Infecté par Anna I liebe you

Bonjour à tous,

Je suis sou windows XP pro, et depuis peu je ne peux plus ouvrir mes 2 diisques durs (C & D) en double cliquant dessus dans "poste de travail", je suis obligé de faire clik droit puis explorer.
Apres avoir fait quelques recherches sur internet à propos de problemes similaires, j'ai essayé de modifier puis enregistrer les fichiers autorun.inf, mais sans succes.
j'ai fait une analyse antivirus avec antivir qui n'a rien changé non plus.
J'ai télécharger AD Aware, puis j'ai lancé une analyse qui m'a trouvé des éléments suspect qu'il a supprimé pour certtains, puis mis en quarantaine pour d'autres.

Apres redémarrage de mon poste , je ne peux toujours pas rentrer dans mes disques dur en double cliquant, et j'ai le message suivant qui apparait :
Echec du chargement du script "C:\WINDOWS\winrun.dll.vbs" (le processus ne peut pas acceder au fichier car ce fichier est utilisé par un autre processus)

j'ai fait quelques recherches qui semblent me mener vers le meme virus, Anna I Liebe YOU

D'autant que quand j'ouvre mon Internet Explorer (que je n'utilise presque jamais) il va sur la page d'accueil (google) mais dans le nom de ma fenetre IE il y a marqué :
Google - //;) anna I liebe you ==> milk@3|_!!!

Comment puis-je me sortir de là SVP???

merci d'avance .

74 réponses

Résumé de la discussion

Sous Windows XP Professionnel, les disques C et D ne s'ouvrent plus par double-clic et affichent l'erreur Échec du chargement du script C:\WINDOWS\winrun.dll.vbs, signe d'une infection potentielle et d'un virus nommé Anna I Liebe You. Plusieurs éléments de réponse pointent vers une infection, notamment des scripts autorun malveillants et des remaniements du navigateur, avec des pages d'accueil détournées et des extensions indésirables. Les réponses préconisent d'analyser et nettoyer le système à l'aide d'outils dédiés (HijackThis, Ad-Aware) pour supprimer les entrées répertoriées et rétablir les accès aux disques. En dernier point, l'utilisation d'un outil UsbFix a généré des fichiers de suppression et un dossier récapitulant les éléments supprimés, apportant une piste utile pour comprendre les modifications apportées au système.

Bobot (l’IA à votre service)
  1. Salut,

    On va commencer par analyser ton PC :

    ● Télécharge RSIT de Random/Random, et enregistre le sur ton Bureau.

    ● Sous XP : Double clique sur RSIT.exe
    ● Sous Vista/7 : Fais un clic droit sur RSIT.exe et sélectionne "Exécuter en tant qu'administrateur"

    ● Clique sur Continue à l'écran Disclaimer.

    ● Si l'outil HijackThis n'est pas présent sur ton PC, RSIT le téléchargera (autorise l'accès dans ton pare-feu s'il te le demande) et tu devras accepter la licence en cliquant sur le bouton accept.

    ● Une fois le scan terminé, deux rapports vont apparaître : poste les dans deux messages séparés.

    ▲ Les rapports sont sauvegardés dans C:\rsit\info.txt et C:\rsit\log.txt

    ► Aide en images
    0
    1. Bonjour, merci de ton aide.
      le info.txt ne passe pas en une seule fois. je vais le mettre en 2 messages.

      info.txt logfile of random's system information tool 1.06 2010-04-22 15:57:18

      ======Uninstall list======

      -->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
      Ad-Aware Email Scanner for Outlook-->MsiExec.exe /I{338F08AB-C262-42C7-B000-34DE1A475273}
      Ad-Aware-->"C:\Documents and Settings\All Users\Application Data\{74D08EB8-01D1-4BAE-91E3-F30C1B031AC6}\Ad-AwareInstaller.exe" REMOVE=TRUE MODIFY=FALSE
      Ad-Aware-->C:\Documents and Settings\All Users\Application Data\{74D08EB8-01D1-4BAE-91E3-F30C1B031AC6}\Ad-AwareInstaller.exe
      Adobe AIR-->c:\Program Files\Fichiers communs\Adobe AIR\Versions\1.0\Resources\Adobe AIR Updater.exe -arp:uninstall
      Adobe AIR-->MsiExec.exe /I{197A3012-8C85-4FD3-AB66-9EC7E13DB92E}
      Adobe Anchor Service CS3-->MsiExec.exe /I{90176341-0A8B-4CCC-A78D-F862228A6B95}
      Adobe Anchor Service CS4-->MsiExec.exe /I{1618734A-3957-4ADD-8199-F973763109A8}
      Adobe Asset Services CS3-->MsiExec.exe /I{6FF5DD7A-FE28-4439-B8CF-1E9AF4EA0A61}
      Adobe Bridge 1.0-->MsiExec.exe /I{B74D4E10-6884-0000-0000-000000000101}
      Adobe Bridge CS3-->MsiExec.exe /I{9C9824D9-9000-4373-A6A5-D0E5D4831394}
      Adobe Bridge CS4-->MsiExec.exe /I{83877DB1-8B77-45BC-AB43-2BAC22E093E0}
      Adobe Bridge Start Meeting-->MsiExec.exe /I{08B32819-6EEF-4057-AEDA-5AB681A36A23}
      Adobe BridgeTalk Plugin CS3-->MsiExec.exe /I{B73CFB12-C814-4638-AFFD-7E3AAFAF0B4E}
      Adobe Camera Raw 4.0-->MsiExec.exe /I{B3BF6689-A81D-40D8-9A86-4AC4ACD9FC1C}
      Adobe CMaps CS4-->MsiExec.exe /I{94D398EB-D2FD-4FD1-B8C4-592635E8A191}
      Adobe Color - Photoshop Specific CS4-->MsiExec.exe /I{3D2C9DE6-9ADE-4252-A241-E43723B0CE02}
      Adobe Color EU Extra Settings-->MsiExec.exe /I{51846830-E7B2-4218-8968-B77F0FF475B8}
      Adobe Color EU Recommended Settings CS4-->MsiExec.exe /I{0DC0E85F-36E4-463B-B3EA-4CD8ED2222A1}
      Adobe Color JA Extra Settings CS4-->MsiExec.exe /I{0D6013AB-A0C7-41DC-973C-E93129C9A29F}
      Adobe Color NA Extra Settings CS4-->MsiExec.exe /I{098A2A49-7CF3-4F08-A38D-FB879117152A}
      Adobe Color NA Recommended Settings-->MsiExec.exe /I{95655ED4-7CA5-46DF-907F-7144877A32E5}
      Adobe Color Video Profiles CS CS4-->MsiExec.exe /I{63C24A08-70F3-4C8E-B9FB-9F21A903801D}
      Adobe Common File Installer-->MsiExec.exe /I{8EDBA74D-0686-4C99-BFDD-F894678E5101}
      Adobe Creative Suite 3 Web Premium-->MsiExec.exe /I{69B6B4A5-1C4D-4F16-BB11-A4EB9A439116}
      Adobe CSI CS4-->MsiExec.exe /I{0F723FC1-7606-4867-866C-CE80AD292DAF}
      Adobe Default Language CS4-->MsiExec.exe /I{C52E3EC1-048C-45E1-8D53-10B0C6509683}
      Adobe Device Central CS3-->MsiExec.exe /I{8D2BA474-F406-4710-9AE4-D4F22D21F0DD}
      Adobe Device Central CS4-->MsiExec.exe /I{67F0E67A-8E93-4C2C-B29D-47C48262738A}
      Adobe Drive CS4-->MsiExec.exe /I{16E16F01-2E2D-4248-A42F-76261C147B6C}
      Adobe ExtendScript Toolkit 2-->MsiExec.exe /I{C2D69781-F392-4118-A5A7-C7E9C38DBFC2}
      Adobe ExtendScript Toolkit CS4-->MsiExec.exe /I{F8EF2B3F-C345-4F20-8FE4-791A20333CD5}
      Adobe Extension Manager CS3-->MsiExec.exe /I{BE5F3842-8309-4754-92D5-83E02E6077A3}
      Adobe Extension Manager CS4-->MsiExec.exe /I{054EFA56-2AC1-48F4-A883-0AB89874B972}
      Adobe Flash Player 10 ActiveX-->C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
      Adobe Flash Player 10 Plugin-->C:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe
      Adobe Fonts All-->MsiExec.exe /I{FCDD51BB-CAD0-4BB1-B7DF-CE86D1032794}
      Adobe Help Center 1.0-->MsiExec.exe /I{E9787678-119F-4D52-B551-6739B2B22101}
      Adobe Help Viewer CS3-->MsiExec.exe /I{04AF207D-9A77-465A-8B76-991F6AB66245}
      Adobe Illustrator CS3-->C:\Program Files\Fichiers communs\Adobe\Installers\e21d2df5563f0bf421cf2cc5ec26c42\Setup.exe
      Adobe Illustrator CS3-->MsiExec.exe /I{6E08CE13-C2AB-4749-9335-5900B958929E}
      Adobe Linguistics CS3-->MsiExec.exe /I{54793AA1-5001-42F4-ABB6-C364617C6078}
      Adobe Linguistics CS4-->MsiExec.exe /I{931AB7EA-3656-4BB7-864D-022B09E3DD67}
      Adobe MotionPicture Color Files-->MsiExec.exe /I{6B708481-748A-4EB4-97C1-CD386244FF77}
      Adobe Output Module-->MsiExec.exe /I{BB4E33EC-8181-4685-96F7-8554293DEC6A}
      Adobe PDF Library Files CS4-->MsiExec.exe /I{F93C84A6-0DC6-42AF-89FA-776F7C377353}
      Adobe Photoshop CS2-->msiexec /I {236BB7C4-4419-42FD-040C-1E257A25E34D}
      Adobe Photoshop CS3-->C:\Program Files\Fichiers communs\Adobe\Installers\719d6f144d0c086a0dfa7ff76bb9ac1\Setup.exe
      Adobe Photoshop CS3-->MsiExec.exe /I{3D7E3EC9-46CF-4359-9289-39CE01DFB82F}
      Adobe Photoshop CS3-->MsiExec.exe /I{C1FA4B3B-1625-4922-9C9D-780E8FCE161A}
      Adobe Photoshop CS4 Support-->MsiExec.exe /I{63E5CDBF-8214-4F03-84F8-CD3CE48639AD}
      Adobe Photoshop CS4-->C:\Program Files\Fichiers communs\Adobe\Installers\faf656ef605427ee2f42989c3ad31b8\Setup.exe --uninstall=1
      Adobe Photoshop CS4-->MsiExec.exe /I{B65BA85C-0A27-4BC0-A22D-A66F0E5B9494}
      Adobe Photoshop CS4-->MsiExec.exe /I{E4848436-0345-47E2-B648-8B522FCDA623}
      Adobe Reader 9 - Français-->MsiExec.exe /I{AC76BA86-7AD7-1036-7B44-A90000000001}
      Adobe Search for Help-->MsiExec.exe /I{F0E64E2E-3A60-40D8-A55D-92F6831875DA}
      Adobe Service Manager Extension-->MsiExec.exe /I{4943EFF5-229F-435D-BEA9-BE3CAEA783A7}
      Adobe Setup-->MsiExec.exe /I{0D67A4E4-5BE0-4C9A-8AD8-AB552B433F23}
      Adobe Setup-->MsiExec.exe /I{BE136F60-5D0F-4663-8B32-938A3EFD3FCB}
      Adobe Setup-->MsiExec.exe /I{CE67DBBB-2ED0-4F35-B482-0CFE4CFC1570}
      Adobe Setup-->MsiExec.exe /I{FF11004C-F42A-4A31-9BCF-7F5C8FDBE53C}
      Adobe Shockwave Player 11.5-->"C:\WINDOWS\system32\Adobe\Shockwave 11\uninstaller.exe"
      Adobe Stock Photos 1.0-->MsiExec.exe /I{786C5747-0C40-4930-9AFE-113BCE553101}
      Adobe Stock Photos CS3-->MsiExec.exe /I{29E5EA97-5F74-4A57-B8B2-D4F169117183}
      Adobe Type Support CS4-->MsiExec.exe /I{820D3F45-F6EE-4AAF-81EF-CE21FF21D230}
      Adobe Update Manager CS3-->MsiExec.exe /I{E69AE897-9E0B-485C-8552-7841F48D42D8}
      Adobe Update Manager CS4-->MsiExec.exe /I{05308C4E-7285-4066-BAE3-6B50DA6ED755}
      Adobe Version Cue CS3 Client-->MsiExec.exe /I{D0DFF92A-492E-4C40-B862-A74A173C25C5}
      Adobe WAS CS3-->MsiExec.exe /I{C5BD220A-EFE8-48A5-B70E-9503D535FACE}
      Adobe WinSoft Linguistics Plugin-->MsiExec.exe /I{184CE391-7E0E-4C63-9935-D7A10EDFD3C6}
      Adobe WinSoft Linguistics Plugin-->MsiExec.exe /I{3DA8DF9A-044E-46C4-8531-DEDBB0EE37FF}
      Adobe XMP Panels CS3-->MsiExec.exe /I{802771A9-A856-4A41-ACF7-1450E523C923}
      Adobe XMP Panels CS4-->MsiExec.exe /I{3A4E8896-C2E7-4084-A4A4-B8FD1894E739}
      AdobeColorCommonSetCMYK-->MsiExec.exe /I{68243FF8-83CA-466B-B2B8-9F99DA5479C4}
      AdobeColorCommonSetRGB-->MsiExec.exe /I{16E6D2C1-7C90-4309-8EC4-D2212690AAA4}
      Advertising Center-->MsiExec.exe /X{B2EC4A38-B545-4A00-8214-13FE0E915E6D}
      AHV content for Acrobat and Flash-->MsiExec.exe /I{6BBAA81D-6A7E-43AD-8889-2F002DCAAFDD}
      Ajouter ou supprimer Adobe Creative Suite 3 Web Premium-->C:\Program Files\Fichiers communs\Adobe\Installers\e7f691c6f2bf7b70c25ea19f3d73b6e\Setup.exe
      Akamai NetSession Interface-->C:\Program Files\Fichiers communs\Akamai\uninstall.exe
      Apple Application Support-->MsiExec.exe /I{553255F3-78FD-40F1-A6F8-6882140265FE}
      Apple Mobile Device Support-->MsiExec.exe /I{B5C3B892-0849-476C-9F46-B12F84819D57}
      Apple Software Update-->MsiExec.exe /I{6956856F-B6B3-4BE0-BA0B-8F495BE32033}
      Archiveur WinRAR-->C:\Program Files\WinRAR\uninstall.exe
      Assistant de connexion Windows Live-->MsiExec.exe /I{DCE8CD14-FBF5-4464-B9A4-E18E473546C7}
      Atheros Communications Inc.(R) AR8121/AR8113 Gigabit/Fast Ethernet Driver-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{3108C217-BE83-42E4-AE9E-A56A2A92E549}\Setup.exe" -l0x9 -removeonly
      Avira AntiVir Personal - Free Antivirus-->C:\Program Files\Avira\AntiVir Desktop\setup.exe /REMOVE
      Bonjour-->MsiExec.exe /X{76BC2442-0002-47FA-9617-43BAD82BEF4C}
      Canon CanoScan Toolbox 4.1-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{BCE46757-7674-4416-BEDB-68205A60409E}\Setup.exe" -l0x9 anything
      CCleaner (remove only)-->"C:\Program Files\CCleaner\uninst.exe"
      Connect-->MsiExec.exe /I{B29AD377-CC12-490A-A480-1452337C618D}
      Correctif pour Windows XP (KB952287)-->"C:\WINDOWS\$NtUninstallKB952287$\spuninst\spuninst.exe"
      Correctif pour Windows XP (KB961118)-->"C:\WINDOWS\$NtUninstallKB961118$\spuninst\spuninst.exe"
      Correctif pour Windows XP (KB970653-v3)-->"C:\WINDOWS\$NtUninstallKB970653-v3$\spuninst\spuninst.exe"
      Correctif pour Windows XP (KB976098-v2)-->"C:\WINDOWS\$NtUninstallKB976098-v2$\spuninst\spuninst.exe"
      Correctif pour Windows XP (KB979306)-->"C:\WINDOWS\$NtUninstallKB979306$\spuninst\spuninst.exe"
      DolbyFiles-->MsiExec.exe /X{B1ADF008-E898-4FE2-8A1F-690D9A06ACAF}
      EasyRecovery DataRecovery Essai-->C:\PROGRA~1\FICHIE~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{A074DE55-29EB-459C-99C9-3F26C5669ECB} /l1036
      eMule-->"C:\Program Files\eMule\Uninstall.exe"
      EPSON Logiciel imprimante-->C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\EPUPDATE.EXE /R
      EPSON Stylus C90_91_D92 Manuel-->C:\Program Files\EPSON\TPMANUAL\ESC90 91 D92\FRA\USE_G\DOCUNINS.EXE
      EPU-6 Engine-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{56B83336-FBC1-4C46-8613-90A9E3B440D6}\setup.exe" -l0x40c
      FILE RECOVERY for Windows-->C:\Program Files\FILE RECOVERY for Windows\Uninstall.exe
      Free Screen To Video V 1.1-->"C:\Program Files\Free Screen To Video\unins000.exe"
      Graffiti Studio 2.0-->"C:\Program Files\Graffiti Studio 2.0\unins000.exe"
      Grand Theft Auto IV-->"C:\Program Files\InstallShield Installation Information\{579BA58C-F33D-4970-9953-B94B43768AC3}\setup.exe" -runfromtemp -l0x040c -removeonly
      High Definition Audio Driver Package - KB888111-->"C:\WINDOWS\$NtUninstallKB888111WXPSP2$\spuninst\spuninst.exe"
      HijackThis 2.0.2-->"D:\dl\HijackThis.exe" /uninstall
      Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)-->C:\WINDOWS\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall /qb+ REBOOTPROMPT=""
      Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)-->C:\WINDOWS\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {A7EEA2F2-BFCD-4A54-A575-7B81A786E658} /qb+ REBOOTPROMPT=""
      HP Deskjet 5900 series-->C:\Program Files\HP\Digital Imaging\{79546A5F-AE7C-4693-8670-A3401B43ABD2}\setup\hpzscr01.exe -datfile hpfscr05.dat
      HP Imaging Device Functions 5.0-->C:\Program Files\HP\Digital Imaging\DigitalImagingMonitor\hpzscr01.exe -datfile hpqbud01.dat
      HP Software Update-->MsiExec.exe /X{15EE79F4-4ED1-4267-9B0F-351009325D7D}
      HP Solution Center & Imaging Support Tools 5.0-->C:\Program Files\HP\Digital Imaging\eSupport\hpzscr01.exe -datfile hpqbud05.dat
      Installation Windows Live-->C:\Program Files\Windows Live\Installer\wlarp.exe
      Installation Windows Live-->MsiExec.exe /I{46ABBC54-1872-4AA3-95E2-F2C063A63F31}
      IsoBuster 1.9-->"C:\Program Files\IsoBuster\Uninst\unins000.exe"
      iTunes-->MsiExec.exe /I{996A2FAA-7514-4628-9D12-A8FC34A0016E}
      Java(TM) 6 Update 17-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216016FF}
      kuler-->MsiExec.exe /I{098727E1-775A-4450-B573-3F441F1CA243}
      marvell 61xx-->C:\Program Files\Marvell\61xx\uninst-61xx.exe
      Menu Templates - Starter Kit-->MsiExec.exe /X{B78120A0-CF84-4366-A393-4D0A59BC546C}
      Microsoft .NET Framework 2.0 Language Pack - DEU-->C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0 Language Pack - DEU\install.exe
      Microsoft .NET Framework 2.0 Service Pack 2-->MsiExec.exe /I{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}
      Microsoft .NET Framework 3.0 Service Pack 2-->MsiExec.exe /I{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}
      Microsoft .NET Framework 3.5 SP1-->C:\WINDOWS\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setup.exe
      Microsoft .NET Framework 3.5 SP1-->MsiExec.exe /I{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}
      Microsoft Choice Guard-->MsiExec.exe /X{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}
      Microsoft Games for Windows - LIVE -->MsiExec.exe /X{4AA3D64E-9EC3-4B0F-AB91-5885AC55641F}
      Microsoft Games for Windows - LIVE Redistributable-->MsiExec.exe /X{FD052FB9-FE90-4438-B355-15EDC89D8FB1}
      Microsoft Internationalized Domain Names Mitigation APIs-->"C:\WINDOWS\$NtServicePackUninstallIDNMitigationAPIs$\spuninst\spuninst.exe"
      Microsoft National Language Support Downlevel APIs-->"C:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$\spuninst\spuninst.exe"
      Microsoft Office Access MUI (French) 2007-->MsiExec.exe /X{90120000-0015-040C-0000-0000000FF1CE}
      Microsoft Office Excel MUI (French) 2007-->MsiExec.exe /X{90120000-0016-040C-0000-0000000FF1CE}
      Microsoft Office InfoPath MUI (French) 2007-->MsiExec.exe /X{90120000-0044-040C-0000-0000000FF1CE}
      Microsoft Office Outlook MUI (French) 2007-->MsiExec.exe /X{90120000-001A-040C-0000-0000000FF1CE}
      Microsoft Office PowerPoint MUI (French) 2007-->MsiExec.exe /X{90120000-0018-040C-0000-0000000FF1CE}
      Microsoft Office Professional Plus 2007-->"C:\Program Files\Fichiers communs\Microsoft Shared\OFFICE12\Office Setup Controller\setup.exe" /uninstall PROPLUS /dll OSETUP.DLL
      Microsoft Office Professional Plus 2007-->MsiExec.exe /X{90120000-0011-0000-0000-0000000FF1CE}
      Microsoft Office Proof (Arabic) 2007-->MsiExec.exe /X{90120000-001F-0401-0000-0000000FF1CE}
      Microsoft Office Proof (Dutch) 2007-->MsiExec.exe /X{90120000-001F-0413-0000-0000000FF1CE}
      Microsoft Office Proof (English) 2007-->MsiExec.exe /X{90120000-001F-0409-0000-0000000FF1CE}
      Microsoft Office Proof (French) 2007-->MsiExec.exe /X{90120000-001F-040C-0000-0000000FF1CE}
      Microsoft Office Proof (German) 2007-->MsiExec.exe /X{90120000-001F-0407-0000-0000000FF1CE}
      Microsoft Office Proof (Spanish) 2007-->MsiExec.exe /X{90120000-001F-0C0A-0000-0000000FF1CE}
      Microsoft Office Proofing (French) 2007-->MsiExec.exe /X{90120000-002C-040C-0000-0000000FF1CE}
      Microsoft Office Publisher MUI (French) 2007-->MsiExec.exe /X{90120000-0019-040C-0000-0000000FF1CE}
      Microsoft Office Shared MUI (French) 2007-->MsiExec.exe /X{90120000-006E-040C-0000-0000000FF1CE}
      Microsoft Office Word MUI (French) 2007-->MsiExec.exe /X{90120000-001B-040C-0000-0000000FF1CE}
      Microsoft User-Mode Driver Framework Feature Pack 1.0-->"C:\WINDOWS\$NtUninstallWudf01000$\spuninst\spuninst.exe"
      Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053-->MsiExec.exe /X{770657D0-A123-3C07-8E44-1C83EC895118}
      Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
      Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{837b34e3-7c30-493c-8f6a-2b0f04e2912c}
      Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148-->MsiExec.exe /X{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}
      Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17-->MsiExec.exe /X{9A25302D-30C0-39D9-BD6F-21E6EC160475}
      Mise à jour de sécurité pour Lecteur Windows Media (KB952069)-->"C:\WINDOWS\$NtUninstallKB952069_WM9$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Lecteur Windows Media (KB954155)-->"C:\WINDOWS\$NtUninstallKB954155_WM9$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Lecteur Windows Media (KB968816)-->"C:\WINDOWS\$NtUninstallKB968816_WM9$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Lecteur Windows Media (KB973540)-->"C:\WINDOWS\$NtUninstallKB973540_WM9$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Lecteur Windows Media (KB973540)-->"C:\WINDOWS\$NtUninstallKB973540_WM9L$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Lecteur Windows Media (KB979402)-->"C:\WINDOWS\$NtUninstallKB979402_WM9$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows Internet Explorer 7 (KB938127-v2)-->"C:\WINDOWS\ie7updates\KB938127-v2-IE7\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows Internet Explorer 7 (KB974455)-->"C:\WINDOWS\ie7updates\KB974455-IE7\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows Internet Explorer 8 (KB971961)-->"C:\WINDOWS\ie8updates\KB971961-IE8\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows Internet Explorer 8 (KB976325)-->"C:\WINDOWS\ie8updates\KB976325-IE8\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows Internet Explorer 8 (KB978207)-->"C:\WINDOWS\ie8updates\KB978207-IE8\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows Internet Explorer 8 (KB981332)-->"C:\WINDOWS\ie8updates\KB981332-IE8\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB923561)-->"C:\WINDOWS\$NtUninstallKB923561$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB923789)-->C:\WINDOWS\system32\MacroMed\Flash\genuinst.exe C:\WINDOWS\system32\MacroMed\Flash\KB923789.inf
      Mise à jour de sécurité pour Windows XP (KB941569)-->"C:\WINDOWS\$NtUninstallKB941569$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB946648)-->"C:\WINDOWS\$NtUninstallKB946648$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB950762)-->"C:\WINDOWS\$NtUninstallKB950762$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB950974)-->"C:\WINDOWS\$NtUninstallKB950974$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB951066)-->"C:\WINDOWS\$NtUninstallKB951066$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB951376-v2)-->"C:\WINDOWS\$NtUninstallKB951376-v2$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB951748)-->"C:\WINDOWS\$NtUninstallKB951748$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB952004)-->"C:\WINDOWS\$NtUninstallKB952004$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB952954)-->"C:\WINDOWS\$NtUninstallKB952954$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB954459)-->"C:\WINDOWS\$NtUninstallKB954459$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB955069)-->"C:\WINDOWS\$NtUninstallKB955069$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB956572)-->"C:\WINDOWS\$NtUninstallKB956572$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB956744)-->"C:\WINDOWS\$NtUninstallKB956744$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB956802)-->"C:\WINDOWS\$NtUninstallKB956802$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB956803)-->"C:\WINDOWS\$NtUninstallKB956803$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB956844)-->"C:\WINDOWS\$NtUninstallKB956844$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB957097)-->"C:\WINDOWS\$NtUninstallKB957097$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB958644)-->"C:\WINDOWS\$NtUninstallKB958644$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB958687)-->"C:\WINDOWS\$NtUninstallKB958687$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB958869)-->"C:\WINDOWS\$NtUninstallKB958869$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB959426)-->"C:\WINDOWS\$NtUninstallKB959426$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB960803)-->"C:\WINDOWS\$NtUninstallKB960803$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB960859)-->"C:\WINDOWS\$NtUninstallKB960859$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB961371-v2)-->"C:\WINDOWS\$NtUninstallKB961371-v2$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB961501)-->"C:\WINDOWS\$NtUninstallKB961501$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB968537)-->"C:\WINDOWS\$NtUninstallKB968537$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB969059)-->"C:\WINDOWS\$NtUninstallKB969059$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB969947)-->"C:\WINDOWS\$NtUninstallKB969947$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB970238)-->"C:\WINDOWS\$NtUninstallKB970238$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB970430)-->"C:\WINDOWS\$NtUninstallKB970430$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB971468)-->"C:\WINDOWS\$NtUninstallKB971468$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB971486)-->"C:\WINDOWS\$NtUninstallKB971486$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB971557)-->"C:\WINDOWS\$NtUninstallKB971557$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB971633)-->"C:\WINDOWS\$NtUninstallKB971633$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB971657)-->"C:\WINDOWS\$NtUninstallKB971657$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB971961)-->"C:\WINDOWS\$NtUninstallKB971961$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB973354)-->"C:\WINDOWS\$NtUninstallKB973354$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB973507)-->"C:\WINDOWS\$NtUninstallKB973507$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB973525)-->"C:\WINDOWS\$NtUninstallKB973525$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB973869)-->"C:\WINDOWS\$NtUninstallKB973869$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB973904)-->"C:\WINDOWS\$NtUninstallKB973904$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB974112)-->"C:\WINDOWS\$NtUninstallKB974112$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB974318)-->"C:\WINDOWS\$NtUninstallKB974318$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB974392)-->"C:\WINDOWS\$NtUninstallKB974392$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB974455)-->"C:\WINDOWS\$NtUninstallKB974455$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB974571)-->"C:\WINDOWS\$NtUninstallKB974571$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB975025)-->"C:\WINDOWS\$NtUninstallKB975025$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB975467)-->"C:\WINDOWS\$NtUninstallKB975467$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB975560)-->"C:\WINDOWS\$NtUninstallKB975560$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB975561)-->"C:\WINDOWS\$NtUninstallKB975561$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB975713)-->"C:\WINDOWS\$NtUninstallKB975713$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB977165)-->"C:\WINDOWS\$NtUninstallKB977165$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB977816)-->"C:\WINDOWS\$NtUninstallKB977816$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB977914)-->"C:\WINDOWS\$NtUninstallKB977914$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB978037)-->"C:\WINDOWS\$NtUninstallKB978037$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB978251)-->"C:\WINDOWS\$NtUninstallKB978251$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB978262)-->"C:\WINDOWS\$NtUninstallKB978262$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB978338)-->"C:\WINDOWS\$NtUninstallKB978338$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB978601)-->"C:\WINDOWS\$NtUninstallKB978601$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB979309)-->"C:\WINDOWS\$NtUninstallKB979309$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB979683)-->"C:\WINDOWS\$NtUninstallKB979683$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB980232)-->"C:\WINDOWS\$NtUninstallKB980232$\spuninst\spuninst.exe"
      Mise à jour pour Windows Internet Explorer 8 (KB976662)-->"C:\WINDOWS\ie8updates\KB976662-IE8\spuninst\spuninst.exe"
      Mise à jour pour Windows Internet Explorer 8 (KB978506)-->"C:\WINDOWS\ie8updates\KB978506-IE8\spuninst\spuninst.exe"
      0
      1. Mise à jour pour Windows XP (KB951978)-->"C:\WINDOWS\$NtUninstallKB951978$\spuninst\spuninst.exe"
        Mise à jour pour Windows XP (KB955759)-->"C:\WINDOWS\$NtUninstallKB955759$\spuninst\spuninst.exe"
        Mise à jour pour Windows XP (KB961503)-->"C:\WINDOWS\$NtUninstallKB961503$\spuninst\spuninst.exe"
        Mise à jour pour Windows XP (KB967715)-->"C:\WINDOWS\$NtUninstallKB967715$\spuninst\spuninst.exe"
        Mise à jour pour Windows XP (KB968389)-->"C:\WINDOWS\$NtUninstallKB968389$\spuninst\spuninst.exe"
        Mise à jour pour Windows XP (KB971737)-->"C:\WINDOWS\$NtUninstallKB971737$\spuninst\spuninst.exe"
        Mise à jour pour Windows XP (KB973687)-->"C:\WINDOWS\$NtUninstallKB973687$\spuninst\spuninst.exe"
        Mise à jour pour Windows XP (KB973815)-->"C:\WINDOWS\$NtUninstallKB973815$\spuninst\spuninst.exe"
        MobileMe Control Panel-->MsiExec.exe /I{51F96AEC-D902-4434-A0DC-B9692A21AE7C}
        Movie Templates - Starter Kit-->MsiExec.exe /X{E498385E-1C51-459A-B45F-1721E37AA1A0}
        Mozilla Firefox (3.6.3)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
        MSVCRT-->MsiExec.exe /I{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}
        MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
        MSXML 4.0 SP2 (KB973688)-->MsiExec.exe /I{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}
        Multimedia Card Reader-->C:\Program Files\Fichiers communs\InstallShield\Driver\8\Intel 32\IDriver.exe /M{FD0955C7-C64C-45DC-A991-FDC4E50C4E09} /l1036
        Nero 9 Trial-->C:\Program Files\Fichiers communs\Nero\Nero ProductInstaller 4\SetupX.exe REMOVESERIALNUMBER="8M01-A0C9-8W34-XC23-MT2U-8T2L-5XX3-9WXU"
        Nero BurnRights-->MsiExec.exe /X{7829DB6F-A066-4E40-8912-CB07887C20BB}
        Nero ControlCenter-->MsiExec.exe /X{BD5CA0DA-71AD-43DA-B19E-6EEE0C9ADC9A}
        Nero CoverDesigner-->MsiExec.exe /X{62AC81F6-BDD3-4110-9D36-3E9EAAB40999}
        Nero DiscSpeed-->MsiExec.exe /X{869200DB-287A-4DC0-B02B-2B6787FBCD4C}
        Nero DriveSpeed-->MsiExec.exe /X{33CF58F5-48D8-4575-83D6-96F574E4D83A}
        Nero InfoTool-->MsiExec.exe /X{FBCDFD61-7DCF-4E71-9226-873BA0053139}
        Nero Installer-->MsiExec.exe /X{E8A80433-302B-4FF1-815D-FCC8EAC482FF}
        Nero PhotoSnap-->MsiExec.exe /X{9E82B934-9A25-445B-B8DF-8012808074AC}
        Nero Recode-->MsiExec.exe /X{359CFC0A-BEB1-440D-95BA-CF63A86DA34F}
        Nero Rescue Agent-->MsiExec.exe /X{368BA326-73AD-4351-84ED-3C0A7A52CC53}
        Nero ShowTime-->MsiExec.exe /X{D9DCF92E-72EB-412D-AC71-3B01276E5F8B}
        Nero StartSmart-->MsiExec.exe /X{7748AC8C-18E3-43BB-959B-088FAEA16FB2}
        Nero Vision-->MsiExec.exe /X{43E39830-1826-415D-8BAE-86845787B54B}
        Nero WaveEditor-->MsiExec.exe /X{A209525B-3377-43F4-B886-32F6B6E7356F}
        NeroBurningROM-->MsiExec.exe /X{D025A639-B9C9-417D-8531-208859000AF8}
        NeroExpress-->MsiExec.exe /X{595A3116-40BB-4E0F-A2E8-D7951DA56270}
        neroxml-->MsiExec.exe /I{56C049BE-79E9-4502-BEA7-9754A3E60F9B}
        Notepad++-->C:\Program Files\Notepad++\uninstall.exe
        NVIDIA Display Control Panel-->C:\Program Files\NVIDIA Corporation\Uninstall\nvuninst.exe DisplayControlPanel
        NVIDIA Drivers-->C:\WINDOWS\system32\nvuninst.exe UninstallGUI
        NVIDIA nView Desktop Manager-->C:\Program Files\NVIDIA Corporation\nView\nViewSetup.exe -uninstall
        Outil de téléchargement Windows Live-->MsiExec.exe /I{205C6BDD-7B73-42DE-8505-9A093F35A238}
        PDF Settings CS4-->MsiExec.exe /I{35D94F92-1D3A-43C5-8605-EA268B1A7BD9}
        PDFCreator-->C:\Program Files\PDFCreator\unins000.exe
        pdfforge Toolbar v1.1.2-->MsiExec.exe /X{5791B7D3-8B34-4218-9750-6A8E45D0AD32}
        Photoshop Camera Raw-->MsiExec.exe /I{CC75AB5C-2110-4A7F-AF52-708680D22FE8}
        Picasa 3-->"C:\Program Files\Google\Picasa3\Uninstall.exe"
        Post-it® Software Notes Lite-->"C:\Program Files\post it\PSNLite\Uninstall.exe" -Prog"C:\Program Files\post it\PSNLite\PsnLite.exe" -INI"C:\Program Files\post it\PSNLite\uninst.ini"
        Pro Evolution Soccer 2010-->MsiExec.exe /X{283FFB23-8751-4B08-ACB8-5E0F8BCF7727}
        QuickTime-->MsiExec.exe /I{28BE306E-5DA6-4F9C-BDB0-DBA3C8C6FFFD}
        Ralink RT7x Wireless LAN Card-->C:\Program Files\InstallShield Installation Information\{E91E8912-769D-42F0-8408-0E329443BABC}\setup.exe -runfromtemp -l0x0009 -removeonly
        Realtek High Definition Audio Driver-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}\setup.exe" -l0x40c -removeonly
        Rockstar Games Social Club-->"C:\Program Files\InstallShield Installation Information\{08B3869E-D282-424C-9AFC-870E04A4BA14}\setup.exe" -runfromtemp -l0x040c -removeonly
        Safari-->MsiExec.exe /I{A67BB21E-D419-45BB-AB86-7D87D14BBCE2}
        Satsuki Decoder Pack 4301-->C:\Program Files\Satsuki Decoder Pack\Uninstall.exe
        Secabo Production Suite1-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\10\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{E17705B3-CE3D-457A-A04D-CCE5263BE790}\SETUP.EXE" -l0x40c -removeonly
        Security Update for 2007 Microsoft Office System (KB951944)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {797AE457-BA17-4BBC-B501-25FB3A0103C7}
        Segoe UI-->MsiExec.exe /I{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}
        Sentinel Protection Installer 7.4.0-->MsiExec.exe /I{5A180ED5-0AC1-410A-B790-5E0319CD0A93}
        Simplify Media-->MsiExec.exe /X{56E2A9E0-9249-446C-896F-D541211C282E}
        SoundTrax-->MsiExec.exe /X{C5A7CB6C-E76D-408F-BA0E-85605420FE9D}
        Suite Shared Configuration CS4-->MsiExec.exe /I{842B4B72-9E8F-4962-B3C1-1C422A5C4434}
        SuperCopier2-->"C:\Program Files\SuperCopier2\SC2Uninst.exe"
        Tablette Wacom-->C:\Program Files\Tablet\Wacom\Remove.exe /u
        Update for 2007 Microsoft Office System (KB967642)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {C444285D-5E4F-48A4-91DD-47AAAA68E92D}
        Update for Microsoft .NET Framework 3.5 SP1 (KB963707)-->C:\WINDOWS\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {B2AE9C82-DC7B-3641-BFC8-87275C4F3607} /qb+ REBOOTPROMPT=""
        Visual C++ 2008 x86 Runtime - (v9.0.30729)-->MsiExec.exe /X{F333A33D-125C-32A2-8DCE-5C5D14231E27}
        Visual C++ 2008 x86 Runtime - v9.0.30729.01-->C:\WINDOWS\system32\msiexec.exe /x {F333A33D-125C-32A2-8DCE-5C5D14231E27} /qb+ REBOOTPROMPT=""
        VLC media player 1.0.3-->C:\Program Files\VideoLAN\VLC\uninstall.exe
        Vuze_Remote Toolbar-->C:\PROGRA~1\VUZE_R~1\UNWISE.EXE /U C:\PROGRA~1\VUZE_R~1\INSTALL.LOG
        Vuze-->C:\Program Files\Vuze\uninstall.exe
        WebTablet IE Plugin-->"C:\Program Files\TabletPlugins\ieUninstall.exe" /S
        WebTablet Netscape Plugin-->"C:\Program Files\TabletPlugins\npUninstall.exe" /S
        WiFi Station N-->C:\Program Files\InstallShield Installation Information\{54A9A9E1-8C4C-44FE-AA6B-182EA1E779FD}\setup.exe -runfromtemp -l0x040c -removeonly
        Windows Internet Explorer 8-->"C:\WINDOWS\ie8\spuninst\spuninst.exe"
        Windows Live Call-->MsiExec.exe /I{82C7B308-0BDD-49D8-8EA5-9CD3A3F9DF41}
        Windows Live Communications Platform-->MsiExec.exe /I{3B4E636E-9D65-4D67-BA61-189800823F52}
        Windows Live Messenger-->MsiExec.exe /X{770F1BEC-2871-4E70-B837-FB8525FFA3B1}
        Windows Live OneCare safety scanner-->RunDll32.exe "C:\Program Files\Windows Live Safety Center\wlscCore.dll",UninstallFunction WLSC_SCANNER_PRODUCT
        Windows Media Format 11 runtime-->"C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll
        Windows Media Format 11 runtime-->"C:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe"
        Windows XP Service Pack 3-->"C:\WINDOWS\$NtServicePackUninstall$\spuninst\spuninst.exe"

        ======Security center information======

        AV: AntiVir Desktop

        ======System event log======

        Computer Name: RENO-8589D5E46B
        Event Code: 7036
        Message: Le service Pml Driver HPZ12 est entré dans l'état : en cours d'exécution.

        Record Number: 29439
        Source Name: Service Control Manager
        Time Written: 20100329232202.000000+120
        Event Type: Informations
        User:

        Computer Name: RENO-8589D5E46B
        Event Code: 7036
        Message: Le service Pml Driver HPZ12 est entré dans l'état : arrêté.

        Record Number: 29438
        Source Name: Service Control Manager
        Time Written: 20100329232003.000000+120
        Event Type: Informations
        User:

        Computer Name: RENO-8589D5E46B
        Event Code: 7035
        Message: Un contrôle Démarrer a correctement été envoyé au service Pml Driver HPZ12.

        Record Number: 29437
        Source Name: Service Control Manager
        Time Written: 20100329232002.000000+120
        Event Type: Informations
        User: RENO-8589D5E46B\renaud

        Computer Name: RENO-8589D5E46B
        Event Code: 7036
        Message: Le service Pml Driver HPZ12 est entré dans l'état : en cours d'exécution.

        Record Number: 29436
        Source Name: Service Control Manager
        Time Written: 20100329232002.000000+120
        Event Type: Informations
        User:

        Computer Name: RENO-8589D5E46B
        Event Code: 7036
        Message: Le service Pml Driver HPZ12 est entré dans l'état : arrêté.

        Record Number: 29435
        Source Name: Service Control Manager
        Time Written: 20100329231803.000000+120
        Event Type: Informations
        User:

        =====Application event log=====

        Computer Name: RENO-8589D5E46B
        Event Code: 4113
        Message: AntiVir a détecté dans le fichier
        C:\System Volume Information\_restore{7469EBB7-4D8D-4584-8781-32D28CF2BD81}\RP186\A0027877.exe
        un code suspect avec la désignation 'TR/Dldr.Swizzor.Gen2'!

        Record Number: 2694
        Source Name: Avira AntiVir
        Time Written: 20100320000622.000000+060
        Event Type: Avertissement
        User: AUTORITE NT\SYSTEM

        Computer Name: RENO-8589D5E46B
        Event Code: 4113
        Message: AntiVir a détecté dans le fichier
        C:\System Volume Information\_restore{7469EBB7-4D8D-4584-8781-32D28CF2BD81}\RP186\A0027877.exe
        un code suspect avec la désignation 'TR/Dldr.Swizzor.Gen2'!

        Record Number: 2693
        Source Name: Avira AntiVir
        Time Written: 20100319230622.000000+060
        Event Type: Avertissement
        User: AUTORITE NT\SYSTEM

        Computer Name: RENO-8589D5E46B
        Event Code: 4113
        Message: AntiVir a détecté dans le fichier
        C:\System Volume Information\_restore{7469EBB7-4D8D-4584-8781-32D28CF2BD81}\RP186\A0027877.exe
        un code suspect avec la désignation 'TR/Dldr.Swizzor.Gen2'!

        Record Number: 2692
        Source Name: Avira AntiVir
        Time Written: 20100319220622.000000+060
        Event Type: Avertissement
        User: AUTORITE NT\SYSTEM

        Computer Name: RENO-8589D5E46B
        Event Code: 4113
        Message: AntiVir a détecté dans le fichier
        C:\System Volume Information\_restore{7469EBB7-4D8D-4584-8781-32D28CF2BD81}\RP186\A0027877.exe
        un code suspect avec la désignation 'TR/Dldr.Swizzor.Gen2'!

        Record Number: 2691
        Source Name: Avira AntiVir
        Time Written: 20100319211834.000000+060
        Event Type: Avertissement
        User: AUTORITE NT\SYSTEM

        Computer Name: RENO-8589D5E46B
        Event Code: 4113
        Message: AntiVir a détecté dans le fichier
        C:\Documents and Settings\renaud\Application Data\filebibteam\Gramblue.exe
        un code suspect avec la désignation 'TR/Dldr.Swizzor.Gen2'!

        Record Number: 2690
        Source Name: Avira AntiVir
        Time Written: 20100319180848.000000+060
        Event Type: Avertissement
        User: AUTORITE NT\SYSTEM

        ======Environment variables======

        "ComSpec"=%SystemRoot%\system32\cmd.exe
        "Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;C:\Program Files\Fichiers communs\Adobe\AGL;C:\Program Files\QuickTime\QTSystem\
        "windir"=%SystemRoot%
        "FP_NO_HOST_CHECK"=NO
        "OS"=Windows_NT
        "PROCESSOR_ARCHITECTURE"=x86
        "PROCESSOR_LEVEL"=6
        "PROCESSOR_IDENTIFIER"=x86 Family 6 Model 15 Stepping 11, GenuineIntel
        "PROCESSOR_REVISION"=0f0b
        "NUMBER_OF_PROCESSORS"=4
        "PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
        "TEMP"=%SystemRoot%\TEMP
        "TMP"=%SystemRoot%\TEMP
        "RGSCLauncher"=C:\Program Files\Rockstar Games\Rockstar Games Social Club
        "RGSC"=C:\Program Files\Rockstar Games\Rockstar Games Social Club\1_0_0_0
        "asl.log"=Destination=file;OnFirstLog=command,environment
        "CLASSPATH"=.;C:\Program Files\Java\jre6\lib\ext\QTJava.zip
        "QTJAVA"=C:\Program Files\Java\jre6\lib\ext\QTJava.zip

        -----------------EOF-----------------
        0
        1. pareil, le log.txt en 2 fois.

          Logfile of random's system information tool 1.06 (written by random/random)
          Run by renaud at 2010-04-22 15:56:52
          Microsoft Windows XP Professionnel Service Pack 3
          System drive C: has 243 GB (80%) free of 305 GB
          Total RAM: 2047 MB (34% free)

          Logfile of Trend Micro HijackThis v2.0.2
          Scan saved at 15:57:16, on 22/04/2010
          Platform: Windows XP SP3 (WinNT 5.01.2600)
          MSIE: Internet Explorer v8.00 (8.00.6001.18702)
          Boot mode: Normal

          Running processes:
          C:\WINDOWS\System32\smss.exe
          C:\WINDOWS\system32\winlogon.exe
          C:\WINDOWS\system32\services.exe
          C:\WINDOWS\system32\lsass.exe
          C:\WINDOWS\system32\nvsvc32.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
          C:\WINDOWS\system32\spoolsv.exe
          C:\Program Files\Avira\AntiVir Desktop\sched.exe
          C:\WINDOWS\System32\svchost.exe
          C:\Program Files\Avira\AntiVir Desktop\avguard.exe
          C:\Program Files\Fichiers communs\Apple\Mobile Device Support\AppleMobileDeviceService.exe
          C:\Program Files\Application Updater\ApplicationUpdater.exe
          C:\Program Files\Bonjour\mDNSResponder.exe
          C:\WINDOWS\system32\HerculesWiFiService.exe
          C:\Program Files\Java\jre6\bin\jqs.exe
          C:\Program Files\Fichiers communs\Nero\Nero BackItUp 4\NBService.exe
          C:\WINDOWS\system32\HPZipm12.exe
          C:\WINDOWS\system32\SAiDownloader.exe
          C:\Program Files\Fichiers communs\SafeNet Sentinel\Sentinel Keys Server\sntlkeyssrvr.exe
          C:\Program Files\Fichiers communs\SafeNet Sentinel\Sentinel Protection Server\WinNT\spnsrvnt.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\system32\Wacom_Tablet.exe
          C:\WINDOWS\Explorer.EXE
          C:\WINDOWS\system32\WTablet\Wacom_TabletUser.exe
          C:\WINDOWS\system32\Wacom_Tablet.exe
          C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
          C:\WINDOWS\System32\WScript.exe
          C:\WINDOWS\System32\WScript.exe
          C:\WINDOWS\system32\wscntfy.exe
          C:\WINDOWS\system32\ctfmon.exe
          C:\Program Files\SuperCopier2\SuperCopier2.exe
          C:\Program Files\PrintScreen\PrintScreen\PrintScreen.exe
          C:\Program Files\Messenger\msmsgs.exe
          C:\Program Files\Simplify Media\SimplifyMedia.exe
          C:\WINDOWS\System32\WScript.exe
          C:\Program Files\post it\PSNLite\PsnLite.exe
          C:\PROGRA~1\POSTIT~1\PSNLite\PSNGive.exe
          C:\Documents and Settings\renaud\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
          C:\Documents and Settings\renaud\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
          C:\Documents and Settings\renaud\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
          C:\WINDOWS\system32\Wscript.exe
          C:\WINDOWS\system32\Wscript.exe
          C:\Documents and Settings\renaud\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
          C:\Program Files\iTunes\iTunes.exe
          C:\Program Files\iPod\bin\iPodService.exe
          C:\Documents and Settings\renaud\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
          C:\Program Files\KONAMI\Pro Evolution Soccer 2010\pes2010.exe
          D:\dl\RSIT.exe
          D:\dl\renaud.exe

          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
          R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = // ;) anna I Liebe YOU ==> MILK@3|_!!!
          R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local
          R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
          R3 - URLSearchHook: (no name) - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:\Program Files\pdfforge Toolbar\SearchSettings.dll
          R3 - URLSearchHook: Vuze Remote Toolbar - {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files\Vuze_Remote\tbVuze.dll
          O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
          O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
          O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
          O2 - BHO: pdfforge Toolbar - {B922D405-6D13-4A2B-AE89-08A030DA4402} - C:\Program Files\pdfforge Toolbar\IE\1.1.2\pdfforgeToolbarIE.dll (file missing)
          O2 - BHO: Vuze Remote Toolbar - {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files\Vuze_Remote\tbVuze.dll
          O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
          O2 - BHO: (no name) - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:\Program Files\pdfforge Toolbar\SearchSettings.dll
          O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
          O3 - Toolbar: pdfforge Toolbar - {B922D405-6D13-4A2B-AE89-08A030DA4402} - C:\Program Files\pdfforge Toolbar\IE\1.1.2\pdfforgeToolbarIE.dll (file missing)
          O3 - Toolbar: Vuze Remote Toolbar - {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files\Vuze_Remote\tbVuze.dll
          O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
          O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
          O4 - HKLM\..\Run: [winrun.dll] C:\WINDOWS\winrun.dll.vbs
          O4 - HKLM\..\Run: [officescan] C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\officescan.vbs
          O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
          O4 - HKCU\..\Run: [SuperCopier2.exe] C:\Program Files\SuperCopier2\SuperCopier2.exe
          O4 - HKCU\..\Run: [Gadwin PrintScreen 2.6] C:\Program Files\PrintScreen\PrintScreen\PrintScreen.exe /nosplash
          O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
          O4 - HKCU\..\Run: [EPSON Stylus D92 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIBZE.EXE /FU "C:\WINDOWS\TEMP\E_S39D6.tmp" /EF "HKCU"
          O4 - HKCU\..\Run: [Simplify Media] "C:\Program Files\Simplify Media\SimplifyMedia.exe"
          O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
          O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
          O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
          O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
          O4 - Global Startup: officescan.vbs
          O4 - Global Startup: Post-it® Software Notes Lite.lnk = C:\Program Files\post it\PSNLite\PsnLite.exe
          O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
          O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
          O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
          O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
          O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
          O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
          O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
          O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
          O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/...
          O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
          O17 - HKLM\System\CCS\Services\Tcpip\..\{1E5897DE-2C78-4379-9899-997C43B62D50}: NameServer = 192.168.1.254
          O17 - HKLM\System\CS1\Services\Tcpip\..\{1E5897DE-2C78-4379-9899-997C43B62D50}: NameServer = 192.168.1.254
          O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
          O23 - Service: Avira AntiVir Planificateur (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
          O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
          O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\AppleMobileDeviceService.exe
          O23 - Service: Application Updater - Spigot, Inc. - C:\Program Files\Application Updater\ApplicationUpdater.exe
          O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
          O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Fichiers communs\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
          O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
          O23 - Service: HerculesWiFi - Guillemot Corporation - C:\WINDOWS\system32\HerculesWiFiService.exe
          O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
          O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
          O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
          O23 - Service: Nero BackItUp Scheduler 4.0 - Nero AG - C:\Program Files\Fichiers communs\Nero\Nero BackItUp 4\NBService.exe
          O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
          O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
          O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - C:\Program Files\WinPcap\rpcapd.exe (file missing)
          O23 - Service: SAiDownloader - TODO: <Company name> - C:\WINDOWS\system32\SAiDownloader.exe
          O23 - Service: Sentinel Keys Server (SentinelKeysServer) - SafeNet, Inc. - C:\Program Files\Fichiers communs\SafeNet Sentinel\Sentinel Keys Server\sntlkeyssrvr.exe
          O23 - Service: Sentinel Protection Server (SentinelProtectionServer) - SafeNet, Inc - C:\Program Files\Fichiers communs\SafeNet Sentinel\Sentinel Protection Server\WinNT\spnsrvnt.exe
          O23 - Service: TabletServiceWacom - Wacom Technology, Corp. - C:\WINDOWS\system32\Wacom_Tablet.exe
          0
          1. [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
            "%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
            "%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
            "C:\Program Files\Fichiers communs\SafeNet Sentinel\Sentinel Protection Server\WinNT\spnsrvnt.exe"="C:\Program Files\Fichiers communs\SafeNet Sentinel\Sentinel Protection Server\WinNT\spnsrvnt.exe:*:Enabled:Sentinel Protection Server"
            "C:\Program Files\Fichiers communs\SafeNet Sentinel\Sentinel Keys Server\sntlkeyssrvr.exe"="C:\Program Files\Fichiers communs\SafeNet Sentinel\Sentinel Keys Server\sntlkeyssrvr.exe:*:Enabled:Sentinel Keys Server"
            "C:\Program Files\Windows Live\Messenger\wlcsdk.exe"="C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call"
            "C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"
            "C:\Program Files\Fichiers communs\Adobe\CS4ServiceManager\CS4ServiceManager.exe"="C:\Program Files\Fichiers communs\Adobe\CS4ServiceManager\CS4ServiceManager.exe:*:Enabled:Adobe CSI CS4"
            "Y:\eSKernel.exe"="Y:\eSKernel.exe:*:Enabled:Bbox assistant d'installation"
            "D:\dl\azureus\[PC Game] PES Pro Evolution Soccer 2010 + crack\[PC] PES 2010 + crack\PES 2010\Crack\pes2010.exe"="D:\dl\azureus\[PC Game] PES Pro Evolution Soccer 2010 + crack\[PC] PES 2010 + crack\PES 2010\Crack\pes2010.exe:*:Enabled:Pro Evolution Soccer 2010"
            "C:\Program Files\KONAMI\Pro Evolution Soccer 2010\pes2010.exe"="C:\Program Files\KONAMI\Pro Evolution Soccer 2010\pes2010.exe:*:Enabled:Pro Evolution Soccer 2010"
            "C:\Program Files\Rockstar Games\Rockstar Games Social Club\RGSCLauncher.exe"="C:\Program Files\Rockstar Games\Rockstar Games Social Club\RGSCLauncher.exe:*:Enabled:Rockstar Games Social Club"
            "C:\Program Files\Rockstar Games\Grand Theft Auto IV\LaunchGTAIV.exe"="C:\Program Files\Rockstar Games\Grand Theft Auto IV\LaunchGTAIV.exe:*:Enabled:Grand Theft Auto IV"
            "C:\Program Files\Bonjour\mDNSResponder.exe"="C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour"
            "C:\Program Files\iTunes\iTunes.exe"="C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes"
            "C:\Program Files\Vuze\Azureus.exe"="C:\Program Files\Vuze\Azureus.exe:*:Enabled:Azureus / Vuze"

            [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
            "%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
            "%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
            "C:\Program Files\Windows Live\Messenger\wlcsdk.exe"="C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call"
            "C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"

            [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{105e221a-ea5d-11de-bc4e-0008d38095b9}]
            shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Wscript.exe winrun.vbs

            [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{1baf1ae1-2ba1-11df-bc5a-0008d38095b9}]
            shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Wscript.exe winrun.vbs

            [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{4291ca99-d36f-11de-bc2b-0008d38095b9}]
            shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL RUNdLl32.ExE .\RECYCLER\S-5-3-42-2819952290-8240758988-879315005-3665\jwgkvsq.vmx,ahaezedrn

            [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{43d858f8-c86c-11de-bc25-0022154398aa}]
            shell\Auto\command - L:\RavMonE.exe e
            shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL RavMonE.exe e

            [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{464398ff-ba4a-11de-965f-806d6172696f}]
            shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Wscript.exe winrun.vbs

            [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{5828734c-ba5a-11de-bc08-0022154398aa}]
            shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Wscript.exe winrun.vbs

            [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{5b0d4b16-c7ac-11de-bc24-0014d15322c5}]
            shell\AutoRun\command - K:\LaunchU3.exe -a

            [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{94da6820-efc9-11de-bc51-0008d38095b9}]
            shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Wscript.exe winrun.vbs

            ======List of files/folders created in the last 1 months======

            2010-04-22 15:56:52 ----D---- C:\rsit
            2010-04-22 09:11:43 ----HDC---- C:\Documents and Settings\All Users\Application Data\{74D08EB8-01D1-4BAE-91E3-F30C1B031AC6}
            2010-04-21 21:19:05 ----A---- C:\WINDOWS\system32\lsdelete.exe
            2010-04-21 19:23:15 ----D---- C:\Program Files\Lavasoft
            2010-04-21 19:23:15 ----D---- C:\Documents and Settings\All Users\Application Data\Lavasoft
            2010-04-21 18:23:17 ----D---- C:\Program Files\CCleaner
            2010-04-21 08:55:19 ----D---- C:\Program Files\Simplify Media
            2010-04-15 21:13:22 ----D---- C:\Program Files\Vuze_Remote
            2010-04-15 21:13:22 ----D---- C:\Program Files\Conduit
            2010-04-15 15:52:53 ----D---- C:\flex_sdk_3.4.1.10084
            2010-04-13 15:51:10 ----RASH---- C:\winrun.vbs
            2010-04-13 15:51:10 ----RASH---- C:\WINDOWS\winrun.dll.vbs
            2010-04-01 00:37:28 ----D---- C:\Documents and Settings\renaud\Application Data\Apowersoft
            2010-03-31 13:54:46 ----A---- C:\WINDOWS\system32\PICSDK2.dll
            2010-03-31 13:54:46 ----A---- C:\WINDOWS\system32\PICSDK.ini
            2010-03-31 13:54:46 ----A---- C:\WINDOWS\system32\PICSDK.dll
            2010-03-31 13:54:46 ----A---- C:\WINDOWS\system32\PICEntry.dll
            2010-03-31 13:54:46 ----A---- C:\WINDOWS\system32\EpPicPrt.dll
            2010-03-31 13:54:46 ----A---- C:\WINDOWS\system32\EPPicMgr.dll
            2010-03-31 13:54:22 ----A---- C:\WINDOWS\system32\E_DCINST.DLL
            2010-03-31 13:54:21 ----A---- C:\WINDOWS\system32\E_FLBBZE.DLL
            2010-03-31 13:54:21 ----A---- C:\WINDOWS\system32\E_FD4BBZE.DLL
            2010-03-31 13:51:14 ----D---- C:\Program Files\EPSON
            2010-03-31 13:51:12 ----D---- C:\Documents and Settings\All Users\Application Data\EPSON
            2010-03-31 13:51:06 ----A---- C:\WINDOWS\CDED92Euro.ini
            2010-03-31 10:50:09 ----D---- C:\Program Files\iPod
            2010-03-31 10:49:59 ----D---- C:\Program Files\iTunes
            2010-03-31 10:49:59 ----D---- C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
            2010-03-31 10:46:11 ----D---- C:\Program Files\QuickTime
            2010-03-26 11:39:25 ----D---- C:\Documents and Settings\renaud\Application Data\Facebook

            ======List of files/folders modified in the last 1 months======

            2010-04-22 15:56:04 ----D---- C:\WINDOWS\Prefetch
            2010-04-22 15:36:45 ----D---- C:\Program Files\Fichiers communs\Akamai
            2010-04-22 10:35:59 ----SD---- C:\WINDOWS\Tasks
            2010-04-22 09:20:10 ----D---- C:\WINDOWS\system32
            2010-04-22 09:20:08 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
            2010-04-22 09:17:00 ----D---- C:\WINDOWS\Temp
            2010-04-22 09:16:54 ----D---- C:\Documents and Settings\renaud\Application Data\WTablet
            2010-04-22 09:16:41 ----D---- C:\WINDOWS
            2010-04-22 09:16:06 ----D---- C:\WINDOWS\system32\CatRoot2
            2010-04-22 09:13:53 ----A---- C:\WINDOWS\SchedLgU.Txt
            2010-04-22 09:13:42 ----D---- C:\WINDOWS\system32\drivers
            2010-04-22 09:11:48 ----SHD---- C:\WINDOWS\Installer
            2010-04-22 09:11:48 ----HD---- C:\Config.Msi
            2010-04-22 09:11:47 ----D---- C:\WINDOWS\WinSxS
            2010-04-21 21:19:02 ----RD---- C:\Program Files
            2010-04-21 19:30:56 ----HD---- C:\WINDOWS\inf
            2010-04-21 19:24:31 ----DC---- C:\WINDOWS\system32\DRVSTORE
            2010-04-21 18:29:40 ----D---- C:\WINDOWS\system32\LogFiles
            2010-04-21 18:29:39 ----D---- C:\WINDOWS\Minidump
            2010-04-21 18:29:39 ----D---- C:\WINDOWS\Debug
            2010-04-21 16:57:59 ----RSD---- C:\WINDOWS\Fonts
            2010-04-21 10:02:56 ----D---- C:\Documents and Settings\renaud\Application Data\Azureus
            2010-04-18 21:37:07 ----D---- C:\Documents and Settings\renaud\Application Data\vlc
            2010-04-18 20:44:41 ----D---- C:\Documents and Settings\renaud\Application Data\dvdcss
            2010-04-17 18:38:49 ----D---- C:\Program Files\Graffiti Studio 2.0
            2010-04-16 15:06:23 ----D---- C:\Program Files\eMule
            2010-04-15 21:13:46 ----D---- C:\Program Files\Vuze
            2010-04-15 16:38:41 ----RSHDC---- C:\WINDOWS\system32\dllcache
            2010-04-15 16:38:34 ----HD---- C:\WINDOWS\$hf_mig$
            2010-04-15 16:36:37 ----D---- C:\WINDOWS\ie8updates
            2010-04-06 19:52:54 ----A---- C:\WINDOWS\system32\MRT.exe
            2010-04-04 19:13:31 ----D---- C:\Documents and Settings\renaud\Application Data\Canon
            2010-04-03 10:38:43 ----D---- C:\Program Files\Mozilla Firefox
            2010-04-01 17:16:20 ----D---- C:\WINDOWS\system32\inetsrv
            2010-03-31 17:47:04 ----SH---- C:\boot.ini
            2010-03-31 17:47:04 ----A---- C:\WINDOWS\win.ini
            2010-03-31 17:47:04 ----A---- C:\WINDOWS\system.ini
            2010-03-31 17:47:03 ----D---- C:\WINDOWS\pss
            2010-03-31 10:50:05 ----D---- C:\Program Files\Fichiers communs\Apple
            2010-03-31 10:42:35 ----D---- C:\Program Files\Bonjour
            2010-03-31 10:36:15 ----D---- C:\Program Files\Safari
            2010-03-24 12:07:16 ----D---- C:\Documents and Settings\renaud\Application Data\filebibteam

            ======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

            R1 AsIO;AsIO; C:\WINDOWS\system32\drivers\AsIO.sys [2007-12-17 12400]
            R1 avgio;avgio; \??\C:\Program Files\Avira\AntiVir Desktop\avgio.sys []
            R1 avipbb;avipbb; C:\WINDOWS\system32\DRIVERS\avipbb.sys [2009-03-30 96104]
            R1 intelppm;Pilote de processeur Intel; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-14 40576]
            R1 kbdhid;Pilote HID de clavier; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-14 14720]
            R1 ssmdrv;ssmdrv; C:\WINDOWS\system32\DRIVERS\ssmdrv.sys [2009-05-11 28520]
            R2 adfs;adfs; C:\WINDOWS\system32\drivers\adfs.sys [2008-08-14 74720]
            R2 AegisP;AEGIS Protocol (IEEE 802.1x) v3.4.5.0; C:\WINDOWS\system32\DRIVERS\AegisP.sys [2009-11-16 21035]
            R2 avgntflt;avgntflt; C:\WINDOWS\system32\DRIVERS\avgntflt.sys [2009-12-10 56816]
            R2 NwlnkIpx;Protocole de transport compatible NWLink IPX/SPX/NetBIOS; C:\WINDOWS\system32\DRIVERS\nwlnkipx.sys [2008-04-13 88320]
            R2 NwlnkNb;NetBIOS NWLink; C:\WINDOWS\system32\DRIVERS\nwlnknb.sys [2004-08-05 63232]
            R2 NwlnkSpx;Protocole NWLink SPX/SPXII; C:\WINDOWS\system32\DRIVERS\nwlnkspx.sys [2004-08-05 55936]
            R2 Sentinel;Sentinel; C:\WINDOWS\System32\Drivers\SENTINEL.SYS [2007-04-27 90688]
            R3 Arp1394;Protocole client ARP 1394; C:\WINDOWS\system32\DRIVERS\arp1394.sys [2008-04-13 60800]
            R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys [2009-05-18 26600]
            R3 HDAudBus;Pilote de bus Microsoft UAA pour High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
            R3 hidusb;Pilote de classe HID Microsoft; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
            R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2008-05-20 4800000]
            R3 L1e;Miniport Driver for Atheros AR8121/AR8113 PCI-E Ethernet Controller; C:\WINDOWS\system32\DRIVERS\l1e51x86.sys [2008-02-02 36864]
            R3 mouhid;Pilote HID de souris; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-08-23 12288]
            R3 MTsensor;ATK0110 ACPI UTILITY; C:\WINDOWS\system32\DRIVERS\ASACPI.sys [2004-08-13 5810]
            R3 NIC1394;Pilote réseau 1394; C:\WINDOWS\system32\DRIVERS\nic1394.sys [2008-04-13 61824]
            R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2010-01-12 10276768]
            R3 NWRDR;NetWare Rdr; C:\WINDOWS\system32\DRIVERS\nwrdr.sys [2008-04-13 163584]
            R3 SNTNLUSB;SafeNet USB SuperPro/UltraPro/HardwareKey; C:\WINDOWS\system32\DRIVERS\SNTNLUSB.SYS [2007-04-27 35328]
            R3 usbccgp;Pilote parent générique USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
            R3 usbehci;Pilote miniport de contrôleur d'hôte amélioré Microsoft USB 2.0; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-13 30208]
            R3 usbhub;Pilote de concentrateur standard USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-13 59520]
            R3 usbprint;Classe d'imprimantes USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-13 25856]
            R3 usbstor;Pilote de stockage de masse USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
            R3 usbuhci;Pilote miniport de contrôleur hôte universel USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]
            R3 wacommousefilter;Wacom Mouse Filter Driver; C:\WINDOWS\system32\DRIVERS\wacommousefilter.sys [2007-02-16 11312]
            R3 wacomvhid;Wacom Virtual Hid Driver; C:\WINDOWS\system32\DRIVERS\wacomvhid.sys [2009-05-20 13736]
            S2 NPF;NetGroup Packet Filter Driver; C:\WINDOWS\system32\drivers\npf.sys []
            S2 Par1284;Par1284; \??\C:\Program Files\Secabo\Secabo Production Suite1\Program\Par1284.sys []
            S3 akw399it;akw399it; C:\WINDOWS\system32\drivers\akw399it.sys []
            S3 CH341SER;CH341SER; C:\WINDOWS\System32\Drivers\CH341SER.SYS [2007-09-24 37488]
            S3 HPZid412;IEEE-1284.4 Driver HPZid412; C:\WINDOWS\system32\DRIVERS\HPZid412.sys [2005-03-08 51120]
            S3 HPZipr12;Print Class Driver for IEEE-1284.4 HPZipr12; C:\WINDOWS\system32\DRIVERS\HPZipr12.sys [2005-03-08 16496]
            S3 HPZius12;USB to IEEE-1284.4 Translation Driver HPZius12; C:\WINDOWS\system32\DRIVERS\HPZius12.sys [2005-03-08 21744]
            S3 rtl8185;Realtek RTL8185 54M Wireless LAN Network Adapter Driver; C:\WINDOWS\system32\DRIVERS\rtl8185.sys []
            S3 RTL8192su;Realtek RTL8192SU Wireless LAN 802.11n USB 2.0 Network Adapter; C:\WINDOWS\system32\DRIVERS\RTL8192su.sys [2009-05-15 583552]
            S3 USBAAPL;Apple Mobile USB Driver; C:\WINDOWS\System32\Drivers\usbaapl.sys [2009-10-16 41472]
            S3 usbscan;Pilote de scanneur USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-13 15104]
            S3 wacmoumonitor;Wacom Mode Helper; C:\WINDOWS\system32\DRIVERS\wacmoumonitor.sys [2009-08-28 16168]
            S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
            S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
            S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []

            ======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

            R2 Akamai;Akamai NetSession Interface; C:\WINDOWS\System32\svchost.exe [2008-04-14 14336]
            R2 AntiVirSchedulerService;Avira AntiVir Planificateur; C:\Program Files\Avira\AntiVir Desktop\sched.exe [2009-05-13 108289]
            R2 AntiVirService;Avira AntiVir Guard; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [2009-07-21 185089]
            R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files\Fichiers communs\Apple\Mobile Device Support\AppleMobileDeviceService.exe [2010-03-19 144672]
            R2 Application Updater;Application Updater; C:\Program Files\Application Updater\ApplicationUpdater.exe [2010-01-08 380928]
            R2 Bonjour Service;Service Bonjour; C:\Program Files\Bonjour\mDNSResponder.exe [2010-02-12 345376]
            R2 HerculesWiFi;HerculesWiFi; C:\WINDOWS\system32\HerculesWiFiService.exe [2009-05-07 53544]
            R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2009-10-11 153376]
            R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service; C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe [2010-04-22 1265264]
            R2 Nero BackItUp Scheduler 4.0;Nero BackItUp Scheduler 4.0; C:\Program Files\Fichiers communs\Nero\Nero BackItUp 4\NBService.exe [2009-09-23 935208]
            R2 NVSvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2010-01-11 154216]
            R2 NWCWorkstation;Service client pour NetWare; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
            R2 Pml Driver HPZ12;Pml Driver HPZ12; C:\WINDOWS\system32\HPZipm12.exe [2004-09-29 69632]
            R2 SAiDownloader;SAiDownloader; C:\WINDOWS\system32\SAiDownloader.exe [2007-09-11 438272]
            R2 SentinelKeysServer;Sentinel Keys Server; C:\Program Files\Fichiers communs\SafeNet Sentinel\Sentinel Keys Server\sntlkeyssrvr.exe [2007-04-27 316992]
            R2 SentinelProtectionServer;Sentinel Protection Server; C:\Program Files\Fichiers communs\SafeNet Sentinel\Sentinel Protection Server\WinNT\spnsrvnt.exe [2007-04-27 206400]
            R2 TabletServiceWacom;TabletServiceWacom; C:\WINDOWS\system32\Wacom_Tablet.exe [2009-10-06 4463400]
            R3 iPod Service;Service de l'iPod; C:\Program Files\iPod\bin\iPodService.exe [2010-03-26 545576]
            S3 Adobe LM Service;Adobe LM Service; C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe [2010-03-18 72704]
            S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
            S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
            S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files\Fichiers communs\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2009-12-19 655624]
            S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
            S3 gusvc;Google Updater Service; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-11-20 136120]
            S3 idsvc;Windows CardSpace; c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
            S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Fichiers communs\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
            S3 ose;Office Source Engine; C:\Program Files\Fichiers communs\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
            S3 rpcapd;Remote Packet Capture Protocol v.0 (experimental); C:\Program Files\WinPcap\rpcapd.exe -d -f C:\Program Files\WinPcap\rpcapd.ini []
            S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
            S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]

            -----------------EOF-----------------
            0
            1. Ok, on commence :

              Note : tu as une infection qui se propage par les disques amovibles.

              ● Télécharge USBFix (de El Desaparecido et C_XX) sur ton Bureau

              ● Sous XP : Double clique sur UsbFix.exe
              ● Sous Vista/7 : Fais un clic droit sur UsbFix.exe et sélectionne "Exécuter en tant qu'administrateur"

              ● Appuie sur la touche F pour sélectionner le français et valide avec la touche Entrée.

              ● Choisis l'option "Recherche" en appuyant sur la touche 1 et valide avec la touche Entrée

              ● Branche à ton PC tes disques amovibles (clé USB, disque dur externe, lecteur MP3, téléphone, etc...) susceptibles d'avoir été infectés sans les ouvrir quand l'outil te le demande et clique sur le bouton OK

              ● Patiente pendant que l'outil travaille

              ● A la fin du scan un rapport va s'ouvrir, copie/colle le dans ta réponse

              ▲ Le rapport est sauvegardé dans C:\UsbFix.txt

              Note :
              Process.exe est détecté par certains antivirus comme étant un RiskTool.
              Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.


              Tutoriel recherche en images
              0
              1. ############################## | UsbFix V6.107 |

                User : renaud (Administrateurs) # RENO-8589D5E46B
                Update on 21/04/2010 by El Desaparecido , C_XX & Chimay8
                Start at: 17:25:08 | 22/04/2010
                Website : http://pagesperso-orange.fr/NosTools/index.html
                Contact : FindyKill.Contact@gmail.com

                Intel(R) Core(TM)2 Quad CPU Q6600 @ 2.40GHz
                Microsoft Windows XP Professionnel (5.1.2600 32-bit) # Service Pack 3
                Internet Explorer 8.0.6001.18702
                Windows Firewall Status : Disabled
                AV : AntiVir Desktop 9.0.1.32 [ Enabled | Updated ]

                C:\ -> Disque fixe local # 298,08 Go (237,45 Go free) # NTFS
                D:\ -> Disque fixe local # 465,76 Go (212,88 Go free) # NTFS
                E:\ -> Disque CD-ROM
                F:\ -> Disque fixe local # 465,76 Go (313,24 Go free) [BZ_500GO] # NTFS
                G:\ -> Disque amovible
                H:\ -> Disque amovible
                I:\ -> Disque amovible
                J:\ -> Disque amovible
                K:\ -> Disque amovible # 15,98 Go (15,97 Go free) [BZ 16GO] # FAT32
                L:\ -> Disque amovible # 939,73 Mo (871,14 Mo free) [BZ 1GO] # FAT
                M:\ -> Disque fixe local # 114,49 Go (406,49 Mo free) [bZ] # NTFS
                Y:\ -> Disque CD-ROM # 4,32 Go (0 Mo free) [les liens du sang] # UDF

                ################## | Elements infectieux |

                C:\WINDOWS\winrun.dll.vbs
                C:\autorun.inf
                C:\winrun.vbs
                D:\autorun.inf
                D:\winrun.vbs
                F:\autorun.inf
                F:\winrun.vbs
                K:\autorun.inf
                K:\winrun.vbs

                ################## | Registre |

                [HKLM\Software\Microsoft\Windows\CurrentVersion\Run] "officescan"
                [HKLM\Software\Microsoft\Windows\CurrentVersion\Run] "winrun.dll"
                [HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer] "NoFind"
                [HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer] "NoFolderOptions"
                [HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer] "NoFolderOptions"
                [HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer] "NoRun"

                ################## | Mountpoints2 |

                HKCU\..\..\Explorer\MountPoints2\{105e221a-ea5d-11de-bc4e-0008d38095b9}
                Shell\AutoRun\command =C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Wscript.exe winrun.vbs

                HKCU\..\..\Explorer\MountPoints2\{1baf1ae1-2ba1-11df-bc5a-0008d38095b9}
                Shell\AutoRun\command =C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Wscript.exe winrun.vbs

                HKCU\..\..\Explorer\MountPoints2\{4291ca99-d36f-11de-bc2b-0008d38095b9}
                Shell\AutoRun\command =C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL RUNdLl32.ExE .\RECYCLER\S-5-3-42-2819952290-8240758988-879315005-3665\jwgkvsq.vmx,ahaezedrn

                HKCU\..\..\Explorer\MountPoints2\{43d858f8-c86c-11de-bc25-0022154398aa}
                Shell\Auto\command =L:\RavMonE.exe e
                Shell\AutoRun\command =C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL RavMonE.exe e

                HKCU\..\..\Explorer\MountPoints2\{464398ff-ba4a-11de-965f-806d6172696f}
                Shell\AutoRun\command =C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Wscript.exe winrun.vbs

                HKCU\..\..\Explorer\MountPoints2\{5828734c-ba5a-11de-bc08-0022154398aa}
                Shell\AutoRun\command =C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Wscript.exe winrun.vbs

                HKCU\..\..\Explorer\MountPoints2\{5b0d4b16-c7ac-11de-bc24-0014d15322c5}
                Shell\AutoRun\command =K:\LaunchU3.exe -a

                HKCU\..\..\Explorer\MountPoints2\{94da6820-efc9-11de-bc51-0008d38095b9}
                Shell\AutoRun\command =C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Wscript.exe winrun.vbs

                ################## | Vaccin |

                ################## | ! Fin du rapport # UsbFix V6.107 ! |
                0
                1. mes disques sont toujours branché, je suis allé dans poste de travail, et là j'ai un message d'erreur windows suivant

                  http://img706.imageshack.us/img706/8061/screenshot046n.jpg

                  Processing Message C 0000013 Parameters 75afbf7c 4 75afbf7c 4 75afbf7c 75afbf7c

                  j'avais deja eu ce message impossible de le faire partir sans redemarrer.
                  ("annuler","recommencer", ou "continuer" il revenait).
                  0
                  1. Bien, on passe au nettoyage :

                    ● Relance UsbFix.exe

                    ● Appuie sur la touche F pour sélectionner le français et valide avec la touche Entrée.

                    ● Choisis l'option "Suppression" en appuyant sur la touche 2 et valide avec la touche Entrée

                    ● Branche à ton PC tes disques amovibles (clé USB, disque dur externe, lecteur MP3, téléphone, etc...) susceptibles d'avoir été infectés sans les ouvrir quand l'outil te le demande et clique sur le bouton OK

                    ● Patiente pendant que l'outil travaille

                    ● A la fin de la suppression un rapport va s'ouvrir, copie/colle le dans ta réponse

                    ▲ Le rapport est sauvegardé dans C:\UsbFix.txt

                    Tutoriel suppression en images
                    0
                    1. j'ai suivi pas à pas, il a redémarré le pc et m'a dit qu'il avait généré un fichier dans
                      C:\UsbFix_Upload_Me_RENO-8589D5E46B.zip dans ce zip il y a winrun.vbs.UsbFix , winrun.dll.vbs.UsbFix , autorun.in.UsbFix et un UsbFix.txt que voila :

                      ############################## | UsbFix V6.107 |

                      User : renaud (Administrateurs) # RENO-8589D5E46B
                      Update on 21/04/2010 by El Desaparecido , C_XX & Chimay8
                      Start at: 18:56:35 | 22/04/2010
                      Website : http://pagesperso-orange.fr/NosTools/index.html
                      Contact : FindyKill.Contact@gmail.com

                      Intel(R) Core(TM)2 Quad CPU Q6600 @ 2.40GHz
                      Microsoft Windows XP Professionnel (5.1.2600 32-bit) # Service Pack 3
                      Internet Explorer 8.0.6001.18702
                      Windows Firewall Status : Disabled
                      AV : AntiVir Desktop 9.0.1.32 [ Enabled | Updated ]

                      C:\ -> Disque fixe local # 298,08 Go (237,4 Go free) # NTFS
                      D:\ -> Disque fixe local # 465,76 Go (212,88 Go free) # NTFS
                      E:\ -> Disque CD-ROM
                      F:\ -> Disque fixe local # 465,76 Go (313,24 Go free) [BZ_500GO] # NTFS
                      G:\ -> Disque amovible
                      H:\ -> Disque amovible
                      I:\ -> Disque amovible
                      J:\ -> Disque amovible
                      K:\ -> Disque amovible # 15,98 Go (15,97 Go free) [BZ 16GO] # FAT32
                      L:\ -> Disque amovible # 939,73 Mo (871,14 Mo free) [BZ 1GO] # FAT
                      M:\ -> Disque fixe local # 114,49 Go (406,49 Mo free) [bZ] # NTFS
                      Y:\ -> Disque CD-ROM # 4,32 Go (0 Mo free) [les liens du sang] # UDF

                      ################## | Elements infectieux |

                      Supprimé ! C:\WINDOWS\winrun.dll.vbs
                      Supprimé ! C:\autorun.inf
                      Supprimé ! C:\winrun.vbs
                      Supprimé ! C:\Recycler\S-1-5-21-448539723-2111687655-725345543-1003
                      Supprimé ! D:\autorun.inf
                      Supprimé ! D:\winrun.vbs
                      Supprimé ! D:\Recycler\S-1-5-21-448539723-2111687655-725345543-1003
                      Supprimé ! F:\autorun.inf
                      Supprimé ! F:\winrun.vbs
                      Supprimé ! F:\Recycler\S-1-5-21-448539723-2111687655-725345543-1003
                      Supprimé ! K:\autorun.inf
                      Supprimé ! K:\winrun.vbs
                      Supprimé ! M:\$Recycle.Bin\S-1-5-21-2580637171-2524933329-3637736659-1000
                      Supprimé ! M:\Recycler\S-1-5-21-1004336348-1960408961-725345543-1004
                      Supprimé ! M:\Recycler\S-1-5-21-1202660629-484763869-1343024091-1004
                      Supprimé ! M:\Recycler\S-1-5-21-1390067357-1957994488-854245398-1004
                      Supprimé ! M:\Recycler\S-1-5-21-2281261906-31434914-4204658359-1005
                      Supprimé ! M:\Recycler\S-1-5-21-3989368926-1593101714-145537262-1006
                      Supprimé ! M:\Recycler\S-1-5-21-4196861610-2860324281-995082217-1006
                      Supprimé ! M:\Recycler\S-1-5-21-839522115-1383384898-2147018563-1004

                      ################## | Registre |

                      Supprimé ! [HKLM\Software\Microsoft\Windows\CurrentVersion\Run] "officescan"
                      Supprimé ! [HKLM\Software\Microsoft\Windows\CurrentVersion\Run] "winrun.dll"
                      Supprimé ! [HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer] "NoFind"
                      Supprimé ! [HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer] "NoFolderOptions"
                      Supprimé ! [HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer] "NoFolderOptions"
                      Supprimé ! [HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer] "NoRun"

                      ################## | Mountpoints2 |

                      Supprimé ! HKCU\...\Explorer\MountPoints2\{105e221a-ea5d-11de-bc4e-0008d38095b9}\Shell\AutoRun\Command
                      Supprimé ! HKCU\...\Explorer\MountPoints2\{4291ca99-d36f-11de-bc2b-0008d38095b9}\Shell\AutoRun\Command
                      Supprimé ! HKCU\...\Explorer\MountPoints2\{43d858f8-c86c-11de-bc25-0022154398aa}\Shell\Auto\Command
                      Supprimé ! HKCU\...\Explorer\MountPoints2\{5b0d4b16-c7ac-11de-bc24-0014d15322c5}\Shell\AutoRun\Command

                      ################## | Listing des fichiers présent |

                      [22/04/2010 18:55|--a------|754] C:\aaw7boot.log
                      [16/10/2009 13:33|--a------|0] C:\AUTOEXEC.BAT
                      [31/03/2010 17:47|---hs----|212] C:\boot.ini
                      [05/08/2004 14:00|-rahs----|4952] C:\Bootfont.bin
                      [16/10/2009 13:33|--a------|0] C:\CONFIG.SYS
                      [16/10/2009 20:44|--a------|1762] C:\FlexiSTARTER Secabo Edition 8.5v1.lnk
                      [03/11/2009 13:31|--a------|20] C:\GINA.TEXT
                      [16/10/2009 13:33|-rahs----|0] C:\IO.SYS
                      [16/10/2009 13:33|-rahs----|0] C:\MSDOS.SYS
                      [05/08/2004 14:00|-rahs----|47564] C:\NTDETECT.COM
                      [16/10/2009 20:07|-rahs----|252240] C:\ntldr
                      [29/02/2004 17:44|--a------|52576] C:\orange.bmp
                      [?|?|?] C:\pagefile.sys
                      [16/10/2009 20:44|--a------|1575] C:\Production Manager 8.5v1.lnk
                      [16/10/2009 14:04|--a------|608] C:\RHDSetup.log
                      [22/04/2010 19:04|--a------|4067] C:\UsbFix.txt
                      [03/11/2009 11:31|--a------|41] C:\WLANCUGINA.TEXT
                      [31/03/2010 13:45|--a------|1413238] K:\bordereau de livraison d'stock.pdf
                      [13/04/2010 15:49|--a------|1216580] K:\tee shirt gnocchi.ai
                      [29/11/2009 12:38|--ah-----|4096] L:\._.Trashes
                      [19/07/2008 23:45|--a------|2067564] L:\P1080025.JPG
                      [19/07/2008 23:47|--a------|2379802] L:\P1080029.JPG
                      [04/10/2008 23:38|--a------|1049805] L:\DSCF6391.JPG
                      [04/10/2008 23:41|--a------|1025977] L:\DSCF6410.JPG
                      [05/10/2008 00:41|--a------|995044] L:\DSCF6431.JPG
                      [05/10/2007 20:16|--a------|1698861] L:\DSCN2309.JPG
                      [05/10/2007 21:41|--a------|1783221] L:\DSCN2349.JPG
                      [05/10/2007 23:40|--a------|1803705] L:\DSCN2361.JPG
                      [06/10/2007 00:32|--a------|1654524] L:\DSCN2391.JPG
                      [06/10/2007 00:42|--a------|1808105] L:\DSCN2438.JPG
                      [04/10/2008 23:55|--a------|2295132] L:\P1050066.JPG
                      [01/10/2007 18:34|--a------|499663] L:\beach.JPG
                      [11/12/2007 00:25|--a------|1052240] L:\P1030592.JPG
                      [02/10/2007 18:39|--a------|730372] L:\envoi.JPG
                      [03/10/2007 18:50|--a------|1243095] L:\P1030489-1.JPG
                      [10/10/2007 19:49|--a------|1259919] L:\d.jpg
                      [10/10/2007 19:50|--a------|569831] L:\e.jpg
                      [07/10/2007 17:02|--a------|365848] L:\velo.JPG
                      [06/10/2007 23:33|--a------|1265846] L:\P1030575-1.JPG
                      [06/10/2007 01:39|--a------|1711356] L:\P1030564-1.JPG
                      [02/04/2008 16:48|--a------|1032494] L:\P1030917.JPG
                      [11/12/2007 02:08|--a------|1085151] L:\P1040136-1.jpg
                      [04/12/2007 20:09|--a------|2337853] L:\P1040170.JPG
                      [11/12/2007 02:10|--a------|860421] L:\P1040325.JPG
                      [07/01/2008 23:49|--a------|1421058] L:\P1040756.JPG
                      [28/01/2008 17:10|--a------|951461] L:\P1040879.JPG
                      [05/01/2008 14:19|--a------|1349073] L:\P1040560.JPG
                      [31/01/2008 17:09|--a------|818516] L:\hitchhiden copie.jpg
                      [07/03/2008 02:31|--a------|1180870] L:\P1040773.JPG
                      [24/02/2008 19:44|--a------|1557258] L:\3faces.jpg
                      [20/02/2008 22:12|--a------|996777] L:\P1050105.JPG
                      [26/03/2008 02:41|--a------|1537417] L:\P1050505.JPG
                      [26/03/2008 02:43|--a------|937979] L:\P1050512.JPG
                      [15/03/2008 18:23|--a------|893271] L:\P1050240.JPG
                      [15/03/2008 18:27|--a------|1438049] L:\P1050242.JPG
                      [21/03/2008 19:53|--a------|661397] L:\P1050317.JPG
                      [23/04/2009 09:41|--a------|3234224] L:\Sans titre-1.jpg
                      [20/06/2008 23:23|--a------|2308624] L:\P1070190.JPG
                      [28/06/2008 22:24|--a------|3380816] L:\P1070397.JPG
                      [28/06/2008 23:19|--a------|2701317] L:\P1070403.JPG
                      [16/05/2008 00:04|--a------|1759850] L:\copie.jpg
                      [16/05/2008 19:57|--a------|2698608] L:\goteborg1 088.jpg
                      [18/05/2008 19:41|--a------|2215948] L:\goteborg1 196.jpg
                      [18/05/2008 19:41|--a------|2331320] L:\goteborg1 199.jpg
                      [18/05/2008 19:43|--a------|3371816] L:\goteborg1 214.jpg
                      [24/02/2008 10:06|--a------|731949056] M:\(Film) Snatch (Brad Pitt) Dvdrip Francais.avi
                      [12/09/2005 11:34|--a------|766142464] M:\(TNT)Mystic.river_DVDRip_Fr.avi
                      [09/11/2007 13:42|--a------|736024576] M:\- Film - Usual Suspect - Divx Fr.avi
                      [25/03/2007 20:06|--a------|728756224] M:\16 Blocks.avi
                      [26/05/2007 21:44|--a------|697745408] M:\187 Code Meurtre Dvdrip Fr.avi
                      [27/01/2006 22:32|--a------|728410112] M:\Aaltra.avi
                      [19/03/2004 14:16|--a------|735045632] M:\AI by C_MoOoi.avi
                      [24/10/2006 04:29|--a------|698058752] M:\Albert.Dupontel.Le.Sale.DVD.FRENCH.DVDRiP.XViD-FiON.CD2.avi
                      [01/03/2005 23:20|--a------|736851968] M:\Ali.le film avec Will Smith(2h26).fr.avi
                      [18/04/2007 18:56|--a------|734347264] M:\Alpha.Dog.FRENCH.DVDRiP.XviD-GeT-BADTIGER.avi
                      [26/09/2006 00:39|--a------|725032960] M:\Apocalypse Now - Divx Fr.avi
                      [26/12/2006 10:16|--a------|727826432] M:\Arnaque.Crime.Et.Botanique.French.DVDRip.avi
                      [19/01/2007 17:16|--a------|728127488] M:\Arthur.Et.Les.Minimoys.2006.FRENCH.TS.XviD-CiNEFOX-SaTaN.avi
                      [24/01/2008 15:06|--a------|733449206] M:\Avida.2006.DVDRip.XviD-SSF.avi
                      [19/01/2008 11:17|--a------|918195420] M:\B13 Banlieue 13 (Sci Fi Action Luc Besson 2004 French Style).avi
                      [17/06/2007 19:59|--a------|732991488] M:\Battement D'ailes Du Papillon.avi
                      [15/01/2008 19:00|--a------|733982720] M:\Beerfest French Dvdrip Xvid-Beerfest-Acebot.avi
                      [15/01/2008 05:42|--a------|734502912] M:\Benoit Poelvoorde Cin'astes · Tout Prix (Fr).avi
                      [23/12/2006 12:07|--a------|558592512] M:\Bernie Noel.avi
                      [25/09/2006 15:39|--a------|721598464] M:\Bernie.FRENCH.DVDRip.DivX-L3b0wsk1.avi
                      [26/07/2005 19:13|--a------|724922368] M:\BLACK AND WHITE.avi
                      [02/01/2008 20:52|--a------|733569024] M:\Blanche - Lou Doillon - J Rochefort - C Bouquet - J Garcia - A de Caunes - Depardieu - M Lavoine - D Besnehard - fr.avi
                      [24/05/2007 13:38|--a------|734040064] M:\Blood.Diamond.FRENCH.DVDRiP.REPACK.1CD.XViD-STS-ANGE.avi
                      [06/11/2007 06:45|--a------|734932992] M:\Bloody Sunday French Dvdrip Xvid-Vibe-Teste Divxovore-.avi
                      [31/05/2007 19:01|--a------|734402560] M:\Borat French Dvdrip Xvid-Borat.avi
                      [19/05/2004 05:09|--a------|679301120] M:\C'est arrive pres de chez vous.avi
                      [17/05/2007 19:43|--a------|734629888] M:\C.R.A.Z.Y.FRENCH.DVDRiP.XViD.SHARE.FUS!ON.avi
                      [12/01/2008 17:06|--a------|733511680] M:\Camping - 2006 - Film Avec Franck Dubosc.avi
                      [10/01/2008 12:45|--a------|724232192] M:\Ce.Soir.Je.Dors.Chez.Toi.FRENCH.CAM.XViD-CyClone.avi
                      [10/09/2005 22:36|--a------|730425344] M:\Constantine_1CD_INTERNAL_FRENCH_DVDRip_XViD-TheNewSquad-TRAC.avi
                      [24/03/2006 21:27|--a------|729669632] M:\Crash.FRENCH.DVDRip.XViD-PLM-GGT.avi
                      [21/01/2008 15:49|--a------|735049728] M:\Danny The Dog FR.avi
                      [15/12/2007 03:18|--a------|733853696] M:\Dans.La.Peau.De.Jacques.Chirac.FRENCH.DVDRip.XviD-OTHERS-D3M0N.avi
                      [07/09/2007 12:52|--a------|732409856] M:\Danse Avec Lui French Dvdrip Repack 1Cd Xvid.avi
                      [20/11/2005 06:07|--a------|729464832] M:\Dawn.Of.The.Dead.FRENCH.DVDRiP.XViD-DORMEUR-GGT.par-www.eMule-Paradise.com.avi
                      [19/01/2008 02:15|--a------|734064640] M:\De Battre Mon Coeur S'est Arrete(Romain Duris).avi
                      [17/10/2007 19:55|--a------|731936086] M:\Dead Man - Jim Jarmush - Fr.avi
                      [02/04/2005 05:17|--a------|734038016] M:\Dedales.FRENCH.DVDRiP.SBC-XMAS-teste.DivXovore.com-.avi
                      [01/11/2005 06:45|--a------|726450480] M:\dobermann.furtif.fr..AVI
                      [27/01/2008 14:50|--a------|734408704] M:\Drame Poelvoorde Entre.Ses.Mains.FRENCH.DVDRip.XviD-LOST.avi
                      [04/05/2007 14:49|--a------|732588658] M:\Entretien Avec Un Vampire - Fr (1994 Tom Cruise, Brad Pitt).avi
                      [15/02/2007 16:41|--a------|733659136] M:\Eragon.FRENCH.DVDSCR.XViD-VCDFRV-D3MoN.LinK.By.LeDivX.Com.avi
                      [02/02/2004 07:38|--a------|679026688] M:\Event Horizon, Le Vaisseau de l'au-dela.avi
                      [03/09/2000 09:11|--a------|308563968] M:\fight club 1.avi
                      [03/09/2000 09:13|--a------|343724032] M:\fight club 2.avi
                      [31/12/2006 15:54|--a------|731660288] M:\Finding_Neverland.FRENCH.DVDRip-XViD-Share.BlueeeMasKKK.avi
                      [12/10/2006 20:53|--a------|693702656] M:\Four.rooms.up.By.Mudvayne.avi
                      [08/08/2007 20:44|--a------|731627520] M:\Fran#ais - Drame - Ne le dis ... personne.avi
                      [19/05/2007 18:41|--a------|734371840] M:\French Connexion.avi
                      [24/03/2006 19:25|--a------|694630400] M:\From.hell-DvDRiP-fr.test'.www.divxovore.com.avi
                      [28/09/2006 06:00|--a------|734087168] M:\Garden.State.FRENCH.DVDRip.XViD-NTK-AvRIL.avi
                      [01/04/2007 16:05|--a------|734404608] M:\Ghost Rider.avi
                      [16/01/2006 12:50|--a------|733364224] M:\Gothika.FRENCH.DVDRip.XViD-SEQUENCE.shared.by.[TFT]-teste.DivXovore.com-.avi
                      [20/02/2007 06:34|--a------|732686336] M:\Happy.Feet.2006.FRENCH.FS.DVDRiP.XviD-STS-D3MoN.LinK-LeDivX.Com.avi
                      [21/11/2005 10:23|--a------|737038336] M:\Harry.Potter.And.The.Goblet.Of.Fire.FRENCH.TS.XViD-FLNC.avi
                      [29/03/2006 20:16|--a------|713152512] M:\Hostel.French.Dvdscr.Xvid.par.www.eMulenfer.org.avi
                      [09/06/2007 03:07|--a------|693716992] M:\Hot shot 1 DVDRIP FR.avi
                      [09/06/2007 02:01|--a------|726405120] M:\Hot Shot 2 - DVDRip - Fr.avi
                      [13/07/2005 03:13|--a------|734992384] M:\I Robot_DVDRip_ By _@ngel_Version fr non canadienne (qualit' sel.2.mer).avi
                      [17/05/2007 21:28|--a------|733505536] M:\Indigenes.FRENCH.DVDRip.REPACK.1CD.XviD-SaTaN.avi
                      [16/10/2006 12:13|--a------|733980672] M:\Jean-Philippe.FRENCH.DVDRip.XviD-LOST-UGM.avi
                      [30/12/2007 17:26|--a------|741357424] M:\Kill Bill 1 Version Fran#aise.avi
                      [15/12/2007 20:16|--a------|738641920] M:\Kill Bill Volume 2 - Francais.avi
                      [31/12/2006 16:35|--a------|728753046] M:\L'arm'e.des.12.Singes.(Bruce.Willis).[BarnZ.DVDrip.Francais].par.eMule-Paradise.com.avi
                      [15/12/2007 03:24|--a------|732221440] M:\L'effet Papillon- Divix Fr.avi
                      [14/07/2002 19:12|--a------|438028288] M:\La 7Sme Proph'tie .avi
                      [17/07/2006 12:40|--a------|730609020] M:\LA BOITE NOIRE (JOSE GARCIA & MARION COTILLARD 2005) DVDRIP DIVX FR.avi
                      [10/07/2007 02:08|--a------|726644736] M:\La Cite Interdite 2006 French Dvdscr Xvid-Cinefox-Satan.avi
                      [24/05/2007 14:31|--a------|734173184] M:\La Colline a des Yeux (2006) Version Non Censur'e.DVDRip.FR de France.avi
                      [24/05/2007 13:10|--a------|734138368] M:\La Colline a des Yeux.DVDRip.FR de France.avi
                      [04/06/2007 13:18|--a------|744495104] M:\La Passion Du Christ - Fran#ais.avi
                      [13/02/2006 11:46|--a------|725411570] M:\La Porte Des Secrets Dvdrip Fr.avi
                      [07/12/2005 18:03|--a------|739627008] M:\La Rose pourpre du Caire (Woody Allen).avi
                      [22/12/2005 02:59|--a------|735320064] M:\La Voix Des Morts -Fr Dvdrip 2005.avi
                      [13/07/2005 02:35|--a------|739180544] M:\La.Cite.De.Dieu.avi
                      [21/10/2006 09:16|--a------|720832628] M:\La.Haine.(DVD-DivX.Francais).teste.www.divxovore.com.avi
                      [10/05/2007 03:47|--a------|668015616] M:\Las_Vegas_Parano-Divx-Fr-Julio-Spartateur.avi
                      [10/05/2007 02:26|--a------|733911040] M:\Le Cercle Des Poetes Disparus(Peter Weir) (avec Robin Williams) (1989).avi
                      [08/12/2007 19:08|--a------|708523146] M:\Le Fabuleux Destin D'Amelie Poulin.AVI
                      [21/05/2007 13:27|--a------|730593280] M:\Le Parfum.Histoire D'Un Meurtrier Fr(TC).avi
                      [19/02/2007 09:32|--a------|726646784] M:\le parrain 1-francis ford coppola-fr.avi
                      [19/02/2007 09:00|--a------|727928832] M:\Le Parrain 2 - Fr Cd 2- de Francis Ford Coppola avec Marlon Brando, Al Pacino (1974) -.avi
                      [19/02/2007 07:54|--a------|734370266] M:\Le Parrain 3 (Drame Policier) (De Francis Ford Coppola) (Avec Al Pacino, Diane Keaton, Andy Garcia) - 1990.avi
                      [19/07/2007 16:44|--a------|733601792] M:\LE PATIENT ANGLAIS avec Juliette Binoche & Kristin Scott Thomas.avi
                      [19/01/2008 13:36|--a------|724453376] M:\Le Terminal - Tom Hanks,Catherine Zeta-Jones {Divx Fr 2004}.avi
                      [27/05/2007 22:22|--a------|730736640] M:\Le.Dernier.roi.d'Ecosse.2006.LiMiTED.FRENCH.DVDSCR.XviD-CiNEFOX-D3MoN.avi
                      [03/04/2006 05:56|--a------|736733814] M:\Le.Secret.De.Brokeback.Mountain.French.Dvdrip.Xvid.par.www.eMulenfer.org.avi
                      [29/01/2007 20:41|--a------|736604160] M:\LeRoyaumedesVoleurslte.avi
                      [06/03/2007 23:38|--a------|735019008] M:\Les Amants Du Nouveau Monde(1995 The Scarlet Letter) Dvdrip Fran#ais.avi
                      [08/06/2006 05:16|--a------|734304256] M:\Les Bronzes Font Du Ski.avi
                      [30/08/2007 21:27|--a------|735174516] M:\Les Fils De L'homme Dvdrip fr By Cooli.avi
                      [21/05/2007 11:03|--a------|731584512] M:\les infiltr's top qualit' FR.avi
                      [08/09/2007 18:51|--a------|733646848] M:\Les.Ambitieux.FRENCH.DVDRip.XviD-SHOTAS.avi
                      [17/05/2007 15:00|--a------|734658560] M:\Les.Invasions.Barbares.FRENCH.DVDRip.XViD-HzN.avi
                      [26/09/2006 12:52|--a------|720620544] M:\Les.Parasites.shared.by.gapsy.teste.www.divxovore.com.avi
                      [04/01/2008 05:24|--a------|783142912] M:\Little Miss Sunshine Dvdrip Fr.avi
                      [24/05/2007 13:06|--a------|794159104] M:\Lord Of War (Nicolas Cage)(2006 Fr DivX5 Config Archos 300).avi
                      [11/02/2006 08:33|--a------|733790208] M:\Lord.Of.War.FRENCH.DVDRip.XviD-hehehe.avi
                      [14/01/2008 16:37|--a------|726581248] M:\Lost In Translation French Dvdrip Xvid-Seq Test'.avi
                      [05/07/2006 07:14|--a------|728438784] M:\Lucky.Number.Slevin.2006.FRENCH.DVDSCR.XviD-CiNEFOX-ALLEZ.LES.BLEUS.avi
                      [15/09/2006 16:34|--a------|726839296] M:\L_Aventurier_du_Grand_Nord_Dvdrip_VF(512x320).avi
                      [18/01/2008 04:43|--a------|725846016] M:\L_Enquete_Corse_FRENCH_DVDRip_XViD-TheNewSquad-Share.BlueeeMasKKK.-dvdphoenix.fr.st-.avi
                      [10/02/2006 22:44|--a------|734580736] M:\Madagascar French DVDrip XVID-Get-Psychotik.avi
                      [28/01/2008 01:35|--a------|709330944] M:\Moulin rouge - dvdrip - FR FRENCH FRANCAIS (guitou).avi
                      [19/10/2006 19:57|--a------|1463373986] M:\M'moire D'une Geisha French Dvdrip.avi
                      [29/11/2007 16:14|--a------|683347968] M:\M'tisse (1993) - (avec Vincent Cassel, de Mathieu Kassovitz) - Fr.avi
                      [26/12/2007 15:16|--a------|722663424] M:\NADIA avec Nicole Kidman, Ben Chaplin, Vincent Cassel & Mathieu Kassovitz.avi
                      [25/02/2008 07:27|--a------|735064064] M:\NEXT.(2007).Vraie.VF.Divx6.French.DVDRip.ARLBOUFFIARD.avi
                      [11/09/2006 10:55|--a------|735064064] M:\Old_Boy.FRENCH.DVDRip.DiVX-GGT.avi
                      [15/02/2002 08:47|--a------|725331098] M:\Operation Espadon.AVI
                      [15/04/2008 22:17|--a------|729182208] M:\Paris - Cedric Klapish - Avec J Binoche R Duris F Luchini - 2008.avi
                      [06/09/2007 17:44|--a------|732547072] M:\Pars.Vite.Et.Reviens.Tard.FRENCH.DVDRip.REPACK.1CD.XViD-ELiTE-CasualFirm.avi
                      [17/05/2007 18:54|--a------|733640704] M:\Pirates.des.Caraibes.2.Pirates des Cara<bes, le secret du coffre maudit -french Xvid.avi
                      [27/08/2004 17:56|--a------|733298688] M:\Podium.avi
                      [14/08/2005 17:44|--a------|726042624] M:\Prisonniers du temps-French-DVDrip-Z2.avi
                      [06/03/2005 03:41|--a------|733955862] M:\Ray.FRENCH.DVDRip.DIVX.REPACK.1CD.1kP-TEAM.teste.www.divxonweb.fr.st.avi
                      [15/05/2004 03:16|--a------|710199296] M:\Requiem for a Dream.avi
                      [24/01/2008 13:44|--a------|738795520] M:\Reservoir Dogs - Divx Fran#ais.avi
                      [29/03/2007 16:56|--a------|731721728] M:\retour vers le futur 2 dvdrip divx fr.avi
                      [01/02/2008 01:28|--a------|733085696] M:\Reussir Ou Mourrir 50 Cent Film French.avi
                      [03/12/2007 16:31|--a------|734196388] M:\Robots avec Vincent Cassel, Monica Bellucci, Edouard Baer (060405).avi
                      [14/10/2007 19:20|--a------|734220288] M:\rochester le derniers des libertins The.Libertine.FRENCH.DVDRiP.XviD-LIBERTINE.avi
                      [18/02/2002 10:51|--a------|738818048] M:\scarface.avi
                      [07/06/2006 03:33|--a------|733966336] M:\Sheitan.FRENCH.DVDSCR.XviD-LOST-SuX.avi
                      [02/12/2007 12:58|--a------|725796864] M:\Shining.-.Dvd.Rip.-.Divx.Francais.-.Timby.avi
                      [05/03/2008 07:42|--a------|734594160] M:\Star Wars - Episode 3 FRENCH-DVDRIP.avi
                      [03/06/2005 22:26|--a------|733388800] M:\Super.Size.Me.SUBFRENCH.DVDRiP.XViD-UNRATED-HuB.Teste.DivXovore.com.avi
                      [20/12/2007 19:40|--a------|735834112] M:\Sur_mes_levres-FR-(Vincent.Cassel,Emmanuelle.Devos)(RipDivX5-Certif).avi
                      [27/12/2007 17:53|--a------|739624960] M:\The Big Lebowski French Dvdrip Xvid.avi
                      [23/01/2008 23:01|--a------|726525952] M:\The.Da.Vinci.Code.2006.FRENCH.TC.REPACK.1CD.XviD-COBRA-songo52.avi
                      [26/12/2007 21:06|--a------|828805120] M:\Tim Burton - Big Fish - Fran#ais.avi
                      [30/12/2007 01:39|--a------|615401472] M:\Transpoting Fr.avi
                      [31/05/2007 11:48|--a------|734294016] M:\Trouble Jeu - Film Thriller avec Robert De Niro, Famke Janssen & Dakota Fanning - DivX Fr.avi
                      [30/12/2007 19:21|--a------|730370048] M:\V Pour Vendetta-Dvdrip-Fr- cd1.avi
                      [14/01/2008 21:17|--a------|739739648] M:\V pour Vendetta.avi
                      [12/05/2005 01:58|--a------|733786112] M:\Writers-20Ans De Graffiti · Paris-.avi
                      [03/06/2007 01:23|--a------|737116160] M:\Zodiac.FRENCH.TS.REPACK.1CD.XViD-STS.By.Zodiacix.avi
                      [28/10/2003 04:23|--a------|677230592] M:\[Team.AFP]Les.anges.de.la.nuit.divx5.AC3.FR.cd2.avi
                      [28/10/2003 07:41|--a------|668207104] M:\[Team.AFP]Les.anges.de.la.nuit.divx5.CBR.FR.cd1.avi
                      [22/06/2007 13:32|--a------|734400528] M:\[Tim.Burton].Edward.aux.Mains.d'Argent.[FR.non.canadienne!!!!!].Ripped.by.eRoZion.PCorg.avi
                      [10/08/2007 20:00|--a------|735188992] M:\[?????].Lady.Chatterley.2006.FRENCH.DVDRip.REPACK.XviD-ELiTE.avi

                      ################## | Vaccination |

                      # C:\autorun.inf -> Dossier créé par UsbFix (El Desaparecido).
                      # D:\autorun.inf -> Dossier créé par UsbFix (El Desaparecido).
                      # F:\autorun.inf -> Dossier créé par UsbFix (El Desaparecido).
                      # K:\autorun.inf -> Dossier créé par UsbFix (El Desaparecido).
                      # L:\autorun.inf -> Dossier créé par UsbFix (El Desaparecido).
                      # M:\autorun.inf -> Dossier créé par UsbFix (El Desaparecido).
                      0
                      1. Refais un rapport RSIT stp et poste-le (juste le fichier log.txt).

                        Pour le fichier "UsbFix_Upload_Me_RENO-8589D5E46B.zip", il s'agit des fichiers détectés lors du travail de 'outil, c'est normal que des virus y soient détectés.
                        Cela permet au créateur de l'outil de l'améliorer.
                        0
                        1. Logfile of random's system information tool 1.06 (written by random/random)
                          Run by renaud at 2010-04-22 21:12:41
                          Microsoft Windows XP Professionnel Service Pack 3
                          System drive C: has 243 GB (80%) free of 305 GB
                          Total RAM: 2047 MB (56% free)

                          Logfile of Trend Micro HijackThis v2.0.2
                          Scan saved at 21:12:46, on 22/04/2010
                          Platform: Windows XP SP3 (WinNT 5.01.2600)
                          MSIE: Internet Explorer v8.00 (8.00.6001.18702)
                          Boot mode: Normal

                          Running processes:
                          C:\WINDOWS\System32\smss.exe
                          C:\WINDOWS\system32\winlogon.exe
                          C:\WINDOWS\system32\services.exe
                          C:\WINDOWS\system32\lsass.exe
                          C:\WINDOWS\system32\nvsvc32.exe
                          C:\WINDOWS\system32\svchost.exe
                          C:\WINDOWS\System32\svchost.exe
                          C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
                          C:\WINDOWS\system32\spoolsv.exe
                          C:\Program Files\Avira\AntiVir Desktop\sched.exe
                          C:\WINDOWS\System32\svchost.exe
                          C:\Program Files\Avira\AntiVir Desktop\avguard.exe
                          C:\Program Files\Fichiers communs\Apple\Mobile Device Support\AppleMobileDeviceService.exe
                          C:\Program Files\Application Updater\ApplicationUpdater.exe
                          C:\Program Files\Bonjour\mDNSResponder.exe
                          C:\WINDOWS\system32\HerculesWiFiService.exe
                          C:\Program Files\Java\jre6\bin\jqs.exe
                          C:\Program Files\Fichiers communs\Nero\Nero BackItUp 4\NBService.exe
                          C:\WINDOWS\system32\HPZipm12.exe
                          C:\WINDOWS\system32\SAiDownloader.exe
                          C:\Program Files\Fichiers communs\SafeNet Sentinel\Sentinel Keys Server\sntlkeyssrvr.exe
                          C:\Program Files\Fichiers communs\SafeNet Sentinel\Sentinel Protection Server\WinNT\spnsrvnt.exe
                          C:\WINDOWS\system32\svchost.exe
                          C:\WINDOWS\system32\Wacom_Tablet.exe
                          C:\WINDOWS\system32\cmd.exe
                          C:\WINDOWS\system32\wscntfy.exe
                          C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
                          C:\WINDOWS\explorer.exe
                          C:\Documents and Settings\renaud\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
                          C:\Documents and Settings\renaud\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
                          C:\Documents and Settings\renaud\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
                          C:\Documents and Settings\renaud\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
                          C:\Documents and Settings\renaud\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
                          C:\Documents and Settings\renaud\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
                          C:\Program Files\Mozilla Firefox\firefox.exe
                          C:\Documents and Settings\renaud\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
                          C:\Documents and Settings\renaud\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
                          C:\Documents and Settings\renaud\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
                          D:\dl\RSIT.exe
                          D:\dl\renaud.exe

                          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                          R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
                          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer
                          R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local
                          R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                          R3 - URLSearchHook: (no name) - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:\Program Files\pdfforge Toolbar\SearchSettings.dll
                          R3 - URLSearchHook: Vuze Remote Toolbar - {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files\Vuze_Remote\tbVuze.dll
                          O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
                          O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
                          O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                          O2 - BHO: pdfforge Toolbar - {B922D405-6D13-4A2B-AE89-08A030DA4402} - C:\Program Files\pdfforge Toolbar\IE\1.1.2\pdfforgeToolbarIE.dll (file missing)
                          O2 - BHO: Vuze Remote Toolbar - {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files\Vuze_Remote\tbVuze.dll
                          O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
                          O2 - BHO: (no name) - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:\Program Files\pdfforge Toolbar\SearchSettings.dll
                          O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
                          O3 - Toolbar: pdfforge Toolbar - {B922D405-6D13-4A2B-AE89-08A030DA4402} - C:\Program Files\pdfforge Toolbar\IE\1.1.2\pdfforgeToolbarIE.dll (file missing)
                          O3 - Toolbar: Vuze Remote Toolbar - {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files\Vuze_Remote\tbVuze.dll
                          O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
                          O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
                          O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
                          O4 - HKCU\..\Run: [SuperCopier2.exe] C:\Program Files\SuperCopier2\SuperCopier2.exe
                          O4 - HKCU\..\Run: [Gadwin PrintScreen 2.6] C:\Program Files\PrintScreen\PrintScreen\PrintScreen.exe /nosplash
                          O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
                          O4 - HKCU\..\Run: [EPSON Stylus D92 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIBZE.EXE /FU "C:\WINDOWS\TEMP\E_S39D6.tmp" /EF "HKCU"
                          O4 - HKCU\..\Run: [Simplify Media] "C:\Program Files\Simplify Media\SimplifyMedia.exe"
                          O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
                          O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
                          O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
                          O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
                          O4 - Global Startup: officescan.vbs
                          O4 - Global Startup: Post-it® Software Notes Lite.lnk = C:\Program Files\post it\PSNLite\PsnLite.exe
                          O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
                          O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
                          O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
                          O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                          O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                          O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                          O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                          O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
                          O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/...
                          O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
                          O17 - HKLM\System\CCS\Services\Tcpip\..\{1E5897DE-2C78-4379-9899-997C43B62D50}: NameServer = 192.168.1.254
                          O17 - HKLM\System\CS1\Services\Tcpip\..\{1E5897DE-2C78-4379-9899-997C43B62D50}: NameServer = 192.168.1.254
                          O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
                          O23 - Service: Avira AntiVir Planificateur (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
                          O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
                          O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\AppleMobileDeviceService.exe
                          O23 - Service: Application Updater - Spigot, Inc. - C:\Program Files\Application Updater\ApplicationUpdater.exe
                          O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
                          O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Fichiers communs\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
                          O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                          O23 - Service: HerculesWiFi - Guillemot Corporation - C:\WINDOWS\system32\HerculesWiFiService.exe
                          O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
                          O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
                          O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
                          O23 - Service: Nero BackItUp Scheduler 4.0 - Nero AG - C:\Program Files\Fichiers communs\Nero\Nero BackItUp 4\NBService.exe
                          O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
                          O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
                          O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - C:\Program Files\WinPcap\rpcapd.exe (file missing)
                          O23 - Service: SAiDownloader - TODO: <Company name> - C:\WINDOWS\system32\SAiDownloader.exe
                          O23 - Service: Sentinel Keys Server (SentinelKeysServer) - SafeNet, Inc. - C:\Program Files\Fichiers communs\SafeNet Sentinel\Sentinel Keys Server\sntlkeyssrvr.exe
                          O23 - Service: Sentinel Protection Server (SentinelProtectionServer) - SafeNet, Inc - C:\Program Files\Fichiers communs\SafeNet Sentinel\Sentinel Protection Server\WinNT\spnsrvnt.exe
                          O23 - Service: TabletServiceWacom - Wacom Technology, Corp. - C:\WINDOWS\system32\Wacom_Tablet.exe
                          0
                          1. [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
                            "HonorAutoRunSetting"=
                            "NoDriveAutoRun"=
                            "NoDriveTypeAutoRun"=

                            [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
                            "%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
                            "%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
                            "C:\Program Files\Fichiers communs\SafeNet Sentinel\Sentinel Protection Server\WinNT\spnsrvnt.exe"="C:\Program Files\Fichiers communs\SafeNet Sentinel\Sentinel Protection Server\WinNT\spnsrvnt.exe:*:Enabled:Sentinel Protection Server"
                            "C:\Program Files\Fichiers communs\SafeNet Sentinel\Sentinel Keys Server\sntlkeyssrvr.exe"="C:\Program Files\Fichiers communs\SafeNet Sentinel\Sentinel Keys Server\sntlkeyssrvr.exe:*:Enabled:Sentinel Keys Server"
                            "C:\Program Files\Windows Live\Messenger\wlcsdk.exe"="C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call"
                            "C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"
                            "C:\Program Files\Fichiers communs\Adobe\CS4ServiceManager\CS4ServiceManager.exe"="C:\Program Files\Fichiers communs\Adobe\CS4ServiceManager\CS4ServiceManager.exe:*:Enabled:Adobe CSI CS4"
                            "Y:\eSKernel.exe"="Y:\eSKernel.exe:*:Enabled:Bbox assistant d'installation"
                            "D:\dl\azureus\[PC Game] PES Pro Evolution Soccer 2010 + crack\[PC] PES 2010 + crack\PES 2010\Crack\pes2010.exe"="D:\dl\azureus\[PC Game] PES Pro Evolution Soccer 2010 + crack\[PC] PES 2010 + crack\PES 2010\Crack\pes2010.exe:*:Enabled:Pro Evolution Soccer 2010"
                            "C:\Program Files\KONAMI\Pro Evolution Soccer 2010\pes2010.exe"="C:\Program Files\KONAMI\Pro Evolution Soccer 2010\pes2010.exe:*:Enabled:Pro Evolution Soccer 2010"
                            "C:\Program Files\Rockstar Games\Rockstar Games Social Club\RGSCLauncher.exe"="C:\Program Files\Rockstar Games\Rockstar Games Social Club\RGSCLauncher.exe:*:Enabled:Rockstar Games Social Club"
                            "C:\Program Files\Rockstar Games\Grand Theft Auto IV\LaunchGTAIV.exe"="C:\Program Files\Rockstar Games\Grand Theft Auto IV\LaunchGTAIV.exe:*:Enabled:Grand Theft Auto IV"
                            "C:\Program Files\Bonjour\mDNSResponder.exe"="C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour"
                            "C:\Program Files\iTunes\iTunes.exe"="C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes"
                            "C:\Program Files\Vuze\Azureus.exe"="C:\Program Files\Vuze\Azureus.exe:*:Enabled:Azureus / Vuze"

                            [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
                            "%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
                            "%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
                            "C:\Program Files\Windows Live\Messenger\wlcsdk.exe"="C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call"
                            "C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"

                            ======List of files/folders created in the last 1 months======

                            2010-04-22 19:04:26 ----RASHD---- C:\autorun.inf
                            2010-04-22 18:56:23 ----A---- C:\UsbFix.txt
                            2010-04-22 17:22:10 ----D---- C:\UsbFix
                            2010-04-22 15:56:52 ----D---- C:\rsit
                            2010-04-22 09:11:43 ----HDC---- C:\Documents and Settings\All Users\Application Data\{74D08EB8-01D1-4BAE-91E3-F30C1B031AC6}
                            2010-04-21 21:19:05 ----A---- C:\WINDOWS\system32\lsdelete.exe
                            2010-04-21 19:23:15 ----D---- C:\Program Files\Lavasoft
                            2010-04-21 19:23:15 ----D---- C:\Documents and Settings\All Users\Application Data\Lavasoft
                            2010-04-21 18:23:17 ----D---- C:\Program Files\CCleaner
                            2010-04-21 08:55:19 ----D---- C:\Program Files\Simplify Media
                            2010-04-15 21:13:22 ----D---- C:\Program Files\Vuze_Remote
                            2010-04-15 21:13:22 ----D---- C:\Program Files\Conduit
                            2010-04-15 15:52:53 ----D---- C:\flex_sdk_3.4.1.10084
                            2010-04-01 00:37:28 ----D---- C:\Documents and Settings\renaud\Application Data\Apowersoft
                            2010-03-31 13:54:46 ----A---- C:\WINDOWS\system32\PICSDK2.dll
                            2010-03-31 13:54:46 ----A---- C:\WINDOWS\system32\PICSDK.ini
                            2010-03-31 13:54:46 ----A---- C:\WINDOWS\system32\PICSDK.dll
                            2010-03-31 13:54:46 ----A---- C:\WINDOWS\system32\PICEntry.dll
                            2010-03-31 13:54:46 ----A---- C:\WINDOWS\system32\EpPicPrt.dll
                            2010-03-31 13:54:46 ----A---- C:\WINDOWS\system32\EPPicMgr.dll
                            2010-03-31 13:54:22 ----A---- C:\WINDOWS\system32\E_DCINST.DLL
                            2010-03-31 13:54:21 ----A---- C:\WINDOWS\system32\E_FLBBZE.DLL
                            2010-03-31 13:54:21 ----A---- C:\WINDOWS\system32\E_FD4BBZE.DLL
                            2010-03-31 13:51:14 ----D---- C:\Program Files\EPSON
                            2010-03-31 13:51:12 ----D---- C:\Documents and Settings\All Users\Application Data\EPSON
                            2010-03-31 13:51:06 ----A---- C:\WINDOWS\CDED92Euro.ini
                            2010-03-31 10:50:09 ----D---- C:\Program Files\iPod
                            2010-03-31 10:49:59 ----D---- C:\Program Files\iTunes
                            2010-03-31 10:49:59 ----D---- C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
                            2010-03-31 10:46:11 ----D---- C:\Program Files\QuickTime
                            2010-03-26 11:39:25 ----D---- C:\Documents and Settings\renaud\Application Data\Facebook

                            ======List of files/folders modified in the last 1 months======

                            2010-04-22 21:00:00 ----A---- C:\WINDOWS\SchedLgU.Txt
                            2010-04-22 20:56:11 ----D---- C:\Program Files\Fichiers communs\Akamai
                            2010-04-22 20:54:18 ----D---- C:\WINDOWS\Temp
                            2010-04-22 19:04:29 ----D---- C:\WINDOWS\Prefetch
                            2010-04-22 19:04:18 ----SHD---- C:\RECYCLER
                            2010-04-22 19:00:25 ----D---- C:\WINDOWS\system32
                            2010-04-22 19:00:25 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
                            2010-04-22 18:58:22 ----D---- C:\WINDOWS
                            2010-04-22 18:58:12 ----SD---- C:\WINDOWS\Tasks
                            2010-04-22 18:56:26 ----D---- C:\WINDOWS\system32\CatRoot2
                            2010-04-22 18:53:25 ----D---- C:\Documents and Settings\renaud\Application Data\WTablet
                            2010-04-22 09:15:37 ----HD---- C:\Config.Msi
                            2010-04-22 09:13:42 ----D---- C:\WINDOWS\system32\drivers
                            2010-04-22 09:11:48 ----SHD---- C:\WINDOWS\Installer
                            2010-04-22 09:11:47 ----D---- C:\WINDOWS\WinSxS
                            2010-04-21 21:19:02 ----RD---- C:\Program Files
                            2010-04-21 19:30:56 ----HD---- C:\WINDOWS\inf
                            2010-04-21 19:24:31 ----DC---- C:\WINDOWS\system32\DRVSTORE
                            2010-04-21 18:29:40 ----D---- C:\WINDOWS\system32\LogFiles
                            2010-04-21 18:29:39 ----D---- C:\WINDOWS\Minidump
                            2010-04-21 18:29:39 ----D---- C:\WINDOWS\Debug
                            2010-04-21 16:57:59 ----RSD---- C:\WINDOWS\Fonts
                            2010-04-21 10:02:56 ----D---- C:\Documents and Settings\renaud\Application Data\Azureus
                            2010-04-18 21:37:07 ----D---- C:\Documents and Settings\renaud\Application Data\vlc
                            2010-04-18 20:44:41 ----D---- C:\Documents and Settings\renaud\Application Data\dvdcss
                            2010-04-17 18:38:49 ----D---- C:\Program Files\Graffiti Studio 2.0
                            2010-04-16 15:06:23 ----D---- C:\Program Files\eMule
                            2010-04-15 21:13:46 ----D---- C:\Program Files\Vuze
                            2010-04-15 16:38:41 ----RSHDC---- C:\WINDOWS\system32\dllcache
                            2010-04-15 16:38:34 ----HD---- C:\WINDOWS\$hf_mig$
                            2010-04-15 16:36:37 ----D---- C:\WINDOWS\ie8updates
                            2010-04-06 19:52:54 ----A---- C:\WINDOWS\system32\MRT.exe
                            2010-04-04 19:13:31 ----D---- C:\Documents and Settings\renaud\Application Data\Canon
                            2010-04-03 10:38:43 ----D---- C:\Program Files\Mozilla Firefox
                            2010-04-01 17:16:20 ----D---- C:\WINDOWS\system32\inetsrv
                            2010-03-31 17:47:04 ----SH---- C:\boot.ini
                            2010-03-31 17:47:04 ----A---- C:\WINDOWS\win.ini
                            2010-03-31 17:47:04 ----A---- C:\WINDOWS\system.ini
                            2010-03-31 17:47:03 ----D---- C:\WINDOWS\pss
                            2010-03-31 10:50:05 ----D---- C:\Program Files\Fichiers communs\Apple
                            2010-03-31 10:42:35 ----D---- C:\Program Files\Bonjour
                            2010-03-31 10:36:15 ----D---- C:\Program Files\Safari
                            2010-03-24 12:07:16 ----D---- C:\Documents and Settings\renaud\Application Data\filebibteam

                            ======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

                            R1 AsIO;AsIO; C:\WINDOWS\system32\drivers\AsIO.sys [2007-12-17 12400]
                            R1 avgio;avgio; \??\C:\Program Files\Avira\AntiVir Desktop\avgio.sys []
                            R1 avipbb;avipbb; C:\WINDOWS\system32\DRIVERS\avipbb.sys [2009-03-30 96104]
                            R1 intelppm;Pilote de processeur Intel; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-14 40576]
                            R1 kbdhid;Pilote HID de clavier; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-14 14720]
                            R1 ssmdrv;ssmdrv; C:\WINDOWS\system32\DRIVERS\ssmdrv.sys [2009-05-11 28520]
                            R2 adfs;adfs; C:\WINDOWS\system32\drivers\adfs.sys [2008-08-14 74720]
                            R2 AegisP;AEGIS Protocol (IEEE 802.1x) v3.4.5.0; C:\WINDOWS\system32\DRIVERS\AegisP.sys [2009-11-16 21035]
                            R2 avgntflt;avgntflt; C:\WINDOWS\system32\DRIVERS\avgntflt.sys [2009-12-10 56816]
                            R2 NwlnkIpx;Protocole de transport compatible NWLink IPX/SPX/NetBIOS; C:\WINDOWS\system32\DRIVERS\nwlnkipx.sys [2008-04-13 88320]
                            R2 NwlnkNb;NetBIOS NWLink; C:\WINDOWS\system32\DRIVERS\nwlnknb.sys [2004-08-05 63232]
                            R2 NwlnkSpx;Protocole NWLink SPX/SPXII; C:\WINDOWS\system32\DRIVERS\nwlnkspx.sys [2004-08-05 55936]
                            R2 Sentinel;Sentinel; C:\WINDOWS\System32\Drivers\SENTINEL.SYS [2007-04-27 90688]
                            R3 Arp1394;Protocole client ARP 1394; C:\WINDOWS\system32\DRIVERS\arp1394.sys [2008-04-13 60800]
                            R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys [2009-05-18 26600]
                            R3 HDAudBus;Pilote de bus Microsoft UAA pour High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
                            R3 hidusb;Pilote de classe HID Microsoft; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
                            R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2008-05-20 4800000]
                            R3 L1e;Miniport Driver for Atheros AR8121/AR8113 PCI-E Ethernet Controller; C:\WINDOWS\system32\DRIVERS\l1e51x86.sys [2008-02-02 36864]
                            R3 mouhid;Pilote HID de souris; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-08-23 12288]
                            R3 MTsensor;ATK0110 ACPI UTILITY; C:\WINDOWS\system32\DRIVERS\ASACPI.sys [2004-08-13 5810]
                            R3 NIC1394;Pilote réseau 1394; C:\WINDOWS\system32\DRIVERS\nic1394.sys [2008-04-13 61824]
                            R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2010-01-12 10276768]
                            R3 NWRDR;NetWare Rdr; C:\WINDOWS\system32\DRIVERS\nwrdr.sys [2008-04-13 163584]
                            R3 SNTNLUSB;SafeNet USB SuperPro/UltraPro/HardwareKey; C:\WINDOWS\system32\DRIVERS\SNTNLUSB.SYS [2007-04-27 35328]
                            R3 usbccgp;Pilote parent générique USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
                            R3 usbehci;Pilote miniport de contrôleur d'hôte amélioré Microsoft USB 2.0; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-13 30208]
                            R3 usbhub;Pilote de concentrateur standard USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-13 59520]
                            R3 usbprint;Classe d'imprimantes USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-13 25856]
                            R3 usbstor;Pilote de stockage de masse USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
                            R3 usbuhci;Pilote miniport de contrôleur hôte universel USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]
                            R3 wacommousefilter;Wacom Mouse Filter Driver; C:\WINDOWS\system32\DRIVERS\wacommousefilter.sys [2007-02-16 11312]
                            R3 wacomvhid;Wacom Virtual Hid Driver; C:\WINDOWS\system32\DRIVERS\wacomvhid.sys [2009-05-20 13736]
                            S2 NPF;NetGroup Packet Filter Driver; C:\WINDOWS\system32\drivers\npf.sys []
                            S2 Par1284;Par1284; \??\C:\Program Files\Secabo\Secabo Production Suite1\Program\Par1284.sys []
                            S3 aow5abnf;aow5abnf; C:\WINDOWS\system32\drivers\aow5abnf.sys []
                            S3 CH341SER;CH341SER; C:\WINDOWS\System32\Drivers\CH341SER.SYS [2007-09-24 37488]
                            S3 HPZid412;IEEE-1284.4 Driver HPZid412; C:\WINDOWS\system32\DRIVERS\HPZid412.sys [2005-03-08 51120]
                            S3 HPZipr12;Print Class Driver for IEEE-1284.4 HPZipr12; C:\WINDOWS\system32\DRIVERS\HPZipr12.sys [2005-03-08 16496]
                            S3 HPZius12;USB to IEEE-1284.4 Translation Driver HPZius12; C:\WINDOWS\system32\DRIVERS\HPZius12.sys [2005-03-08 21744]
                            S3 rtl8185;Realtek RTL8185 54M Wireless LAN Network Adapter Driver; C:\WINDOWS\system32\DRIVERS\rtl8185.sys []
                            S3 RTL8192su;Realtek RTL8192SU Wireless LAN 802.11n USB 2.0 Network Adapter; C:\WINDOWS\system32\DRIVERS\RTL8192su.sys [2009-05-15 583552]
                            S3 USBAAPL;Apple Mobile USB Driver; C:\WINDOWS\System32\Drivers\usbaapl.sys [2009-10-16 41472]
                            S3 usbscan;Pilote de scanneur USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-13 15104]
                            S3 wacmoumonitor;Wacom Mode Helper; C:\WINDOWS\system32\DRIVERS\wacmoumonitor.sys [2009-08-28 16168]
                            S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
                            S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
                            S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []

                            ======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

                            R2 Akamai;Akamai NetSession Interface; C:\WINDOWS\System32\svchost.exe [2008-04-14 14336]
                            R2 AntiVirSchedulerService;Avira AntiVir Planificateur; C:\Program Files\Avira\AntiVir Desktop\sched.exe [2009-05-13 108289]
                            R2 AntiVirService;Avira AntiVir Guard; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [2009-07-21 185089]
                            R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files\Fichiers communs\Apple\Mobile Device Support\AppleMobileDeviceService.exe [2010-03-19 144672]
                            R2 Application Updater;Application Updater; C:\Program Files\Application Updater\ApplicationUpdater.exe [2010-01-08 380928]
                            R2 Bonjour Service;Service Bonjour; C:\Program Files\Bonjour\mDNSResponder.exe [2010-02-12 345376]
                            R2 HerculesWiFi;HerculesWiFi; C:\WINDOWS\system32\HerculesWiFiService.exe [2009-05-07 53544]
                            R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2009-10-11 153376]
                            R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service; C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe [2010-04-22 1265264]
                            R2 Nero BackItUp Scheduler 4.0;Nero BackItUp Scheduler 4.0; C:\Program Files\Fichiers communs\Nero\Nero BackItUp 4\NBService.exe [2009-09-23 935208]
                            R2 NVSvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2010-01-11 154216]
                            R2 NWCWorkstation;Service client pour NetWare; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
                            R2 Pml Driver HPZ12;Pml Driver HPZ12; C:\WINDOWS\system32\HPZipm12.exe [2004-09-29 69632]
                            R2 SAiDownloader;SAiDownloader; C:\WINDOWS\system32\SAiDownloader.exe [2007-09-11 438272]
                            R2 SentinelKeysServer;Sentinel Keys Server; C:\Program Files\Fichiers communs\SafeNet Sentinel\Sentinel Keys Server\sntlkeyssrvr.exe [2007-04-27 316992]
                            R2 SentinelProtectionServer;Sentinel Protection Server; C:\Program Files\Fichiers communs\SafeNet Sentinel\Sentinel Protection Server\WinNT\spnsrvnt.exe [2007-04-27 206400]
                            R2 TabletServiceWacom;TabletServiceWacom; C:\WINDOWS\system32\Wacom_Tablet.exe [2009-10-06 4463400]
                            S3 Adobe LM Service;Adobe LM Service; C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe [2010-03-18 72704]
                            S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
                            S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
                            S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files\Fichiers communs\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2009-12-19 655624]
                            S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
                            S3 gusvc;Google Updater Service; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-11-20 136120]
                            S3 idsvc;Windows CardSpace; c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
                            S3 iPod Service;Service de l'iPod; C:\Program Files\iPod\bin\iPodService.exe [2010-03-26 545576]
                            S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Fichiers communs\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
                            S3 ose;Office Source Engine; C:\Program Files\Fichiers communs\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
                            S3 rpcapd;Remote Packet Capture Protocol v.0 (experimental); C:\Program Files\WinPcap\rpcapd.exe -d -f C:\Program Files\WinPcap\rpcapd.ini []
                            S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
                            S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]

                            -----------------EOF-----------------
                            0
                            1. Ok, on va maintenant s'occuper d'une Toolbar néfaste :

                              Note : Tu as une Toolbar infectieuse (Pdfforge). Les Toolbars sont généralement proposées en accompagnement d'autres logiciels à leur installation.
                              Quand tu installes un logiciel, prends le temps de lire les options d'installation et décoche les programmes additionnels inutiles (ne clique pas bêtement sur "suivant").


                              ● Télécharge et enregistre le fichier sur ton bureau Ad-Remover

                              ● Double clique sur AD-R.exe

                              ● Au menu principal choisis l'option "Nettoyer"

                              ● Patiente pendant que l'outil fait son travail

                              ● Un rapport va s'ouvrir, copie/colle le dans ta réponse

                              ▲ Le rapport est sauvegardé dans C:\Ad-report.log

                              Note :
                              Process.exe est détecté par certains antivirus comme étant un RiskTool.
                              Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.
                              0
                              1. je fais attention généralement...

                                .
                                ======= RAPPORT D'AD-REMOVER 2.0.0.0,C | UNIQUEMENT XP/VISTA/7 =======
                                .
                                Mis à jour par C_XX le 22/04/10 à 19:00
                                Contact: AdRemover.contact@gmail.com
                                Site web: http://pagesperso-orange.fr/NosTools/ad_remover.html
                                .
                                Lancé à: 21:32:44 le 22/04/2010 | Mode normal | Option: CLEAN
                                Exécuté de: C:\Ad-Remover\ADR.exe
                                SE: Microsoft® Windows XP(TM) Service Pack 3 - X86
                                Nom du PC: RENO-8589D5E46B
                                Utilisateur actuel: renaud (Administrateur)
                                .
                                ============== ÉLÉMENT(S) NEUTRALISÉ(S) ==============
                                .
                                Service: *Application Updater*
                                .
                                C:\Documents and Settings\renaud\Application Data\pdfforge
                                C:\Documents and Settings\renaud\Application Data\Search Settings
                                C:\Program Files\Application Updater
                                C:\Program Files\Mozilla Firefox\extensions\searchsettings@spigot.com
                                C:\Program Files\pdfforge Toolbar

                                (!) -- Fichiers temporaires supprimés.
                                .
                                HKCU\Software\AppDataLow\Software\pdfforge
                                HKCU\Software\Microsoft\Internet Explorer\LowRegistry\Search Settings
                                HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}
                                HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{B922D405-6D13-4A2B-AE89-08A030DA4402}
                                HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{E312764E-7706-43F1-8DAB-FCDD2B1E416D}
                                HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B922D405-6D13-4A2B-AE89-08A030DA4402}
                                HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{E312764E-7706-43F1-8DAB-FCDD2B1E416D}
                                HKCU\Software\Search Settings
                                HKLM\Software\Application Updater
                                HKLM\Software\Classes\CLSID\{B922D405-6D13-4A2B-AE89-08A030DA4402}
                                HKLM\Software\Classes\CLSID\{E312764E-7706-43F1-8DAB-FCDD2B1E416D}
                                HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B922D405-6D13-4A2B-AE89-08A030DA4402}
                                HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E312764E-7706-43F1-8DAB-FCDD2B1E416D}
                                HKLM\Software\pdfforge
                                HKLM\Software\Search Settings
                                HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks|{E312764E-7706-43F1-8DAB-FCDD2B1E416D}
                                HKLM\Software\Microsoft\Internet Explorer\Toolbar|{B922D405-6D13-4A2B-AE89-08A030DA4402}
                                HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDLLs|C:\Program Files\Application Updater\ApplicationUpdater.exe
                                HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDLLs|C:\Program Files\pdfforge Toolbar\FF\chrome.manifest
                                HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDLLs|C:\Program Files\pdfforge Toolbar\FF\chrome\locale\EN-US\widgitoolbarplugin.properties
                                HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDLLs|C:\Program Files\pdfforge Toolbar\FF\components\pdfforgeToolbarFF.dll
                                HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDLLs|C:\Program Files\pdfforge Toolbar\FF\install.rdf
                                HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDLLs|C:\Program Files\pdfforge Toolbar\SearchSettings.dll
                                HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDLLs|C:\Program Files\pdfforge Toolbar\SearchSettings.exe
                                HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDLLs|C:\Program Files\pdfforge Toolbar\SSFF\chrome.manifest
                                HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDLLs|C:\Program Files\pdfforge Toolbar\SSFF\chrome\locale\en-US\searchsettingsplugin.dtd
                                HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDLLs|C:\Program Files\pdfforge Toolbar\SSFF\components\SearchSettingsFF.dll
                                HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDLLs|C:\Program Files\pdfforge Toolbar\SSFF\install.rdf
                                .
                                (Orpheline) HKCU,Run - EPSON Stylus D92 Series - C:\WINDOWS\TEMP\E_S39D6.tmp (Fichier manquant)
                                (Orpheline) BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} (CLSID manquant)
                                (Orpheline) HKLM,Uninstall - KB888111WXPSP2 - C:\WINDOWS\$NtUninstallKB888111WXPSP2$\spuninst\spuninst.exe (Fichier manquant)
                                (Orpheline) HKLM,Uninstall - KB923561 - C:\WINDOWS\$NtUninstallKB923561$\spuninst\spuninst.exe (Fichier manquant)
                                (Orpheline) HKLM,Uninstall - KB941569 - C:\WINDOWS\$NtUninstallKB941569$\spuninst\spuninst.exe (Fichier manquant)
                                (Orpheline) HKLM,Uninstall - KB950762 - C:\WINDOWS\$NtUninstallKB950762$\spuninst\spuninst.exe (Fichier manquant)
                                (Orpheline) HKLM,Uninstall - KB951066 - C:\WINDOWS\$NtUninstallKB951066$\spuninst\spuninst.exe (Fichier manquant)
                                (Orpheline) HKLM,Uninstall - KB951748 - C:\WINDOWS\$NtUninstallKB951748$\spuninst\spuninst.exe (Fichier manquant)
                                (Orpheline) HKLM,Uninstall - KB952004 - C:\WINDOWS\$NtUninstallKB952004$\spuninst\spuninst.exe (Fichier manquant)
                                (Orpheline) HKLM,Uninstall - KB952287 - C:\WINDOWS\$NtUninstallKB952287$\spuninst\spuninst.exe (Fichier manquant)
                                (Orpheline) HKLM,Uninstall - KB954155_WM9 - C:\WINDOWS\$NtUninstallKB954155_WM9$\spuninst\spuninst.exe (Fichier manquant)
                                (Orpheline) HKLM,Uninstall - KB955069 - C:\WINDOWS\$NtUninstallKB955069$\spuninst\spuninst.exe (Fichier manquant)
                                (Orpheline) HKLM,Uninstall - KB956572 - C:\WINDOWS\$NtUninstallKB956572$\spuninst\spuninst.exe (Fichier manquant)
                                (Orpheline) HKLM,Uninstall - KB956802 - C:\WINDOWS\$NtUninstallKB956802$\spuninst\spuninst.exe (Fichier manquant)
                                (Orpheline) HKLM,Uninstall - KB956844 - C:\WINDOWS\$NtUninstallKB956844$\spuninst\spuninst.exe (Fichier manquant)
                                (Orpheline) HKLM,Uninstall - KB958644 - C:\WINDOWS\$NtUninstallKB958644$\spuninst\spuninst.exe (Fichier manquant)
                                (Orpheline) HKLM,Uninstall - KB958869 - C:\WINDOWS\$NtUninstallKB958869$\spuninst\spuninst.exe (Fichier manquant)
                                (Orpheline) HKLM,Uninstall - KB960803 - C:\WINDOWS\$NtUninstallKB960803$\spuninst\spuninst.exe (Fichier manquant)
                                (Orpheline) HKLM,Uninstall - KB961118 - C:\WINDOWS\$NtUninstallKB961118$\spuninst\spuninst.exe (Fichier manquant)
                                (Orpheline) HKLM,Uninstall - KB961501 - C:\WINDOWS\$NtUninstallKB961501$\spuninst\spuninst.exe (Fichier manquant)
                                (Orpheline) HKLM,Uninstall - KB967715 - C:\WINDOWS\$NtUninstallKB967715$\spuninst\spuninst.exe (Fichier manquant)
                                (Orpheline) HKLM,Uninstall - KB968537 - C:\WINDOWS\$NtUninstallKB968537$\spuninst\spuninst.exe (Fichier manquant)
                                (Orpheline) HKLM,Uninstall - KB969059 - C:\WINDOWS\$NtUninstallKB969059$\spuninst\spuninst.exe (Fichier manquant)
                                (Orpheline) HKLM,Uninstall - KB970238 - C:\WINDOWS\$NtUninstallKB970238$\spuninst\spuninst.exe (Fichier manquant)
                                (Orpheline) HKLM,Uninstall - KB970653-v3 - C:\WINDOWS\$NtUninstallKB970653-v3$\spuninst\spuninst.exe (Fichier manquant)
                                (Orpheline) HKLM,Uninstall - KB971486 - C:\WINDOWS\$NtUninstallKB971486$\spuninst\spuninst.exe (Fichier manquant)
                                (Orpheline) HKLM,Uninstall - KB971633 - C:\WINDOWS\$NtUninstallKB971633$\spuninst\spuninst.exe (Fichier manquant)
                                (Orpheline) HKLM,Uninstall - KB971737 - C:\WINDOWS\$NtUninstallKB971737$\spuninst\spuninst.exe (Fichier manquant)
                                (Orpheline) HKLM,Uninstall - KB973354 - C:\WINDOWS\$NtUninstallKB973354$\spuninst\spuninst.exe (Fichier manquant)
                                (Orpheline) HKLM,Uninstall - KB973525 - C:\WINDOWS\$NtUninstallKB973525$\spuninst\spuninst.exe (Fichier manquant)
                                (Orpheline) HKLM,Uninstall - KB973540_WM9L - C:\WINDOWS\$NtUninstallKB973540_WM9L$\spuninst\spuninst.exe (Fichier manquant)
                                (Orpheline) HKLM,Uninstall - KB973815 - C:\WINDOWS\$NtUninstallKB973815$\spuninst\spuninst.exe (Fichier manquant)
                                (Orpheline) HKLM,Uninstall - KB973904 - C:\WINDOWS\$NtUninstallKB973904$\spuninst\spuninst.exe (Fichier manquant)
                                (Orpheline) HKLM,Uninstall - KB974318 - C:\WINDOWS\$NtUninstallKB974318$\spuninst\spuninst.exe (Fichier manquant)
                                (Orpheline) HKLM,Uninstall - KB974455 - C:\WINDOWS\$NtUninstallKB974455$\spuninst\spuninst.exe (Fichier manquant)
                                (Orpheline) HKLM,Uninstall - KB974571 - C:\WINDOWS\$NtUninstallKB974571$\spuninst\spuninst.exe (Fichier manquant)
                                (Orpheline) HKLM,Uninstall - KB975467 - C:\WINDOWS\$NtUninstallKB975467$\spuninst\spuninst.exe (Fichier manquant)
                                (Orpheline) HKLM,Uninstall - KB975561 - C:\WINDOWS\$NtUninstallKB975561$\spuninst\spuninst.exe (Fichier manquant)
                                (Orpheline) HKLM,Uninstall - KB976098-v2 - C:\WINDOWS\$NtUninstallKB976098-v2$\spuninst\spuninst.exe (Fichier manquant)
                                (Orpheline) HKLM,Uninstall - KB977165 - C:\WINDOWS\$NtUninstallKB977165$\spuninst\spuninst.exe (Fichier manquant)
                                (Orpheline) HKLM,Uninstall - KB977914 - C:\WINDOWS\$NtUninstallKB977914$\spuninst\spuninst.exe (Fichier manquant)
                                (Orpheline) HKLM,Uninstall - KB978251 - C:\WINDOWS\$NtUninstallKB978251$\spuninst\spuninst.exe (Fichier manquant)
                                (Orpheline) HKLM,Uninstall - KB978338 - C:\WINDOWS\$NtUninstallKB978338$\spuninst\spuninst.exe (Fichier manquant)
                                (Orpheline) HKLM,Uninstall - KB978601 - C:\WINDOWS\$NtUninstallKB978601$\spuninst\spuninst.exe (Fichier manquant)
                                (Orpheline) HKLM,Uninstall - KB979309 - C:\WINDOWS\$NtUninstallKB979309$\spuninst\spuninst.exe (Fichier manquant)
                                (Orpheline) HKLM,Uninstall - KB979683 - C:\WINDOWS\$NtUninstallKB979683$\spuninst\spuninst.exe (Fichier manquant)
                                (Orpheline) HKLM,Uninstall - NVIDIA Display Control Panel - C:\Program Files\NVIDIA Corporation\Uninstall\nvuninst.exe (Fichier manquant)
                                (Orpheline) HKCU,Uninstall - browsesigncorn - C:\DOCUME~1\renaud\APPLIC~1\FILEBI~1\Gramblue.exe (Fichier manquant)
                                .
                                ============== SCAN ADDITIONNEL ==============
                                .
                                * Mozilla FireFox Version 3.6.3 (fr) *
                                .
                                C:\Documents and Settings\renaud\..\hcuw06jz.default\prefs.js - browser.download.dir: D:\\dl
                                C:\Documents and Settings\renaud\..\hcuw06jz.default\prefs.js - browser.download.lastDir: C:\\Documents and Settings\\renaud\\Bureau
                                C:\Documents and Settings\renaud\..\hcuw06jz.default\prefs.js - browser.search.defaulturl: hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2504091&SearchSource=3&q={searchTerms}
                                C:\Documents and Settings\renaud\..\hcuw06jz.default\prefs.js - browser.search.selectedEngine: Google Powered Search
                                C:\Documents and Settings\renaud\..\hcuw06jz.default\prefs.js - browser.startup.homepage: www.google.fr
                                C:\Documents and Settings\renaud\..\hcuw06jz.default\prefs.js - browser.startup.homepage_override.mstone: rv:1.9.2.3
                                .
                                .
                                * Internet Explorer Version 8.0.6001.18702 *
                                .
                                [HKCU\Software\Microsoft\Internet Explorer\Main]
                                .
                                AutoHide: yes
                                Default_Page_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
                                Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
                                Do404Search: 0x01000000
                                Enable Browser Extensions: yes
                                Local Page: C:\WINDOWS\system32\blank.htm
                                Search bar: hxxp://go.microsoft.com/fwlink/?linkid=54896
                                Show_ToolBar: yes
                                Start Page: hxxp://fr.msn.com/
                                Use Search Asst: no
                                .
                                [HKLM\Software\Microsoft\Internet Explorer\Main]
                                .
                                Default_Page_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
                                Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
                                Delete_Temp_Files_On_Exit: yes
                                Local Page: C:\WINDOWS\system32\blank.htm
                                Search bar: hxxp://search.msn.com/spbasic.htm
                                Search Page: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
                                Start Page: hxxp://fr.msn.com/
                                .
                                [HKLM\Software\Microsoft\Internet Explorer\ABOUTURLS]
                                .
                                Tabs: res://ieframe.dll/tabswelcome.htm
                                Blank: res://mshtml.dll/blank.htm
                                .
                                ============== SUSPECT(S) ==============
                                .
                                C:\Documents and Settings\renaud\Application Data\Azureus\torrents\Photoshop_CS4_(Keygen_and_Tutorial)_Virus_Free_.4535812.TPB.torrent
                                .
                                ========================================
                                .
                                C:\DOCUME~1\renaud\LOCALS~1\Temp: 3 Fichier(s), 72 Dossier(s)
                                C:\WINDOWS\temp: 5 Fichier(s), 0 Dossier(s)
                                Temporary Internet Files: 2 Fichier(s), 9 Dossier(s)
                                .
                                C:\Ad-Remover\Quarantine: 79 Fichier(s)
                                C:\Ad-Remover\Backup: 13 Fichier(s)
                                .
                                C:\Ad-Report-CLEAN[1].txt - 11440 Octet(s)
                                .
                                Fin à: 21:35:04, 22/04/2010
                                .
                                ============== E.O.F - CLEAN[1] ==============
                                0
                                1. j'ai redémmaré mon poste comme me le conseillait Ad-Remover, au démarrage de windows j'ai de nouveau eu le message :

                                  http://img706.imageshack.us/img706/8061/screenshot046n.jpg

                                  Processing Message C 0000013 Parameters 75afbf7c 4 75afbf7c 4 75afbf7c 75afbf7c
                                  0
                                  1. On a beau faire attention, certaines Toolbars savent se faire discrètes à l'installation.
                                    Évite aussi les cracks et keygens (Photoshop_CS4_(Keygen_and_Tutorial)_Virus_Free_.4535812.TPB.torrent)
                                    La mention "Virus Free" sur les réseaux P2P n'est pas forcément gage de qualité ;).

                                    La suite :

                                    ● Télécharge Malwarebytes' Anti-Malware (MBAM)

                                    ● Double clique sur mbam-setup.exe pour lancer l'installation

                                    ● Laisse les options par défaut lors de l'installation

                                    ● Lance MBAM et laisse les Mises à jour se télécharger

                                    ● Va dans l'onglet Recherche, choisis "Exécuter un examen complet" puis clique sur Rechercher
                                    Note : le scan peut durer plusieurs heures en fonction de la quantité de données présente sur ton PC

                                    ● A la fin du scan, clique sur Afficher les résultats

                                    ● Coche tous les éléments détectés puis clique sur Supprimer la sélection

                                    ● S'il t'est demandé de redémarrer, clique sur Yes

                                    ● Un rapport va s'ouvrir, copie/colle le dans ta réponse

                                    ▲ Le rapport se trouve dans l'onglet Rapports/Logs de MBAM
                                    0
                                    1. Malwarebytes' Anti-Malware 1.45
                                      www.malwarebytes.org

                                      Version de la base de données: 4023

                                      Windows 5.1.2600 Service Pack 3
                                      Internet Explorer 8.0.6001.18702

                                      23/04/2010 00:10:23
                                      mbam-log-2010-04-23 (00-10-23).txt

                                      Type d'examen: Examen complet (C:\|D:\|F:\|K:\|L:\|M:\|)
                                      Elément(s) analysé(s): 314397
                                      Temps écoulé: 2 heure(s), 5 minute(s), 1 seconde(s)

                                      Processus mémoire infecté(s): 0
                                      Module(s) mémoire infecté(s): 0
                                      Clé(s) du Registre infectée(s): 1
                                      Valeur(s) du Registre infectée(s): 0
                                      Elément(s) de données du Registre infecté(s): 0
                                      Dossier(s) infecté(s): 0
                                      Fichier(s) infecté(s): 2

                                      Processus mémoire infecté(s):
                                      (Aucun élément nuisible détecté)

                                      Module(s) mémoire infecté(s):
                                      (Aucun élément nuisible détecté)

                                      Clé(s) du Registre infectée(s):
                                      HKEY_CURRENT_USER\SOFTWARE\NetPumper (Adware.NetPumper) -> Quarantined and deleted successfully.

                                      Valeur(s) du Registre infectée(s):
                                      (Aucun élément nuisible détecté)

                                      Elément(s) de données du Registre infecté(s):
                                      (Aucun élément nuisible détecté)

                                      Dossier(s) infecté(s):
                                      (Aucun élément nuisible détecté)

                                      Fichier(s) infecté(s):
                                      C:\System Volume Information\_restore{7469EBB7-4D8D-4584-8781-32D28CF2BD81}\RP145\A0024660.exe (Trojan.Agent.CK) -> Quarantined and deleted successfully.
                                      C:\System Volume Information\_restore{7469EBB7-4D8D-4584-8781-32D28CF2BD81}\RP230\A0035641.exe (Adware.NetPumper) -> Quarantined and deleted successfully.
                                      0
                                      1. apres avoir posté le rapport, j'ai eteint le PC, et au démarrage ce matin, j'ai toujours le meme message d'erreur :

                                        http://img706.imageshack.us/img706/8061/screenshot046n.jpg

                                        Processing Message C 0000013 Parameters 75afbf7c 4 75afbf7c 4 75afbf7c 75afbf7c

                                        en plus de ca, avast me detecte un virus dans C:\WINDOWS\winrun.dll.vbs (contient le modèle de détection du virus de script HTML HTML/Rce.Gen)
                                        0
                                        1. Refais un rapport RSIT stp.
                                          0
                                          • 1
                                          • 2
                                          • 3
                                          • 4