPrivilege
        SeLoadDriverPrivilege
        SeBackupPrivilege
        SeRestorePrivilege
        SeDebugPrivilege
        SeAuditPrivilege
        SeSystemEnvironmentPrivilege
        SeImpersonatePrivilege
        Record Number: 30693
        Source Name: Microsoft-Windows-Security-Auditing
        Time Written: 20091023195330.803698-000
        Event Type: Succès de l'audit
        User:

        Computer Name: PC-de-virginie
        Event Code: 4624
        Message: L'ouverture de session d'un compte s'est correctement déroulée.

        Sujet :
        ID de sécurité : S-1-5-18
        Nom du compte : PC-DE-VIRGINIE$
        Domaine du compte : WORKGROUP
        ID d'ouverture de session : 0x3e7

        Type d'ouverture de session : 5

        Nouvelle ouverture de session :
        ID de sécurité : S-1-5-18
        Nom du compte : SYSTEM
        Domaine du compte : AUTORITE NT
        ID d'ouverture de session : 0x3e7
        GUID d'ouverture de session : {00000000-0000-0000-0000-000000000000}

        Informations sur le processus :
        ID du processus : 0x25c
        Nom du processus : C:\Windows\System32\services.exe

        Informations sur le réseau :
        Nom de la station de travail :
        Adresse du réseau source : -
        Port source : -

        Informations détaillées sur l'authentification :
        Processus d'ouverture de session : Advapi
        Package d'authentification : Negotiate
        Services en transit : -
        Nom du package (NTLM uniquement) : -
        Longueur de la clé : 0

        Cet événement est généré lors de la création d'une ouverture de session. Il est généré sur l'ordinateur sur lequel l'ouverture de session a été effectuée.

        Le champ Objet indique le compte sur le système local qui a demandé l'ouverture de session. Il s'agit le plus souvent d'un service, comme le service Serveur, ou un processus local tel que Winlogon.exe ou Services.exe.

        Le champ Type d'ouverture de session indique le type d'ouverture de session qui s'est produit. Les types les plus courants sont 2 (interactif) et 3 (réseau).

        Le champ Nouvelle ouverture de session indique le compte pour lequel la nouvelle ouverture de session a été créée, par exemple, le compte qui s'est connecté.

        Les champs relatifs au réseau indiquent la provenance d'une demande d'ouverture de session à distance. Le nom de la station de travail n'étant pas toujours disponible, peut être laissé vide dans certains cas.

        Les champs relatifs aux informations d'authentification fournissent des détails sur cette demande d'ouverture de session spécifique.
        - Le GUID d'ouverture de session est un identificateur unique pouvant servir à associer cet événement à un événement KDC .
        - Les services en transit indiquent les services intermédiaires qui ont participé à cette demande d'ouverture de session.
        - Nom du package indique quel est le sous-protocole qui a été utilisé parmi les protocoles NTLM.
        - La longueur de la clé indique la longueur de la clé de session générée. Elle a la valeur 0 si aucune clé de session n'a été demandée.
        Record Number: 30692
        Source Name: Microsoft-Windows-Security-Auditing
        Time Written: 20091023195330.803698-000
        Event Type: Succès de l'audit
        User:

        Computer Name: PC-de-virginie
        Event Code: 4648
        Message: Tentative d'ouverture de session en utilisant des informations d'identification explicites.

        Sujet :
        ID de sécurité : S-1-5-18
        Nom du compte : PC-DE-VIRGINIE$
        Domaine du compte : WORKGROUP
        ID d'ouverture de session : 0x3e7
        GUID d'ouverture de session : {00000000-0000-0000-0000-000000000000}

        Compte dont les informations d'identification ont été utilisées :
        Nom du compte : SYSTEM
        Domaine du compte : AUTORITE NT
        GUID d'ouverture de session : {00000000-0000-0000-0000-000000000000}

        Serveur cible :
        Nom du serveur cible : localhost
        Informations supplémentaires : localhost

        Informations sur le processus :
        ID du processus : 0x25c
        Nom du processus : C:\Windows\System32\services.exe

        Informations sur le réseau :
        Adresse du réseau : -
        Port : -

        Cet événement est généré lorsqu'un processus tente d'ouvrir une session pour un compte en spécifiant explicitement les informations d'identification de ce compte. Ceci se produit le plus souvent dans les configurations par lot comme les tâches planifiées, ou avec l'utilisation de la commande RUNAS.
        Record Number: 30691
        Source Name: Microsoft-Windows-Security-Auditing
        Time Written: 20091023195330.803698-000
        Event Type: Succès de l'audit
        User:

        Computer Name: PC-de-virginie
        Event Code: 4902
        Message: La table de stratégie d'audit par utilisateur a été créée.

        Nombre d'éléments : 0
        ID de la stratégie : 0xe38c
        Record Number: 30690
        Source Name: Microsoft-Windows-Security-Auditing
        Time Written: 20091023195330.429295-000
        Event Type: Succès de l'audit
        User:

        Computer Name: PC-de-virginie
        Event Code: 4624
        Message: L'ouverture de session d'un compte s'est correctement déroulée.

        Sujet :
        ID de sécurité : S-1-0-0
        Nom du compte : -
        Domaine du compte : -
        ID d'ouverture de session : 0x0

        Type d'ouverture de session : 0

        Nouvelle ouverture de session :
        ID de sécurité : S-1-5-18
        Nom du compte : SYSTEM
        Domaine du compte : AUTORITE NT
        ID d'ouverture de session : 0x3e7
        GUID d'ouverture de session : {00000000-0000-0000-0000-000000000000}

        Informations sur le processus :
        ID du processus : 0x4
        Nom du processus :

        Informations sur le réseau :
        Nom de la station de travail : -
        Adresse du réseau source : -
        Port source : -

        Informations détaillées sur l'authentification :
        Processus d'ouverture de session : -
        Package d'authentification : -
        Services en transit : -
        Nom du package (NTLM uniquement) : -
        Longueur de la clé : 0

        Cet événement est généré lors de la création d'une ouverture de session. Il est généré sur l'ordinateur sur lequel l'ouverture de session a été effectuée.

        Le champ Objet indique le compte sur le système local qui a demandé l'ouverture de session. Il s'agit le plus souvent d'un service, comme le service Serveur, ou un processus local tel que Winlogon.exe ou Services.exe.

        Le champ Type d'ouverture de session indique le type d'ouverture de session qui s'est produit. Les types les plus courants sont 2 (interactif) et 3 (réseau).

        Le champ Nouvelle ouverture de session indique le compte pour lequel la nouvelle ouverture de session a été créée, par exemple, le compte qui s'est connecté.

        Les champs relatifs au réseau indiquent la provenance d'une demande d'ouverture de session à distance. Le nom de la station de travail n'étant pas toujours disponible, peut être laissé vide dans certains cas.

        Les champs relatifs aux informations d'authentification fournissent des détails sur cette demande d'ouverture de session spécifique.
        - Le GUID d'ouverture de session est un identificateur unique pouvant servir à associer cet événement à un événement KDC .
        - Les services en transit indiquent les services intermédiaires qui ont participé à cette demande d'ouverture de session.
        - Nom du package indique quel est le sous-protocole qui a été utilisé parmi les protocoles NTLM.
        - La longueur de la clé indique la longueur de la clé de session générée. Elle a la valeur 0 si aucune clé de session n'a été demandée.
        Record Number: 30689
        Source Name: Microsoft-Windows-Security-Auditing
        Time Written: 20091023195330.210894-000
        Event Type: Succès de l'audit
        User:

        ======Environment variables======

        "ComSpec"=%SystemRoot%\system32\cmd.exe
        "FP_NO_HOST_CHECK"=NO
        "OS"=Windows_NT
        "Path"=%CommonProgramFiles%\Microsoft Shared\Windows Live;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Program Files\Common Files\Ulead Systems\MPEG;C:\Program Files\Ulead Systems\Ulead DVD MovieFactory 3 SE;C:\Program Files\QuickTime\QTSystem\
        "PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC
        "PROCESSOR_ARCHITECTURE"=x86
        "TEMP"=%SystemRoot%\TEMP
        "TMP"=%SystemRoot%\TEMP
        "USERNAME"=SYSTEM
        "windir"=%SystemRoot%
        "PROCESSOR_LEVEL"=6
        "PROCESSOR_IDENTIFIER"=x86 Family 6 Model 15 Stepping 13, GenuineIntel
        "PROCESSOR_REVISION"=0f0d
        "NUMBER_OF_PROCESSORS"=1
        "TRACE_FORMAT_SEARCH_PATH"=\\NTREL202.ntdev.corp.microsoft.com\4F18C3A5-CA09-4DBD-B6FC-219FDD4C6BE0\TraceFormat
        "DFSTRACINGON"=FALSE
        "CLASSPATH"=.;C:\Program Files\Java\jre6\lib\ext\QTJava.zip
        "QTJAVA"=C:\Program Files\Java\jre6\lib\ext\QTJava.zip
        "NTIPath"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem

        -----------------EOF-----------------
        1. Contributeur sécurité
          bonjour

          Télécharge UsbFix de C_XX & Chiquitine29

          http://pagesperso-orange.fr/NosTools/Chiquitine29/UsbFix.exe

          (!) Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) susceptible d'avoir été infectées sans les ouvrir

          * Double clic sur "UsbFix.exe" présent sur ton bureau ( clic droit "exécuter en tant qu'administrateur" pour Vista & 7 )

          * Choisis l'option F pour français et tape sur [entrée] .

          * Choisis l'option 1 ( Recherche ) et tape sur [entrée] .

          * Laisse travailler l'outil.

          * Ensuite poste le rapport UsbFix.txt qui apparaitra.

          * Note : Le rapport UsbFix.txt est sauvegardé a la racine du disque. ( C:\UsbFix.txt )

          ( CTRL+A Pour tout sélectionner , CTRL+C pour copier et CTRL+V pour coller )

          * Note : "Process.exe", une composante de l'outil, est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool.
          Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.
          Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall...) d'où l'alerte émise par ces antivirus.
      2. bonjour, voici le scan de usbfix

        ############################## | UsbFix V6.100 |

        User : virginie (Administrateurs) # PC-DE-VIRGINIE
        Update on 18/03/2010 by El Desaparecido , C_XX & Chimay8
        Start at: 10:40:47 | 27/03/2010
        Website : http://pagesperso-orange.fr/NosTools/index.html
        Contact : FindyKill.Contact@gmail.com

        Genuine Intel(R) CPU 575 @ 2.00GHz
        Microsoft® Windows Vista(TM) Édition Familiale Basique (6.0.6002 32-bit) # Service Pack 2
        Internet Explorer 8.0.6001.18882
        Windows Firewall Status : Enabled

        C:\ -> Disque fixe local # 69,52 Go (26,56 Go free) [OS] # NTFS
        D:\ -> Disque fixe local # 69,52 Go (29,43 Go free) [DATA] # NTFS
        E:\ -> Disque CD-ROM
        F:\ -> Disque amovible # 7,46 Go (1,31 Go free) [UDISK 2.0] # FAT32
        G:\ -> Disque amovible # 3,8 Go (2,86 Go free) # FAT32

        ################## | Elements infectieux |

        C:\Users\virginie\AppData\Local\Temp\ytb.exe
        C:\Users\virginie\AppData\Local\Temp\un.bat
        D:\Music.lnk

        ################## | Registre |

        ################## | Mountpoints2 |

        ################## | Vaccin |

        (!) Cet ordinateur n'est pas vacciné !

        ################## | ! Fin du rapport # UsbFix V6.100 ! |
        1. Contributeur sécurité
          Suppression

          Branche tes sources de données externes à ton PC, (clé USB, disque dur externe......) susceptibles d'avoir été infectés sans les ouvrir

          (1) Double clic sur le raccourci UsbFix présent sur ton bureau

          (2) Choisi l option 2 ( Suppression )

          Ton bureau disparaitra et le pc redémarrera .

          Au redémarrage , UsbFix scannera ton pc , laisse travailler l outil.

          Ensuite poste le rapport UsbFix.txt qui apparaitra avec le bureau .

          Note : Le rapport UsbFix.txt est sauvegardé a la racine du disque.( C:\UsbFix.txt )

          ( CTRL+A Pour tout selectionner , CTRL+C pour copier et CTRL+V pour coller )
      3. résultat de suppression

        ############################## | UsbFix V6.100 |

        User : virginie (Administrateurs) # PC-DE-VIRGINIE
        Update on 18/03/2010 by El Desaparecido , C_XX & Chimay8
        Start at: 21:15:35 | 27/03/2010
        Website : http://pagesperso-orange.fr/NosTools/index.html
        Contact : FindyKill.Contact@gmail.com

        Genuine Intel(R) CPU 575 @ 2.00GHz
        Microsoft® Windows Vista(TM) Édition Familiale Basique (6.0.6002 32-bit) # Service Pack 2
        Internet Explorer 8.0.6001.18882
        Windows Firewall Status : Enabled

        C:\ -> Disque fixe local # 69,52 Go (27,72 Go free) [OS] # NTFS
        D:\ -> Disque fixe local # 69,52 Go (29,15 Go free) [DATA] # NTFS
        E:\ -> Disque CD-ROM
        F:\ -> Disque amovible # 7,46 Go (1,31 Go free) [UDISK 2.0] # FAT32

        ################## | Elements infectieux |

        Supprimé ! C:\Users\virginie\AppData\Local\Temp\NEW3F8.tmp.exe
        Supprimé ! C:\Users\virginie\AppData\Local\Temp\ytb.exe
        Supprimé ! C:\Users\virginie\AppData\Local\Temp\8rv530iv.exe
        Supprimé ! C:\Users\virginie\AppData\Local\Temp\un.bat
        Supprimé ! C:\$Recycle.Bin\S-1-5-21-1636974808-2324910112-272626297-1000
        Supprimé ! C:\$Recycle.Bin\S-1-5-21-1636974808-2324910112-272626297-500
        Supprimé ! C:\$Recycle.Bin\S-1-5-21-3182342893-2048724265-3389494133-500
        Supprimé ! D:\Music.lnk
        Supprimé ! D:\$Recycle.Bin\S-1-5-21-1636974808-2324910112-272626297-1000
        Supprimé ! D:\$Recycle.Bin\S-1-5-21-1636974808-2324910112-272626297-500

        ################## | Registre |

        ################## | Mountpoints2 |

        ################## | Listing des fichiers présent |

        [18/09/2006 22:43|--a------|24] C:\autoexec.bat
        [11/04/2009 07:36|-rahs----|333257] C:\bootmgr
        [29/05/2008 18:15|-ra-s----|8192] C:\BOOTSECT.BAK
        [18/09/2006 22:43|--a------|10] C:\config.sys
        [?|?|?] C:\hiberfil.sys
        [15/09/2009 12:21|-rahs----|0] C:\IO.SYS
        [15/09/2009 12:21|-rahs----|0] C:\MSDOS.SYS
        [29/02/2004 16:44|--a------|52576] C:\orange.bmp
        [?|?|?] C:\pagefile.sys
        [29/05/2008 08:58|--a------|426] C:\RHDSetup.log
        [27/03/2010 21:23|--a------|1990] C:\UsbFix.txt
        [13/03/2009 00:09|--a------|386748] C:\vcredist_x86.log
        [15/09/2009 12:05|---hs----|53] D:\desktop.ini
        [27/10/2009 12:23|-ra------|528] D:\MediaID.bin
        [26/12/2008 10:45|---hs----|147] F:\desktop.ini
        [17/06/2009 21:10|---hs----|245760] F:\Thumbs.db
        [21/02/2010 13:12|--a------|732803072] F:\Very Bad Trip French DvdRip By Jun'Inyo [www.thrillergangstahiphop.blogspot.com].avi
        [14/02/2010 11:01|--a------|733335552] F:\The.Shadow.Dancer.2005.DiRFiX.LiMiTED.TRUEFRENCH.DVDRip.XviD-UNSKiLLED.avi
        [07/02/2010 15:26|--a------|731463680] F:\Fly Me To The Moon [DVDRiP].avi
        [25/02/2010 19:44|--a------|734675414] F:\Mostly.Ghostly.2009.STV.FRENCH.DVDRip.XviD-UTT-wWw.Extreme-Down.Com.avi
        [11/03/2010 11:28|--a------|732792832] F:\Hoboken.Hollow.2010.TRUEFRENCH.UNRATED.DVDRIP.XViD-ARTEFAC.avi
        [11/03/2010 10:18|--a------|733900800] F:\Did.You.Hear.About.The.Morgans.2009.FRENCH.BDRiP.XViD-SURViVAL.avi
        [14/03/2010 21:49|--a------|733536256] F:\Whiteout.TRUEFRENCH.DVDRiP.XviD-UNSKiLLED.avi
        [07/12/2009 15:38|--a------|731365376] F:\Astro.Boy.FRENCH.R5.MD.XviD-BOWSER.avi
        [26/01/2010 13:57|--a------|733732568] F:\The.Princess.avi

        ################## | Vaccination |

        # C:\autorun.inf -> Dossier créé par UsbFix (El Desaparecido).
        # D:\autorun.inf -> Dossier créé par UsbFix (El Desaparecido).
        # F:\autorun.inf -> Dossier créé par UsbFix (El Desaparecido).

        ################## | Upload |

        Veuillez envoyer le fichier : C:\UsbFix_Upload_Me_PC-de-virginie.zip : https://www.ionos.fr/?affiliate_id=77097
        Merci pour votre contribution .

        ################## | ! Fin du rapport # UsbFix V6.100 ! |
        1. Contributeur sécurité
          Désactive ton antivirus le temps de la manip ainsi que ton parefeu si présent(car il est détecte a tort comme infection)

          Télécharge et installe List&Kill'em et enregistre le sur ton bureau

          http://sd-1.archive-host.com/...

          double clique ( clic droit "exécuter en tant qu'administrateur" pour Vista/7 ) sur le raccourci sur ton bureau pour lancer l'installation

          une fois terminée , clic sur "terminer" et le programme se lancera seul

          choisis l'option Search

          un icone blanc et noir va s'afficher sur le bureau , il te servira à relancer le programme par la suite.
          un autre rouge et noir te servira a désinstaller le prog a la fin de la désinfection.

          ? laisse travailler l'outil

          à l'apparition de la fenêtre blanche , c'est un peu long , c'est normal , le programme n'est pas bloqué.

          un rapport du nom de catchme apparait sur ton bureau , ignore-le,ne le poste pas , , il s'auto supprimera a la fin du scan

          ? Poste le contenu du rapport qui s'ouvre aux 100 % du scan à l'écran "COMPLETED"
      4. List'em by g3n-h@ckm@n 1.6.0.6

        User : virginie (Administrateurs)
        Update on 27/03/2010 by g3n-h@ckm@n ::::: 14.50
        Start at: 23:16:12 | 27/03/2010

        Genuine Intel(R) CPU 575 @ 2.00GHz
        Microsoft® Windows Vista(TM) Édition Familiale Basique (6.0.6002 32-bit) # Service Pack 2
        Internet Explorer 8.0.6001.18882
        Windows Firewall Status : Disabled

        C:\ -> Disque fixe local | 69,52 Go (27,85 Go free) [OS] | NTFS
        D:\ -> Disque fixe local | 69,52 Go (28,99 Go free) [DATA] | NTFS
        E:\ -> Disque CD-ROM

        Boot: Normal

        ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Processes running

        C:\Windows\System32\smss.exe
        C:\Windows\system32\csrss.exe
        C:\Windows\system32\wininit.exe
        C:\Windows\system32\csrss.exe
        C:\Windows\system32\winlogon.exe
        C:\Windows\system32\services.exe
        C:\Windows\system32\lsass.exe
        C:\Windows\system32\lsm.exe
        C:\Windows\system32\svchost.exe
        C:\Windows\system32\svchost.exe
        C:\Windows\System32\svchost.exe
        C:\Windows\System32\svchost.exe
        C:\Windows\System32\svchost.exe
        C:\Windows\system32\svchost.exe
        C:\Windows\system32\svchost.exe
        C:\Windows\system32\SLsvc.exe
        C:\Windows\system32\svchost.exe
        C:\Windows\system32\svchost.exe
        C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
        C:\Windows\system32\WLANExt.exe
        C:\Windows\System32\spoolsv.exe
        C:\Windows\system32\svchost.exe
        C:\Windows\system32\svchost.exe
        C:\Program Files\Bonjour\mDNSResponder.exe
        C:\Program Files\EMACHINES\eMachines Recovery Management\Service\ETService.exe
        C:\Program Files\Common Files\LightScribe\LSSrvc.exe
        C:\Windows\system32\svchost.exe
        C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
        C:\Windows\system32\svchost.exe
        C:\Windows\system32\svchost.exe
        C:\Windows\System32\svchost.exe
        C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
        C:\Windows\system32\SearchIndexer.exe
        C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
        C:\Windows\system32\Dwm.exe
        C:\Windows\Explorer.EXE
        C:\Program Files\Windows Defender\MSASCui.exe
        C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
        C:\Windows\System32\igfxtray.exe
        C:\Windows\System32\hkcmd.exe
        C:\Windows\System32\igfxpers.exe
        C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
        C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
        C:\Program Files\Common Files\Java\Java Update\jusched.exe
        C:\Program Files\Alwil Software\Avast5\AvastUI.exe
        C:\Windows\System32\p2phost.exe
        C:\Program Files\Windows Live\Messenger\msnmsgr.exe
        C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
        C:\Windows\system32\taskeng.exe
        C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
        C:\Program Files\Skype\Phone\Skype.exe
        C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
        C:\Windows\system32\igfxsrvc.exe
        C:\Windows\system32\wbem\unsecapp.exe
        C:\Windows\system32\wbem\wmiprvse.exe
        C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
        C:\Program Files\Skype\Plugin Manager\skypePM.exe
        C:\Program Files\Windows Media Player\wmpnscfg.exe
        C:\Program Files\Windows Media Player\wmpnetwk.exe
        C:\Users\virginie\AppData\Local\Google\Chrome\Application\chrome.exe
        C:\Users\virginie\AppData\Local\Google\Chrome\Application\chrome.exe
        C:\Users\virginie\AppData\Local\Google\Chrome\Application\chrome.exe
        C:\Windows\system32\ctfmon.exe
        C:\Windows\system32\SearchProtocolHost.exe
        C:\Windows\system32\SearchFilterHost.exe
        C:\Program Files\List_Kill'em\List_Kill'em.exe
        C:\Windows\system32\cmd.exe
        C:\Windows\system32\conime.exe
        C:\Windows\system32\DllHost.exe
        C:\Windows\system32\wbem\wmiprvse.exe
        C:\Program Files\List_Kill'em\pv.exe

        ======================
        Keys "Run"
        ======================
        [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
        WindowsWelcomeCenter REG_SZ rundll32.exe oobefldr.dll,ShowWelcomeCenter
        CollaborationHost REG_SZ C:\Windows\system32\p2phost.exe -s
        MsnMsgr REG_SZ "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
        swg REG_SZ "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
        Google Update REG_SZ "C:\Users\virginie\AppData\Local\Google\Update\GoogleUpdate.exe" /c
        Skype REG_SZ "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
        Uniblue RegistryBooster 2 REG_SZ c:\program files\uniblue\registrybooster 2\StartRegistryBooster.exe

        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
        Windows Defender REG_EXPAND_SZ %ProgramFiles%\Windows Defender\MSASCui.exe -hide
        IAAnotif REG_SZ C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
        IgfxTray REG_SZ C:\Windows\system32\igfxtray.exe
        HotKeysCmds REG_SZ C:\Windows\system32\hkcmd.exe
        Persistence REG_SZ C:\Windows\system32\igfxpers.exe
        eRecoveryService REG_SZ
        Google Desktop Search REG_SZ "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
        WarReg_PopUp REG_SZ C:\Program Files\eMachines\WR_PopUp\WarReg_PopUp.exe
        EoEngine REG_SZ
        QuickTime Plugin Install REG_SZ C:\Program Files\QuickTime\Plugins\DeleteMe1.exe
        Adobe Reader Speed Launcher REG_SZ "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
        Adobe ARM REG_SZ "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
        SynTPEnh REG_EXPAND_SZ %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe
        eorezo REG_SZ
        SunJavaUpdateSched REG_SZ "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
        QuickTime Task REG_SZ "C:\Program Files\QuickTime\QTTask.exe" -atboottime
        avast5 REG_SZ C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe /nogui
        SpiderMessenger REG_SZ

        [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices]

        [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]

        =====================
        Other Keys
        =====================
        [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
        ConsentPromptBehaviorAdmin REG_DWORD 2 (0x2)
        ConsentPromptBehaviorUser REG_DWORD 1 (0x1)
        EnableInstallerDetection REG_DWORD 1 (0x1)
        EnableLUA REG_DWORD 1 (0x1)
        EnableSecureUIAPaths REG_DWORD 1 (0x1)
        EnableVirtualization REG_DWORD 1 (0x1)
        PromptOnSecureDesktop REG_DWORD 1 (0x1)
        ValidateAdminCodeSignatures REG_DWORD 0 (0x0)
        dontdisplaylastusername REG_DWORD 0 (0x0)
        legalnoticecaption REG_SZ
        legalnoticetext REG_SZ
        scforceoption REG_DWORD 0 (0x0)
        shutdownwithoutlogon REG_DWORD 1 (0x1)
        undockwithoutlogon REG_DWORD 1 (0x1)
        FilterAdministratorToken REG_DWORD 0 (0x0)
        EnableUIADesktopToggle REG_DWORD 0 (0x0)

        ===============
        [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
        NoDriveAutoRun REG_DWORD 255 (0xff)
        NoDriveTypeAutoRun REG_DWORD 255 (0xff)
        HonorAutoRunSetting REG_DWORD 0 (0x0)

        ===============
        [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
        BindDirectlyToPropertySetStorage REG_DWORD 0 (0x0)
        NoDriveAutoRun REG_DWORD 255 (0xff)
        NoDriveTypeAutoRun REG_DWORD 255 (0xff)
        HonorAutoRunSetting REG_DWORD 0 (0x0)

        ===============
        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
        AppInit_DLLS REG_SZ C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL

        ===============
        [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
        ReportBootOk REG_SZ 1
        Shell REG_SZ explorer.exe
        Userinit REG_SZ C:\Windows\system32\userinit.exe,
        VmApplet REG_SZ rundll32 shell32,Control_RunDLL "sysdm.cpl"
        AutoRestartShell REG_DWORD 1 (0x1)
        LegalNoticeCaption REG_SZ
        LegalNoticeText REG_SZ
        PowerdownAfterShutdown REG_SZ 0
        ShutdownWithoutLogon REG_SZ 0
        cachedlogonscount REG_SZ 10
        forceunlocklogon REG_DWORD 0 (0x0)
        passwordexpirywarning REG_DWORD 14 (0xe)
        Background REG_SZ 0 0 0
        DebugServerCommand REG_SZ no
        WinStationsDisabled REG_SZ 0
        DisableCAD REG_DWORD 1 (0x1)
        scremoveoption REG_SZ 0
        ShutdownFlags REG_DWORD 135 (0x87)

        ===============
        [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\igfxcui]

        ===============
        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]

        ===============
        [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

        [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

        ===============
        ActivX controls
        ===============
        [HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{8AD9C840-044E-11D1-B3E9-00805F499D93}]
        [HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA}]

        ===============
        [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}]
        [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{26923b43-4d38-484f-9b9e-de460746276c}]
        [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
        [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{08B0E5C0-4FCB-11CF-AAA5-00401C608500}]
        [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{2179C5D3-EBFF-11CF-B6FD-00AA00B4E220}]
        [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{22d6f312-b0f6-11d0-94ab-0080c74c7e95}]
        [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}]
        [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{3af36230-a269-11d1-b5bf-0000f8051515}]
        [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}]
        [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA848-CC51-11CF-AAFA-00AA00B6015C}]
        [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA855-CC51-11CF-AAFA-00AA00B6015F}]
        [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{45ea75a0-a269-11d1-b5bf-0000f8051515}]
        [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{4f645220-306d-11d2-995d-00c04f98bbc9}]
        [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{5fd399c0-a70a-11d1-9948-00c04f98bbc9}]
        [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{630b1da0-b465-11d1-9948-00c04f98bbc9}]
        [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}]
        [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{6fab99d0-bab8-11d1-994a-00c04f98bbc9}]
        [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{7790769C-0471-11d2-AF11-00C04FA35D02}]
        [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{7C028AF8-F614-47B3-82DA-BA94E41B1089}]
        [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{89820200-ECBD-11cf-8B85-00AA005B4340}]
        [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{89820200-ECBD-11cf-8B85-00AA005B4383}]
        [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{89B4C1CD-B018-4511-B0A1-5476DBF70820}]
        [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{9381D8F2-0288-11D0-9501-00AA00B911A5}]
        [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{C6BAF60B-6E91-453F-BFF9-D3789CFEFCDD}]
        [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{C9E9A340-D1F1-11D0-821E-444553540600}]
        [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{CDD7975E-60F8-41d5-8149-19E51D6F71D0}]
        [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{D27CDB6E-AE6D-11CF-96B8-444553540000}]
        [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{de5aed00-a4bf-11d1-9948-00c04f98bbc9}]
        [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{E92B03AB-B707-11d2-9CBD-0000F87A369E}]

        ==============
        BHO :
        ======
        [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
        [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{5C255C8A-E604-49b4-9D64-90988571CECB}]
        [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{6EBF7485-159F-4bff-A14F-B9E3AAC4465B}]
        [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
        [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
        [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
        [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
        [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{E15A8DC0-8516-42A1-81EA-DC94EC1ACF10}]

        ===
        DNS
        ===

        HKLM\SYSTEM\CCS\Services\Tcpip\..\{DEACE777-5171-40E5-B531-3B4AD1992E37}: DhcpNameServer=212.27.40.240 212.27.40.241
        HKLM\SYSTEM\CS1\Services\Tcpip\..\{DEACE777-5171-40E5-B531-3B4AD1992E37}: DhcpNameServer=212.27.40.240 212.27.40.241
        HKLM\SYSTEM\CS2\Services\Tcpip\..\{DEACE777-5171-40E5-B531-3B4AD1992E37}: DhcpNameServer=212.27.40.240 212.27.40.241
        HKLM\SYSTEM\CS3\Services\Tcpip\..\{DEACE777-5171-40E5-B531-3B4AD1992E37}: DhcpNameServer=212.27.40.240 212.27.40.241
        HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=212.27.40.240 212.27.40.241
        HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=212.27.40.240 212.27.40.241
        HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: DhcpNameServer=212.27.40.240 212.27.40.241
        HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: DhcpNameServer=212.27.40.240 212.27.40.241

        ================
        Internet Explorer :
        ================
        [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
        Start Page REG_SZ https://www.msn.com/fr-fr

        [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
        Start Page REG_SZ http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome

        ========
        Services
        ========
        [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services]

        Ndisuio : 0x3 ( OK = 3 )
        EapHost : 0x3 ( OK = 2 )
        Wlansvc : 0x2 ( OK = 2 )
        SharedAccess : 0x3 ( OK = 2 )
        windefend : 0x2 ( OK = 2 )
        wuauserv : 0x2 ( OK = 2 )
        wscsvc : 0x2 ( OK = 2 )

        =========
        Atapi.sys
        =========

        %%%% HASHDEEP-1.0
        %%%% size,md5,sha256,filename
        ## Invoked from: C:\Program Files\List_Kill'em
        ## C:\> hashdeep.exe C:\Windows\System32\drivers\atapi.sys
        ##
        21560,2d9c903dc76a66813d350a562de40ed9,82609f01a08c6842e4c17c077bb641c1429c0e6657964b7f2d114035e1bdcbf3,C:\Windows\System32\drivers\atapi.sys
        %%%% HASHDEEP-1.0
        %%%% size,md5,sha256,filename
        ## Invoked from: C:\Program Files\List_Kill'em
        ## C:\> hashdeep.exe C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_b12d8e84\atapi.sys
        ##
        19944,1f05b78ab91c9075565a9d8a4b880bc4,737be9f9376dab0ccdfed93ea6d67f0c432367ea63cd772a453485be769af3bd,C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_b12d8e84\atapi.sys
        %%%% HASHDEEP-1.0
        %%%% size,md5,sha256,filename
        ## Invoked from: C:\Program Files\List_Kill'em
        ## C:\> hashdeep.exe C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_c6c2e699\atapi.sys
        ##
        19048,4f4fcb8b6ea06784fb6d475b7ec7300f,6202d85c9a75e3f01f5f94f069c4cd8a2b9295a182301eae5940ec3bc2c1d896,C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_c6c2e699\atapi.sys
        %%%% HASHDEEP-1.0
        %%%% size,md5,sha256,filename
        ## Invoked from: C:\Program Files\List_Kill'em
        ## C:\> hashdeep.exe C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_cc18792d\atapi.sys
        ##
        21560,2d9c903dc76a66813d350a562de40ed9,82609f01a08c6842e4c17c077bb641c1429c0e6657964b7f2d114035e1bdcbf3,C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_cc18792d\atapi.sys
        %%%% HASHDEEP-1.0
        %%%% size,md5,sha256,filename
        ## Invoked from: C:\Program Files\List_Kill'em
        ## C:\> hashdeep.exe C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6001.18000_none_dd38281a2189ce9c\atapi.sys
        ##
        21560,2d9c903dc76a66813d350a562de40ed9,82609f01a08c6842e4c17c077bb641c1429c0e6657964b7f2d114035e1bdcbf3,C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6001.18000_none_dd38281a2189ce9c\atapi.sys
        %%%% HASHDEEP-1.0
        %%%% size,md5,sha256,filename
        ## Invoked from: C:\Program Files\List_Kill'em
        ## C:\> hashdeep.exe C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6002.18005_none_df23a1261eab99e8\atapi.sys
        ##
        19944,1f05b78ab91c9075565a9d8a4b880bc4,737be9f9376dab0ccdfed93ea6d67f0c432367ea63cd772a453485be769af3bd,C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6002.18005_none_df23a1261eab99e8\atapi.sys

        Référence :
        ==========

        Win 2000_SP2 : ff953a8f08ca3f822127654375786bbe
        Win 2000_SP4 : 8c718aa8c77041b3285d55a0ce980867
        Win XP_32b : a64013e98426e1877cb653685c5c0009
        Win XP_SP2_32b : CDFE4411A69C224BD1D11B2DA92DAC51
        Win XP_SP3_32b : 9F3A2F5AA6875C72BF062C712CFA2674
        Vista_32b : e03e8c99d15d0381e02743c36afc7c6f
        Vista_SP1_32b : 2d9c903dc76a66813d350a562de40ed9
        Vista_SP2_32b : 1F05B78AB91C9075565A9D8A4B880BC4
        Vista_SP2_64b : 1898FAE8E07D97F2F6C2D5326C633FAC
        Windows 7_32b : 80C40F7FDFC376E4C5FEEC28B41C119E
        Windows 7_64b : 02062C0B390B7729EDC9E69C680A6F3C
        Windows 7_32b_Ultimate : 338c86357871c167a96ab976519bf59e

        =======
        Drive :
        =======

        D'fragmenteur de disque Windows
        Copyright (c) 2006 Microsoft Corp.

        Rapport d'analyse pour le volume C: OS

        Taille du volume = 69.52 Go
        Espace libre = 27.86 Go
        tendue d'espace libre la plus grande = 6.40 Go
        Pourcentage de fragmentation des fichiers = 4 %

        Remarqueÿ: sur les volumes NTFS, les fragments de fichiers de plus de 64ÿMo ne sont pas inclus dans les statistiques de fragmentation.

        Il n'est pas n'cessaire de d'fragmenter ce volume.

        ¤¤¤¤¤¤¤¤¤¤ Files/folders :

        Present !! : C:\Users\virginie\AppData\Local\bqxmsh.bat
        Present !! : C:\Users\virginie\AppData\Local\daqgfuk.bat
        Present !! : C:\Users\virginie\AppData\Local\ggggggxx.bat
        Present !! : C:\Users\virginie\AppData\Local\qsvybea.bat
        Present !! : C:\Users\virginie\AppData\Local\rfrcp.bat
        Present !! : C:\Users\virginie\AppData\Local\woghxp.bat
        Present !! : C:\Users\virginie\AppData\Local\ymemsyy.bat
        Present !! : C:\Users\virginie\AppData\Local\GDIPFONTCACHEV1.DAT
        Present !! : C:\Users\virginie\AppData\Roaming\EoRezo
        Present !! : C:\Users\virginie\Local Settings\Temp\crt.dll
        Present !! : C:\Users\virginie\Local Settings\Temp\db.dat
        Present !! : C:\Users\virginie\Local Settings\Temp\hip.jpg
        Present !! : C:\Users\virginie\Local Settings\Temp\tdf.zip
        Present !! : C:\Users\virginie\Local Settings\Temp\un2.bat
        Present !! : C:\Users\virginie\Local Settings\Temp\url.txt
        Present !! : C:\Users\virginie\LOCAL Settings\Temp\askToolbarInstaller.exe
        Present !! : C:\Users\virginie\LOCAL Settings\Temp\DAPREMOVE.EXE
        Present !! : C:\Users\virginie\LOCAL Settings\Temp\DivXWebPlayerInstaller.exe
        Present !! : C:\Users\virginie\LOCAL Settings\Temp\FlashPlayerUpdate.exe
        Present !! : C:\Users\virginie\LOCAL Settings\Temp\FlashPlayerUpdate01.exe
        Present !! : C:\Users\virginie\LOCAL Settings\Temp\GoogleUpdateSetup.exe109f6a
        Present !! : C:\Users\virginie\LOCAL Settings\Temp\GoogleUpdate.exe4bf58
        Present !! : C:\Users\virginie\LOCAL Settings\Temp\GoogleUpdateSetup.exe2f83d1e
        Present !! : C:\Users\virginie\LOCAL Settings\Temp\GoogleUpdateSetup.exe13f540e
        Present !! : C:\Users\virginie\LOCAL Settings\Temp\GRRemove.exe
        Present !! : C:\Users\virginie\LOCAL Settings\Temp\jre-6u18-windows-i586-iftw-rv.exe
        Present !! : C:\Users\virginie\LOCAL Settings\Temp\kiwee_setup.exe
        Present !! : C:\Users\virginie\LOCAL Settings\Temp\msnsearch.exe
        Present !! : C:\Users\virginie\LOCAL Settings\Temp\RunWizards.exe
        Present !! : C:\Users\virginie\LOCAL Settings\Temp\SearchWithGoogleUpdate.exe
        Present !! : C:\Users\virginie\LOCAL Settings\Temp\svd_dap.exe
        Present !! : C:\Users\virginie\LOCAL Settings\Temp\VARemove.exe
        Present !! : C:\Users\virginie\LOCAL Settings\Temp\db.dat
        Present !! : C:\Users\virginie\LOCAL Settings\Temp\isconfig.dat
        Present !! : C:\Users\virginie\LOCAL Settings\Temp\liveplayer_exe.dat
        Present !! : C:\Users\virginie\LOCAL Settings\Temp\liveplayer_skin.dat
        Present !! : C:\Users\virginie\LOCAL Settings\Temp\skin_dll.dat
        Present !! : C:\Users\virginie\LOCAL Settings\Temp\sqlite_dll.dat
        Present !! : C:\Users\virginie\LOCAL Settings\Temp\srtspse.dat
        Present !! : C:\Users\virginie\LOCAL Settings\Temp\srtspso.dat
        Present !! : C:\Users\virginie\LOCAL Settings\Temp\srtspsp.dat
        Present !! : C:\Users\virginie\LOCAL Settings\Temp\BrowserSet.dll
        Present !! : C:\Users\virginie\LOCAL Settings\Temp\cabex.dll
        Present !! : C:\Users\virginie\LOCAL Settings\Temp\crt.dll
        Present !! : C:\Users\virginie\LOCAL Settings\Temp\goopdate.dll4bfa6
        Present !! : C:\Users\virginie\LOCAL Settings\Temp\goopdateres_fr.dll4c995
        Present !! : C:\Users\virginie\LOCAL Settings\Temp\hGu8YnFX.dll
        Present !! : C:\Users\virginie\LOCAL Settings\Temp\I64xG6fq.dll
        Present !! : C:\Users\virginie\LOCAL Settings\Temp\tmp9AE7.tmp
        Present !! : C:\Users\virginie\LOCAL Settings\Temp\tmp9AF8.tmp

        ¤¤¤¤¤¤¤¤¤¤ Keys :

        Present !! : HKLM\Software\Microsoft\Windows\CurrentVersion\Run\Eoengine
        Present !! : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\{D4027C7F-154A-4066-A1AD-4243D8127440}
        Present !! : HKCR\CLSID\{ca3eb689-8f09-4026-aa10-b9534c691ce0}
        Present !! : HKCR\Interface\{4897bba6-48d9-468c-8efa-846275d7701b}
        Present !! : HKCR\interface\{877f3eab-4462-44df-8475-6064eafd7fbf}
        Present !! : HKCR\TypeLib\{4509d3cc-b642-4745-b030-645b79522c6d}
        Present !! : HKCR\urlsearchhook.toolbarurlsearchhook
        Present !! : HKCR\urlsearchhook.toolbarurlsearchhook.1
        Present !! : HKCU\SOFTWARE\EoRezo
        Present !! : HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{83ff80f4-8c74-4b80-b5ba-c8ddd434e5c4}
        Present !! : HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{EEE6C35B-6118-11DC-9C72-001320C79847}
        Present !! : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EEE6C35C-6118-11DC-9C72-001320C79847}
        Present !! : HKCU\Software\SweetIM
        Present !! : HKLM\Software\Classes\Interface\{877F3EAB-4462-44DF-8475-6064EAFD7FBF}
        Present !! : HKLM\Software\Classes\TypeLib\{565DD573-549E-4DA9-8CD7-6AE3DF25339A}
        Present !! : HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\SoftwareUpdate_is1
        Present !! : HKLM\SOFTWARE\SweetIM
        Present !! : HKU\.DEFAULT\Software\AGI

        ============

        catchme 0.3.1398.3 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
        Rootkit scan 2010-03-27 23:39:07
        Windows 6.0.6002 Service Pack 2 FAT NTAPI

        scanning hidden processes ...

        scanning hidden services ...

        scanning hidden autostart entries ...

        HKCU\Software\Microsoft\Windows\CurrentVersion\Run
        MsnMsgr = "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background??s

        scanning hidden files ...

        scan completed successfully
        hidden processes: 0
        hidden services: 0
        hidden files: 0

        Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

        device: opened successfully
        user: MBR read successfully
        called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys acpi.sys hal.dll iaStor.sys usbhub.sys partmgr.sys volmgr.sys ecache.sys volsnap.sys Ntfs.sys dxgkrnl.sys igdkmd32.sys ndis.sys bcmwl6.sys tcpip.sys NETIO.SYS USBPORT.SYS usbuhci.sys nwifi.sys hidusb.sys HIDCLASS.SYS HIDPARSE.SYS mouhid.sys mouclass.sys afd.sys rdbss.sys
        kernel: MBR read successfully
        user & kernel MBR OK

        ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤( EOF )¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤

        End of scan : 23:39:10,91
        HKLM\SYSTEM\CCS\Services\Tcpip\..\{DEACE777-5171-40E5-B531-3B4AD1992E37}: DhcpNameServer=212.27.40.240 212.27.40.241
        HKLM\SYSTEM\CS1\Services\Tcpip\..\{DEACE777-5171-40E5-B531-3B4AD1992E37}: DhcpNameServer=212.27.40.240 212.27.40.241
        HKLM\SYSTEM\CS2\Services\Tcpip\..\{DEACE777-5171-40E5-B531-3B4AD1992E37}: DhcpNameServer=212.27.40.240 212.27.40.241
        HKLM\SYSTEM\CS3\Services\Tcpip\..\{DEACE777-5171-40E5-B531-3B4AD1992E37}: DhcpNameServer=212.27.40.240 212.27.40.241
        HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=212.27.40.240 212.27.40.241
        HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=212.27.40.240 212.27.40.241
        HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: DhcpNameServer=212.27.40.240 212.27.40.241
        HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: DhcpNameServer=212.27.40.240 212.27.40.241
        1. salut benurrr.... pour le scan j'ai eu un seul rapport .. le rapport catchme avec le complet.. merci encore
        2. Contributeur sécurité
          le rapport complet se trouve a la racine de C:
        3. le rapport ci dessus que je t'ai posté est le seul que j'obtiens a 100% du scan ça s'affiche complet et c'est se rapport qui s'affiche ...
        4. Contributeur sécurité
          va dans poste de travaille et la tu clique sur ta partition C et la tu aura le complet
        5. j'ai un probléme pour poster le rapport le message ne passe pas!!! je vais retenter
      5. salut, benurrr... a tu reçu le rapport ?? j'ai des probleme avec java script j'ai un message qui me dis qu'il est désactivé alors que non...

        Discussions similaires

        disque dur et bbox bouygues

        1 réponse