Intrusion HTTP LOP Toolbar Activity

bonjour,
voilà j'ai un souci avec mon pc, j'ai norton antivirus qui est constament en train de m'avertir d'une tentative d'intrusion
Intrusion: HTTP LOP Toolbar Activity
Intrus : localhost (1546)
niveau de risque : élevé
Protocole : TCP
IP attaqué : ads.dns-look-up.com(64.34.228.126)
Port attaqué : http(80)

J'ai windows XP SP2 édition familliale

je sais qu'il y a pas mal de personnes ayant ce problème , j'ai téléchargé HiJackThis et voici le rapport:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 13:09:42, on 09/09/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\System32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
c:\Program Files\Fichiers communs\Symantec Shared\ccProxy.exe
c:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
c:\Program Files\Norton Internet Security\ISSVC.exe
c:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
c:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
c:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe
c:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
c:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\LxrJD31s.exe
C:\Program Files\Spyware Doctor\svcntaux.exe
C:\Program Files\Spyware Doctor\swdsvc.exe
C:\WINDOWS\system32\svchost.exe
c:\Program Files\Fichiers communs\Symantec Shared\Security Center\SymWSC.exe
C:\Program Files\Spyware Doctor\SDTrayApp.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
C:\windows\system\hpsysdrv.exe
C:\WINDOWS\AGRSMMSG.exe
C:\HP\KBD\KBD.EXE
C:\Program Files\Fichiers communs\InterVideo\SchSvr\SchSvr.exe
C:\Program Files\InterVideo\Common\Bin\WinRemote.exe
C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\ALCXMNTR.EXE
C:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
C:\WINDOWS\vsnpstd2.exe
C:\Program Files\OrangeHSS\Systray\SystrayApp.exe
C:\Program Files\OrangeHSS\Launcher\Launcher.exe
C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\AlertModule\0\AlertModule.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\OrangeHSS\connectivity\connectivitymanager.exe
C:\Program Files\OrangeHSS\connectivity\CoreCom\CoreCom.exe
C:\Program Files\OrangeHSS\connectivity\CoreCom\OraConfigRecover.exe
C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTCOMModule\0\FTCOMModule.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\WinRAR\WinRAR.exe
C:\DOCUME~1\HP_PRO~1\LOCALS~1\Temp\Rar$EX00.344\HijackThis.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr?cobrand=hp-desktop.msn.com&ocid=HPDHP&pc=HPDTDF
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=FR_FR&c=Q105&bd=pavilion&pf=desktop
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=FR_FR&c=Q105&bd=pavilion&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://estore.sonic.com/upgrades/purchase.asp?srnm=CK5RGXJS6LVQ7LYHC&lang=FRA&id=14
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\Program Files\OrangeHSS\SearchURLHook\SearchPageURL.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Shareaza Web Download Hook - {0EEDB912-C5FA-486F-8334-57288578C627} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - c:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - c:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [Home Theater SchSvr] "C:\Program Files\Fichiers communs\InterVideo\SchSvr\SchSvr.exe"
O4 - HKLM\..\Run: [WINREMOTE] "C:\Program Files\InterVideo\Common\Bin\WinRemote.exe"
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\FICHIE~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [SSC_UserPrompt] c:\Program Files\Fichiers communs\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SNPSTD2] C:\WINDOWS\vsnpstd2.exe
O4 - HKLM\..\Run: [SystrayORAHSS] "C:\Program Files\OrangeHSS\Systray\SystrayApp.exe"
O4 - HKLM\..\Run: [orahssStartup] "C:\Program Files\OrangeHSS\Launcher\Launcher.exe" -appid connectivityapp
O4 - HKLM\..\Run: [Sony Ericsson PC Suite] "C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions
O4 - HKLM\..\Run: [the bone download 1] C:\Documents and Settings\All Users\Application Data\axis wait the bone\film flag.exe
O4 - HKLM\..\Run: [SDTray] "C:\Program Files\Spyware Doctor\SDTrayApp.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Wipe rule] C:\DOCUME~1\LOCALS~1\APPLIC~1\SECOND~1\BowsStupid.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Windows Registry Repair Pro] C:\Program Files\3B Software\Windows Registry Repair Pro\RegistryRepairPro.exe 4
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_8 -reboot 1
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - .DEFAULT User Startup: AutoTBar.exe (User 'Default user')
O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Utilitaire réseau pour SAGEM Wi-Fi 11g USB adapter.lnk = ?
O4 - Global Startup: Weezo.lnk = C:\Program Files\Weezo\bin\Weezo.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program Files\Fichiers communs\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messager Wanadoo - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\WANADO~1\Wanadoo Messager.exe
O9 - Extra 'Tools' menuitem: Messager Wanadoo - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\WANADO~1\Wanadoo Messager.exe
O9 - Extra button: Wanadoo - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - https://www.orange.fr/portail (file missing) (HKCU)
O16 - DPF: {31B7EB4E-8B4B-11D1-A789-00A0CC6651A8} (Cult3D ActiveX Player) - https://www.cult3d.com/
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase9602.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O20 - Winlogon Notify: winhld32 - winhld32.dll (file missing)
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - c:\Program Files\Fichiers communs\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - c:\Program Files\Fichiers communs\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom SA - C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: ISSvc (ISSVC) - Symantec Corporation - c:\Program Files\Norton Internet Security\ISSVC.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Unknown owner - c:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
O23 - Service: Lexar JD31 (LxrJD31s) - Unknown owner - C:\WINDOWS\SYSTEM32\LxrJD31s.exe
O23 - Service: Service Norton AntiVirus Auto-Protect (navapsvc) - Symantec Corporation - c:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: SAVScan - Symantec Corporation - c:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - c:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - c:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - c:\Program Files\Fichiers communs\Symantec Shared\Security Center\SymWSC.exe

--
End of file - 12668 bytes

Merci d'avance pour votre aide
Configuration: Windows XP
Firefox 1.5.0.6

15 réponses

  1. Contributeur sécurité
    mets a jour java:

    https://www.java.com/fr/

    puis supprime l'ancienne version dans ajout/suppression de programme

    _____________

    dans démarrer puis PANNEAU DE CONFIGURATION puis AJOUT SUPPRESSION DE PROGRAMME

    cherche quelque chose comme CID et msn plus et desinstalle les
    si tu doit réinstaller msn plus fait le sans les sponsor surtout

    _____________

    si ca persiste:

    télécharger sur le bureau
    Navilog.zip
    http://perso.orange.fr/il.mafioso/Navifix/Navilog1.exe

    = Double-Clic navilog1.zip
    = Extraire tout sur le bureau
    = Double-Clic navilog1 qui est sur le bureau
    = Appuyer sur une touche jusqu' arriver aux options
    = Choisir option 1

    un rapport : fixnavi.txt dans C : va se creer
    le copier/coller dans ton prochain message.
    0
    1. salut jlpjlp

      j'ai supprimé et réinstallé la nouvelle version de java et j'ai supprimé msn plus , par contre je n'ai rien trouvé ressemblant à CID...
      le problème est toujours présent

      voici le rapport de navilog

      [+] Initializing ...
      [+] Starting scan, press Ctrl-C to abort.
      [+] Scanning for hidden items ..................................................................................
      [+] Scan complete.
      [+] Summary: 0 hidden item(s) found, 0 scheduled for renaming.
      [+] Exited on 09/11/07 at 08:41:01 (return code = 0).

      *** Recherche avec GenericNaviSearch ***
      !!! Tous Ces résultats peuvent révéler des fichiers légitimes !!!
      !!! A verifier impérativement avant toute suppression manuelle !!!

      * Scan C:\WINDOWS\system32 *

      Fichiers trouvés :

      Aucun Fichier trouvé !

      Fichiers suspects :

      Aucun Fichier suspect trouvé !

      *** Recherche fichiers ***

      *** Recherche cles registre ***

      *** Module de Recherche complémentaire ***
      (Recherche fichiers spécifiques)

      1)Recherche fichiers connus:

      2)Recherche Heuristique :
      *

      3)Recherche Certificats :

      Certificat Egroup absent !

      *** Analyse Terminé le 11/09/2007 à 8:41:16,28 ***
      0
      1. Contributeur sécurité
        smit fraud fix

        http://telechargement.zebulon.fr/smitfraudfix.html

        2/ double clique sur smitfraudfix. puis sélectionne 1 et appuyer sur entrée afin de créer le rapport des infection présentes. une fois le rapport effectué redémarre en mode sans échec (en appuyant sur F8 ou suppr, ou F5 au démarrage en général)

        3/ puis refaire comme en 2/ mais selectionne l'option 2 et appuyer sur entrée pour commencer la desinfection. lorsque le programme demande si tu veut nettoyer le registre metsoui en tapant 0 et entrée

        _______________

        AVG antispyxare

        https://www.01net.com/telecharger/

        Tuto :
        http://www.kachouri.com/tuto/tuto-161-avg-anti-spyware-75-pour-votre-securite.html

        ->Relance AVG AS -> "Analyse" ->"Paramètres"

        Sous la question "Comment réagir ?" :

        -> clique sur "Actions recommandées" et choisis "Quarantaines"
        -> Re-clique sur l'onglet "Analyse" puis réalise une "Analyse complète du système"

        Si un fichier est infecté en fin d'analyse

        ->Clique sur "Appliquer toutes les actions "

        ->Clique sur "Enregistrer le rapport" puis sur "Enregistrer le rapport sous".

        ->Enregistre ce fichier texte sur ton bureau ensuite colle le rapport ici

        ______________

        AD AWARE:
        https://www.01net.com/telecharger/windows/Securite/anti-spyware/fiches/11643.html

        _______________
        colle le rapport d'un scan en ligne
        avec un des suivants:

        bitdefender en ligne :
        http://www.bitdefender.fr/scan_fr/scan8/ie.html

        Panda en ligne :
        http://pandasoftware.fr

        scan en ligne firefox

        https://www.trendmicro.com/fr_fr/business.html
        0
        1. Bbonjour,
          voilà j'ai un souci avec mon pc, j'ai norton antivirus qui est constament en train de m'avertir d'une tentative d'intrusion
          Intrusion: HTTP LOP Toolbar Activity
          niveau de risque : élevé
          IP attaqué : ads.dns-look-up.com(64.34.228.126,80)

          J'ai windows XP SP2 édition familliale
          j'ai téléchargé HiJackThis et voici le rapport:

          Logfile of HijackThis v1.99.1
          Scan saved at 22:49:58, on 01/10/2007
          Platform: Windows XP SP2 (WinNT 5.01.2600)
          MSIE: Internet Explorer v7.00 (7.00.6000.16512)

          Running processes:
          C:\WINDOWS\System32\smss.exe
          C:\WINDOWS\system32\winlogon.exe
          C:\WINDOWS\system32\services.exe
          C:\WINDOWS\system32\lsass.exe
          C:\WINDOWS\system32\Ati2evxx.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          c:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe
          C:\WINDOWS\system32\Ati2evxx.exe
          C:\WINDOWS\Explorer.EXE
          C:\Program Files\Fichiers communs\Symantec Shared\AppCore\AppSvc32.exe
          C:\WINDOWS\system32\spoolsv.exe
          C:\WINDOWS\system32\drivers\CDAC11BA.EXE
          C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
          C:\WINDOWS\system32\svchost.exe
          C:\windows\system\hpsysdrv.exe
          C:\WINDOWS\system32\hphmon06.exe
          C:\HP\KBD\KBD.EXE
          C:\WINDOWS\system32\keyhook.exe
          C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe
          C:\WINDOWS\AGRSMMSG.exe
          C:\WINDOWS\SOUNDMAN.EXE
          C:\WINDOWS\ALCWZRD.EXE
          C:\WINDOWS\ALCMTR.EXE
          C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
          C:\Program Files\Fichiers communs\Logitech\QCDriver2\LVCOMS.EXE
          C:\Program Files\QuickTime\qttask.exe
          C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I0P1.EXE
          C:\Program Files\Fichiers communs\Ahead\lib\NMBgMonitor.exe
          C:\Program Files\Internet Explorer\IEXPLORE.EXE
          C:\WINDOWS\system32\ctfmon.exe
          C:\Program Files\modem ADSL USB\modem ADSL USB\dslmon.exe
          C:\Program Files\NETGEAR\WG111T Configuration Utility\wlan111t.exe
          C:\Program Files\WinZip\WZQKPICK.EXE
          C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcsvc.exe
          C:\WINDOWS\System32\svchost.exe
          C:\Program Files\Internet Explorer\iexplore.exe
          C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
          C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
          C:\Program Files\CasinoEuro\CasinoEuroPoker.exe
          C:\Program Files\Internet Explorer\IEXPLORE.EXE
          C:\Program Files\Microsoft Office\Office\EXCEL.EXE
          C:\Documents and Settings\HP_Propriétaire\Bureau\blabla.exe

          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://neufportail.fr/
          R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = Grgory
          R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
          R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
          F3 - REG:win.ini: load=
          O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
          O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
          O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
          O3 - Toolbar: Vue HP - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\HP\Digital Imaging\bin\HPDTLK02.dll
          O3 - Toolbar: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
          O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
          O4 - HKLM\..\Run: [HPHUPD06] c:\Program Files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06.exe
          O4 - HKLM\..\Run: [HPHmon06] C:\WINDOWS\system32\hphmon06.exe
          O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
          O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
          O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
          O4 - HKLM\..\Run: [SiS Windows KeyHook] C:\WINDOWS\system32\keyhook.exe
          O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe"
          O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
          O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
          O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
          O4 - HKLM\..\Run: [AlcWzrd] ALCWZRD.EXE
          O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
          O4 - HKLM\..\Run: [adiras] adiras.exe
          O4 - HKLM\..\Run: [hpppta] C:\Program Files\Hewlett-Packard\HP PrecisionScan\PrecisionScan\hpppta.exe /ICON
          O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
          O4 - HKLM\..\Run: [LVCOMS] C:\Program Files\Fichiers communs\Logitech\QCDriver2\LVCOMS.EXE
          O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
          O4 - HKLM\..\Run: [EPSON PictureMate] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I0P1.EXE /P17 "EPSON PictureMate" /O6 "USB001" /M "PictureMate"
          O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
          O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Fichiers communs\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Fichiers communs\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
          O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
          O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
          O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton AntiVirus\osCheck.exe"
          O4 - HKLM\..\Run: [bend logo clock film] C:\Documents and Settings\All Users\Application Data\Frag great bend logo\New Pop.exe
          O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
          O4 - HKCU\..\Run: [MediaDICO4Ut] C:\Program Files\Micro Application\Les 4 Dictionnaires Utiles\LanceMediaDICO4Ut.exe Lancement
          O4 - HKCU\..\Run: [EPSON PictureMate] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I0P1.EXE /P17 "EPSON PictureMate" /M "PictureMate" /EF "HKCU"
          O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Ahead\lib\NMBgMonitor.exe"
          O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
          O4 - Global Startup: DSLMON.lnk = ?
          O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
          O4 - Global Startup: NETGEAR WG111T Smart Wizard.lnk = ?
          O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
          O8 - Extra context menu item: &Search - http://kx.bar.need2find.com/KX/menusearch.html?p=KX
          O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
          O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
          O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
          O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
          O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
          O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
          O11 - Options group: [INTERNATIONAL] International*
          O16 - DPF: fdjeux - https://www.fdjeux.net/classes/fdjeux.cab
          O16 - DPF: {1DA3C4AB-E6B6-47A6-B0F3-1BD81524B51B} (ActiveWorldsDownload Control) - http://objects.activeworlds.com/AXTest/ActiveWorldsDownload.cab
          O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
          O16 - DPF: {45A0A292-ECC6-4D8F-9EA9-A4BD411D24C1} (king.com) - http://fr.midas.games.yahoo.net/ctl/kingcomie.cab
          O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} (Symantec Download Manager) - https://webdl.symantec.com/activex/symdlmgr.cab
          O16 - DPF: {CE69F98F-2AF3-4306-BAC6-A79070EDA1B4} (Zylom Loader Object) - http://eu.download.games.yahoo.com/zylom/activex/zylomloader.cab
          O16 - DPF: {F7EDBBEA-1AD2-4EBF-AA07-D453CC29EE65} (Flash Casino Helper Object) - https://casinoclassic.microgaming.com/casinoclassic/FlashAX2.cab
          O16 - DPF: {FB90BA05-66E6-4C56-BCD3-D65B0F7EBA39} (Foto.com SpeedUploader 1.0 Control) - http://fotogoodies.foto.com/activex/SpeedUploader.cab
          O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
          O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
          O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
          O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
          O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
          O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
          O23 - Service: Boonty Games - BOONTY - C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe
          O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\system32\drivers\CDAC11BA.EXE
          O23 - Service: Symantec Event Manager (ccEvtMgr) - Unknown owner - c:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
          O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - c:\Program Files\Fichiers communs\Symantec Shared\ccPwdSvc.exe
          O23 - Service: Symantec Settings Manager (ccSetMgr) - Unknown owner - c:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
          O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - c:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
          O23 - Service: Firebird Server - MAGIX Instance (FirebirdServerMAGIXInstance) - MAGIX® - C:\MAGIX\Common\Database\bin\fbserver.exe
          O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
          O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
          O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\isPwdSvc.exe
          O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
          O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Unknown owner - c:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
          O23 - Service: LiveUpdate Notice Service - Unknown owner - C:\Program Files\Fichiers communs\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /m "C:\Program Files\Fichiers communs\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PifEng.dll (file missing)
          O23 - Service: Planificateur LiveUpdate automatique - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
          O23 - Service: Spyware Doctor Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
          O23 - Service: Spyware Doctor Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe
          O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcsvc.exe
          O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\AppCore\AppSvc32.exe

          Comment puis je supprimer ces messages ??

          Que faire,

          Merci de votre aide
          0
          1. Contributeur sécurité
            dans démarrer puis PANNEAU DE CONFIGURATION puis AJOUT SUPPRESSION DE PROGRAMME

            cherche quelque chose comme CID et msn plus et desinstalle les
            si tu doit réinstaller msn plus fait le sans les sponsor surtout

            _____________

            AVG antispyxare

            https://www.01net.com/

            Tuto :
            http://www.kachouri.com/tuto/tuto-161-avg-anti-spyware-75-pour-votre-securite.html

            ->Relance AVG AS -> "Analyse" ->"Paramètres"

            Sous la question "Comment réagir ?" :

            -> clique sur "Actions recommandées" et choisis "Quarantaines"
            -> Re-clique sur l'onglet "Analyse" puis réalise une "Analyse complète du système"

            Si un fichier est infecté en fin d'analyse

            ->Clique sur "Appliquer toutes les actions "

            ->Clique sur "Enregistrer le rapport" puis sur "Enregistrer le rapport sous".

            ->Enregistre ce fichier texte sur ton bureau ensuite colle le rapport ici

            ______________

            AD AWARE:
            https://www.01net.com/telecharger/windows/Securite/anti-spyware/fiches/11643.html

            _______________
            colle le rapport d'un scan en ligne
            avec un des suivants:

            bitdefender en ligne :
            http://www.bitdefender.fr/scan_fr/scan8/ie.html

            Panda en ligne :
            http://pandasoftware.fr

            scan en ligne firefox

            https://www.trendmicro.com/fr_fr/business.html
            _____________

            télécharger sur le bureau
            Navilog.zip
            http://perso.orange.fr/il.mafioso/Navifix/Navilog1.exe

            = Double-Clic navilog1.zip
            = Extraire tout sur le bureau
            = Double-Clic navilog1 qui est sur le bureau
            = Appuyer sur une touche jusqu' arriver aux options
            = Choisir option 1

            un rapport : fixnavi.txt dans C : va se creer
            le copier/coller dans ton prochain message.

            ______________
            recolle aussi un rapport hijackthis et dis tes pbs
            0
            1. Bonjour,
              Je suis oi aussi victime des CID et Norton me signale HTTP LOP Toolbar Activity à un rique élevé..
              Je ne m'y connai pas en informatique c'est pour cela que je vous demande votre aide.
              Merci d'avance
              0
              1. Bonsoir moi ossi j'ai un souci avec HTTP LOP Toolbar activity je c'est pas trop comment m'y prendre si quelqu'un pouvait me guider je vous en remercie d'avance!! ...
                0
                1. Contributeur sécurité
                  créé ton propre message

                  merci
                  0
                  1. Contributeur sécurité
                    bon ok je suis généreux:

                    tu télécharge Lop S&D.exe sur ton Bureau.https://77b4795d-a-62cb3a1a-s-sites.googlegroups.com/site/eric71mespages/LopSD.exe?attachauth=ANoY7co3ntqUavpZ3q1BG-h4pc13vqDZmhcNeEPChtsyrgAykRbhE8bZzhk979EfQD4AgwtQUHCaQ7ZQwNYMo3_0kA8htAspckDJtu2K5t6J9z6dLW4fpZyH4FpFL1tVMBZ8H-KnN7afZ5vt-WxZRpnynk-a0XmV_Y0C0q6DxGEDKie1TnPT7gFoZnoCnspzBmbW6ZzxA4fNr3oEDlbelNZON-LjF8nOmQ%3D%3D&attredirects=2

                    * Double-clique dessus pour lancer l'installation
                    * Puis double-clique sur le raccourci Lop S&D présent sur ton Bureau
                    * Séléctionne la langue souhaitée , puis choisis l'option 1 (Recherche)
                    * Patiente jusqu'à la fin du scan
                    * Poste le rapport généré (C:\lopR.txt)
                    0
                    1. VOICI LE RAPPORT

                      --------------------\\ Lop S&D 4.2.5-0 XP/Vista

                      Microsoft® Windows Vista™ Édition Familiale Premium ( v6.0.6002 ) Service Pack 2
                      X86-based PC ( Multiprocessor Free : Intel(R) Core(TM)2 Solo CPU U3500 @ 1.40GHz )
                      BIOS : Ver 1.000
                      USER : marokina ( Administrator )
                      BOOT : Normal boot
                      C:\ (Local Disk) - NTFS - Total:43 Go (Free:7 Go)
                      D:\ (Local Disk) - NTFS - Total:414 Go (Free:412 Go)

                      "C:\Lop SD" ( MAJ : 19-12-2008|23:40 )
                      Option : [1] ( 02/01/2010|22:02 )

                      [ UAC => 1 ]

                      --------------------\\ Listing des dossiers dans Local

                      [31/10/2009|20:37] C:\Users\marokina\AppData\Local\Adobe
                      [02/11/2009|21:10] C:\Users\marokina\AppData\Local\Apple
                      [29/11/2009|20:12] C:\Users\marokina\AppData\Local\Apple Computer
                      [30/10/2009|21:20] C:\Users\marokina\AppData\Local\Application Data
                      [31/10/2009|21:41] C:\Users\marokina\AppData\Local\Apps
                      [08/11/2009|23:20] C:\Users\marokina\AppData\Local\d3d9caps.dat
                      [18/12/2009|23:25] C:\Users\marokina\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
                      [31/10/2009|21:42] C:\Users\marokina\AppData\Local\Deployment
                      [05/12/2009|13:37] C:\Users\marokina\AppData\Local\GDIPFONTCACHEV1.DAT
                      [22/11/2009|19:41] C:\Users\marokina\AppData\Local\Google
                      [30/10/2009|21:20] C:\Users\marokina\AppData\Local\Historique
                      [02/01/2010|17:15] C:\Users\marokina\AppData\Local\IconCache.db
                      [01/01/2010|02:58] C:\Users\marokina\AppData\Local\Microsoft
                      [01/11/2009|14:56] C:\Users\marokina\AppData\Local\Microsoft Games
                      [13/11/2009|17:31] C:\Users\marokina\AppData\Local\Mozilla
                      [02/01/2010|22:01] C:\Users\marokina\AppData\Local\Temp
                      [30/10/2009|21:20] C:\Users\marokina\AppData\Local\Temporary Internet Files
                      [30/10/2009|21:41] C:\Users\marokina\AppData\Local\Toshiba
                      [01/11/2009|15:14] C:\Users\marokina\AppData\Local\VirtualStore

                      --------------------\\ Tâches planifiées dans C:\Windows\tasks

                      [02/01/2010 18:25][--a------] C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
                      [02/01/2010 21:45][--a------] C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
                      [01/01/2010 23:21][--ah-----] C:\Windows\tasks\User_Feed_Synchronization-{3F34FAE1-E45B-46E6-B966-AB39434AA72B}.job
                      [02/01/2010 21:54][--a------] C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-166636228-761668181-3398955113-1000UA.job
                      [01/01/2010 23:54][--a------] C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-166636228-761668181-3398955113-1000Core.job
                      [02/01/2010 21:45][--ah-----] C:\Windows\tasks\SA.DAT
                      [02/01/2010 18:48][--a------] C:\Windows\tasks\SCHEDLGU.TXT

                      --------------------\\ Listing des dossiers dans C:\ProgramData

                      [02/11/2009|21:17] C:\ProgramData\{755AC846-7372-4AC8-8550-C52491DAA8BD}
                      [19/11/2009|11:35] C:\ProgramData\Adobe
                      [02/11/2009|21:02] C:\ProgramData\Apple
                      [02/11/2009|21:15] C:\ProgramData\Apple Computer
                      [02/11/2006|14:02] C:\ProgramData\Application Data
                      [02/11/2006|14:02] C:\ProgramData\Desktop
                      [02/11/2006|14:02] C:\ProgramData\Documents
                      [12/11/2009|20:45] C:\ProgramData\Downloaded Installations
                      [02/11/2006|14:02] C:\ProgramData\Favorites
                      [24/12/2009|23:41] C:\ProgramData\MessengerDiscovery 2
                      [01/11/2009|14:15] C:\ProgramData\Microsoft
                      [14/12/2009|22:38] C:\ProgramData\Microsoft Help
                      [15/08/2008|22:54] C:\ProgramData\MSI_autolocker.ini
                      [01/01/2010|23:21] C:\ProgramData\MSI_CamPowSet.ini
                      [30/10/2009|21:57] C:\ProgramData\Norton
                      [22/02/2002|10:43] C:\ProgramData\NortonInstaller
                      [02/01/2010|00:00] C:\ProgramData\ntuser.pol
                      [15/12/2009|15:16] C:\ProgramData\Sixth media send
                      [02/11/2006|14:02] C:\ProgramData\Start Menu
                      [30/10/2009|21:58] C:\ProgramData\Symantec
                      [02/11/2006|14:02] C:\ProgramData\Templates
                      [21/02/2002|22:49] C:\ProgramData\TOSHIBA
                      [30/10/2009|21:36] C:\ProgramData\Ulead Systems
                      [30/10/2009|21:35] C:\ProgramData\WindowsSearch
                      [24/12/2009|23:46] C:\ProgramData\Zwunzi

                      --------------------\\ Listing des dossiers dans C:\Program Files

                      [17/11/2009|18:47] C:\Program Files\Adobe
                      [01/01/2010|21:11] C:\Program Files\Ad-Remover
                      [02/11/2009|21:10] C:\Program Files\Apple Software Update
                      [02/11/2009|21:13] C:\Program Files\Bonjour
                      [02/11/2009|21:02] C:\Program Files\Common Files
                      [19/12/2009|17:11] C:\Program Files\Google
                      [30/10/2009|21:37] C:\Program Files\InstallShield Installation Information
                      [22/02/2002|01:08] C:\Program Files\Intel
                      [01/01/2010|16:45] C:\Program Files\Internet Explorer
                      [02/11/2009|21:15] C:\Program Files\iPod
                      [02/11/2009|21:17] C:\Program Files\iTunes
                      [02/01/2010|00:34] C:\Program Files\Java
                      [02/11/2009|23:28] C:\Program Files\LimeWire
                      [24/12/2009|23:41] C:\Program Files\MessengerDiscovery 2
                      [30/10/2009|21:32] C:\Program Files\Microsoft
                      [02/11/2006|13:37] C:\Program Files\Microsoft Games
                      [30/10/2009|21:34] C:\Program Files\Microsoft Office
                      [22/02/2002|05:24] C:\Program Files\Microsoft Office Suite Activation Assistant
                      [01/11/2009|17:26] C:\Program Files\Microsoft Silverlight
                      [30/10/2009|21:30] C:\Program Files\Microsoft SQL Server Compact Edition
                      [30/10/2009|21:31] C:\Program Files\Microsoft Sync Framework
                      [03/11/2009|23:06] C:\Program Files\Microsoft Works
                      [22/02/2002|04:05] C:\Program Files\Microsoft.NET
                      [01/01/2010|16:45] C:\Program Files\Movie Maker
                      [22/12/2009|14:58] C:\Program Files\Mozilla Firefox
                      [02/11/2006|13:37] C:\Program Files\MSBuild
                      [22/02/2002|05:59] C:\Program Files\MSI
                      [01/11/2009|14:08] C:\Program Files\MSXML 4.0
                      [22/02/2002|10:45] C:\Program Files\Norton Internet Security
                      [22/02/2002|10:43] C:\Program Files\NortonInstaller
                      [02/12/2009|00:08] C:\Program Files\OpenOffice.org 3
                      [02/11/2009|21:13] C:\Program Files\QuickTime
                      [30/10/2009|21:23] C:\Program Files\Reallusion
                      [21/02/2002|00:05] C:\Program Files\Realtek
                      [02/11/2006|13:37] C:\Program Files\Reference Assemblies
                      [01/11/2009|14:34] C:\Program Files\Symantec
                      [22/02/2002|10:20] C:\Program Files\System Control Manager
                      [21/02/2002|00:09] C:\Program Files\Temp
                      [21/02/2002|01:20] C:\Program Files\Toshiba
                      [30/10/2009|21:36] C:\Program Files\Ulead Systems
                      [02/11/2006|14:01] C:\Program Files\Uninstall Information
                      [01/01/2010|16:45] C:\Program Files\Windows Calendar
                      [01/01/2010|16:45] C:\Program Files\Windows Collaboration
                      [01/01/2010|16:45] C:\Program Files\Windows Defender
                      [01/01/2010|16:45] C:\Program Files\Windows Journal
                      [15/11/2009|14:58] C:\Program Files\Windows Live
                      [30/10/2009|21:27] C:\Program Files\Windows Live SkyDrive
                      [01/01/2010|16:45] C:\Program Files\Windows Mail
                      [01/01/2010|16:45] C:\Program Files\Windows Media Player
                      [02/11/2006|13:37] C:\Program Files\Windows NT
                      [01/01/2010|16:45] C:\Program Files\Windows Photo Gallery
                      [02/01/2010|17:16] C:\Program Files\Windows Portable Devices
                      [01/01/2010|16:45] C:\Program Files\Windows Sidebar
                      [22/02/2002|03:49] C:\Program Files\WinRAR 3.61 Multi
                      [24/12/2009|23:46] C:\Program Files\Zwunzi

                      --------------------\\ Listing des dossiers dans C:\Program Files\Common Files

                      [17/11/2009|18:48] C:\Program Files\Common Files\Adobe
                      [22/02/2002|03:28] C:\Program Files\Common Files\Adobe AIR
                      [02/11/2009|21:15] C:\Program Files\Common Files\Apple
                      [22/02/2002|04:06] C:\Program Files\Common Files\DESIGNER
                      [21/02/2002|00:05] C:\Program Files\Common Files\InstallShield
                      [03/11/2009|23:06] C:\Program Files\Common Files\microsoft shared
                      [30/10/2009|21:23] C:\Program Files\Common Files\Reallusion
                      [02/11/2006|12:18] C:\Program Files\Common Files\Services
                      [02/11/2006|12:18] C:\Program Files\Common Files\SpeechEngines
                      [31/10/2009|23:02] C:\Program Files\Common Files\Symantec Shared
                      [01/01/2010|16:45] C:\Program Files\Common Files\System
                      [30/10/2009|21:37] C:\Program Files\Common Files\Ulead Systems
                      [30/10/2009|21:26] C:\Program Files\Common Files\Windows Live

                      --------------------\\ Process

                      ( 75 Processes )

                      ... OK !

                      --------------------\\ Recherche avec S_Lop

                      Aucun fichier / dossier Lop trouvé !

                      --------------------\\ Recherche de Fichiers / Dossiers Lop

                      Aucun fichier / dossier Lop trouvé !

                      --------------------\\ Verification du Registre

                      ..... OK !

                      --------------------\\ Verification du fichier Hosts

                      Fichier Hosts PROPRE

                      --------------------\\ Recherche de fichiers avec Catchme

                      catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
                      Rootkit scan 2010-01-02 22:03:25
                      Windows 6.0.6002 Service Pack 2 NTFS
                      scanning hidden processes ...
                      scanning hidden files ...
                      scan completed successfully
                      hidden processes: 0
                      hidden files: 0

                      --------------------\\ Recherche d'autres infections

                      Aucune autre infection trouvée !

                      [F:24][D:61]-> C:\Users\marokina\AppData\Local\Temp
                      [F:26][D:1]-> C:\Users\marokina\AppData\Roaming\MICROS~1\Windows\Cookies
                      [F:116][D:4]-> C:\Users\marokina\AppData\Local\MICROS~1\Windows\TEMPOR~1\content.IE5
                      [F:3][D:1]-> C:\$Recycle.Bin

                      1 - "C:\Lop SD\LopR_1.txt" - 02/01/2010|15:47 - Option : [1]
                      2 - "C:\Lop SD\LopR_2.txt" - 02/01/2010|21:59 - Option : [2]
                      3 - "C:\Lop SD\LopR_3.txt" - 02/01/2010|22:06 - Option : [1]

                      --------------------\\ Fin du rapport a 22:06:01
                      [ UAC => 1 ]

                      0
                      1. Contributeur sécurité
                        Télécharge ici :

                        http://images.malwareremoval.com/random/RSIT.exe

                        random's system information tool (RSIT) par andom/random et sauvegarde-le sur le Bureau.

                        Double-clique sur RSIT.exe afin de lancer RSIT.

                        Clique Continue à l'écran Disclaimer.

                        Si l'outil HijackThis (version à jour) n'est pas présent ou non détecté sur l'ordinateur, RSIT le téléchargera (autorise l'accès dans ton pare-feu, si demandé) et tu devras accepter la licence.

                        Lorsque l'analyse sera terminée, deux fichiers texte s'ouvriront.

                        Poste le contenu de log.txt (<<qui sera affiché)
                        ainsi que de info.txt (<<qui sera réduit dans la Barre des Tâches).

                        NB : Les rapports sont sauvegardés dans le dossier C:\rsit
                        0
                        1. Voici le contenu de log.txt:

                          Logfile of random's system information tool 1.06 (written by random/random)
                          Run by marokina at 2010-01-03 19:20:12
                          Microsoft® Windows Vista™ Édition Familiale Premium Service Pack 2
                          System drive C: has 7 GB (16%) free of 45 GB
                          Total RAM: 2010 MB (37% free)

                          Logfile of Trend Micro HijackThis v2.0.2
                          Scan saved at 19:21:45, on 03/01/2010
                          Platform: Windows Vista SP2 (WinNT 6.00.1906)
                          MSIE: Internet Explorer v8.00 (8.00.6001.18865)
                          Boot mode: Normal

                          Running processes:
                          C:\Windows\system32\Dwm.exe
                          C:\Windows\system32\taskeng.exe
                          C:\Windows\Explorer.EXE
                          C:\Program Files\Windows Defender\MSASCui.exe
                          C:\Windows\System32\igfxtray.exe
                          C:\Windows\System32\hkcmd.exe
                          C:\Windows\System32\igfxpers.exe
                          C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
                          C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
                          C:\Program Files\MSI\EasyFace Logon\KillAutoAP.exe
                          C:\Program Files\System Control Manager\MGSysCtrl.exe
                          C:\Program Files\Norton Internet Security\Engine\16.7.2.11\ccSvcHst.exe
                          C:\Program Files\iTunes\iTunesHelper.exe
                          C:\Windows\system32\igfxsrvc.exe
                          C:\Program Files\Java\jre6\bin\jusched.exe
                          C:\Program Files\Windows Media Player\wmpnscfg.exe
                          C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
                          C:\Windows\system32\wbem\unsecapp.exe
                          C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
                          C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe
                          C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe
                          C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                          C:\Program Files\MessengerDiscovery 2\MessengerDiscovery 2.exe
                          C:\Windows\system32\conime.exe
                          C:\Program Files\Windows Live\Contacts\wlcomm.exe
                          C:\Users\marokina\AppData\Local\Google\Chrome\Application\chrome.exe
                          C:\Users\marokina\AppData\Local\Google\Chrome\Application\chrome.exe
                          C:\Users\marokina\AppData\Local\Google\Chrome\Application\chrome.exe
                          C:\Users\marokina\AppData\Local\Google\Chrome\Application\chrome.exe
                          C:\Users\marokina\Documents\Downloads\RSIT.exe
                          C:\Program Files\trend micro\marokina.exe

                          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
                          R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
                          R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
                          R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
                          R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
                          R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                          O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
                          O2 - BHO: Windows Live OneCare Family Safety Browser Helper - {4f3ed5cd-0726-42a9-87f5-d13f3d2976ac} - C:\Program Files\Windows Live\Family Safety\fssbho.dll
                          O2 - BHO: Symantec NCO BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton Internet Security\Engine\16.7.2.11\coIEPlg.dll
                          O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton Internet Security\Engine\16.7.2.11\IPSBHO.DLL
                          O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
                          O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                          O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
                          O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
                          O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Internet Security\Engine\16.7.2.11\coIEPlg.dll
                          O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
                          O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
                          O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
                          O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
                          O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
                          O4 - HKLM\..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
                          O4 - HKLM\..\Run: [ITSecMng] %ProgramFiles%\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe /START
                          O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
                          O4 - HKLM\..\Run: [AutoLocker] C:\Program Files\MSI\EasyFace Logon\KillAutoAP.exe
                          O4 - HKLM\..\Run: [MGSysCtrl] C:\Program Files\System Control Manager\MGSysCtrl.exe
                          O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
                          O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
                          O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
                          O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
                          O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
                          O4 - HKCU\..\Run: [Google Update] "C:\Users\marokina\AppData\Local\Google\Update\GoogleUpdate.exe" /c
                          O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
                          O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
                          O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
                          O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
                          O4 - Startup: LimeWire On Startup.lnk = C:\Program Files\LimeWire\LimeWire.exe
                          O4 - Global Startup: Bluetooth Manager.lnk = ?
                          O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
                          O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
                          O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
                          O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
                          O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
                          O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
                          O13 - Gopher Prefix:
                          O18 - Protocol: symres - {AA1061FE-6C41-421F-9344-69640C9732AB} - C:\Program Files\Norton Internet Security\Engine\16.7.2.11\coIEPlg.dll
                          O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                          O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
                          O23 - Service: Service Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
                          O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
                          O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
                          O23 - Service: Micro Star SCM - Micro-Star Int'l Co., Ltd. - C:\Program Files\System Control Manager\MSIService.exe
                          O23 - Service: Norton Internet Security - Symantec Corporation - C:\Program Files\Norton Internet Security\Engine\16.7.2.11\ccSvcHst.exe
                          O23 - Service: TOSHIBA Bluetooth Service - TOSHIBA CORPORATION - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
                          O23 - Service: Zwunzi Service - Unknown owner - C:\ProgramData\Zwunzi\zwunzi133.exe
                          0
                          1. Voici le contenu info.txt:

                            info.txt logfile of random's system information tool 1.06 2010-01-03 19:21:50

                            ======Uninstall list======

                            Actualização do Microsoft Office Excel 2007 Help (KB963678)-->msiexec /package {90120000-0016-0816-0000-0000000FF1CE} /uninstall {CCDE3C71-5F35-477F-BA90-1A399C91C10C}
                            Actualização do Microsoft Office Powerpoint 2007 Help (KB963669)-->msiexec /package {90120000-0018-0816-0000-0000000FF1CE} /uninstall {CF0BC77F-1B63-44BF-BCFE-3A8CBB9077D1}
                            Actualização do Microsoft Office Word 2007 Help (KB963665)-->msiexec /package {90120000-001B-0816-0000-0000000FF1CE} /uninstall {A1A8C49E-BB40-4852-853E-B5A1F6BB2A3C}
                            Adobe AIR-->c:\Program Files\Common Files\Adobe AIR\Versions\1.0\Resources\Adobe AIR Updater.exe -arp:uninstall
                            Adobe AIR-->MsiExec.exe /I{A2BCA9F1-566C-4805-97D1-7FDC93386723}
                            Adobe Flash Player 10 Plugin-->C:\Windows\system32\Macromed\Flash\uninstall_plugin.exe
                            Adobe Flash Player 9 ActiveX-->C:\Windows\system32\Macromed\Flash\FlashUtil9b.exe -uninstallDelete
                            Adobe Reader 9.2-->MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A92000000001}
                            Ad-Remover By C_XX-->"C:\Program Files\Ad-Remover\Uninstall ADR.exe"
                            Apple Application Support-->MsiExec.exe /I{B607C354-CD79-4D22-86D1-92DC94153F42}
                            Apple Mobile Device Support-->MsiExec.exe /I{AADEA55D-C834-4BCB-98A3-4B8D1C18F4EE}
                            Apple Software Update-->MsiExec.exe /I{6956856F-B6B3-4BE0-BA0B-8F495BE32033}
                            Assistant de connexion Windows Live-->MsiExec.exe /I{D3116CC7-24DC-4CA3-9CE1-23FED836E9F2}
                            Bluetooth Stack for Windows by Toshiba-->MsiExec.exe /X{CEBB6BFB-D708-4F99-A633-BC2600E01EF6}
                            Bonjour-->MsiExec.exe /I{07287123-B8AC-41CE-8346-3D777245C35B}
                            BurnRecovery-->MsiExec.exe /I{2892E1B7-E24D-4CCB-B8A7-B63D4B66F89F}
                            CrazyTalk Cam Suite-->C:\Program Files\InstallShield Installation Information\{D1504C77-1B19-4AF0-8DEC-946666123B55}\setup.exe -runfromtemp -l0x040c -removeonly /remove
                            EasyFace Logon-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{0A960933-4D39-4495-A3F5-E5149943D761}\setup.exe" -l0x9 -removeonly
                            Galerie de photos Windows Live-->MsiExec.exe /X{B131E59D-202C-43C6-84C9-68F0C37541F1}
                            Google Update Helper-->MsiExec.exe /I{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}
                            Google Earth-->MsiExec.exe /X{C084BC61-E537-11DE-8616-005056806466}
                            HijackThis 2.0.2-->"C:\Program Files\trend micro\HijackThis.exe" /uninstall
                            Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)-->C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall /qb+ REBOOTPROMPT=""
                            Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)-->C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {A7EEA2F2-BFCD-4A54-A575-7B81A786E658} /qb+ REBOOTPROMPT=""
                            Installation Windows Live-->C:\Program Files\Windows Live\Installer\wlarp.exe
                            Installation Windows Live-->MsiExec.exe /I{46ABBC54-1872-4AA3-95E2-F2C063A63F31}
                            Intel(R) Graphics Media Accelerator Driver-->C:\Windows\system32\igxpun.exe -uninstall
                            Intel(R) TV Wizard-->C:\Windows\system32\TVWizudlg.exe -uninstall
                            Intel® Matrix Storage Manager-->C:\Program Files\Intel\Intel Matrix Storage Manager\Uninstall\imsmudlg.exe -uninstall
                            iTunes-->MsiExec.exe /I{D1A74FBB-CA8D-4CCA-9B89-BAAA436DB178}
                            Java(TM) 6 Update 17-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216017FF}
                            Junk Mail filter update-->MsiExec.exe /I{E2DFE069-083E-4631-9B6C-43C48E991DE5}
                            LimeWire 5.3.6-->"C:\Program Files\LimeWire\uninstall.exe"
                            MessengerDiscovery 2.1.79-->"C:\Program Files\MessengerDiscovery 2\unins000.exe"
                            Microsoft .NET Framework 3.5 Language Pack SP1 - fra-->MsiExec.exe /I{3E31821C-7917-367E-938E-E65FC413EA31}
                            Microsoft .NET Framework 3.5 SP1-->C:\Windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setup.exe
                            Microsoft .NET Framework 3.5 SP1-->MsiExec.exe /I{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}
                            Microsoft Choice Guard-->MsiExec.exe /X{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}
                            Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0016-0409-0000-0000000FF1CE} /uninstall {2FC4457D-409E-466F-861F-FB0CB796B53E}
                            Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0016-040C-0000-0000000FF1CE} /uninstall {AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
                            Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0016-0410-0000-0000000FF1CE} /uninstall {71CCE0F1-A3B4-49C9-A328-1DABE845E0C4}
                            Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0016-0816-0000-0000000FF1CE} /uninstall {C2EC91A8-CC39-45F7-9E46-62B85ADF9DF5}
                            Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0016-0C0A-0000-0000000FF1CE} /uninstall {91A7F72A-3273-4C1E-8BE0-BC9DD0D9345C}
                            Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0018-0409-0000-0000000FF1CE} /uninstall {2FC4457D-409E-466F-861F-FB0CB796B53E}
                            Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0018-040C-0000-0000000FF1CE} /uninstall {AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
                            Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0018-0410-0000-0000000FF1CE} /uninstall {71CCE0F1-A3B4-49C9-A328-1DABE845E0C4}
                            Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0018-0816-0000-0000000FF1CE} /uninstall {C2EC91A8-CC39-45F7-9E46-62B85ADF9DF5}
                            Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0018-0C0A-0000-0000000FF1CE} /uninstall {91A7F72A-3273-4C1E-8BE0-BC9DD0D9345C}
                            Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001B-0409-0000-0000000FF1CE} /uninstall {2FC4457D-409E-466F-861F-FB0CB796B53E}
                            Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001B-040C-0000-0000000FF1CE} /uninstall {AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
                            Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001B-0410-0000-0000000FF1CE} /uninstall {71CCE0F1-A3B4-49C9-A328-1DABE845E0C4}
                            Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001B-0816-0000-0000000FF1CE} /uninstall {C2EC91A8-CC39-45F7-9E46-62B85ADF9DF5}
                            Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001B-0C0A-0000-0000000FF1CE} /uninstall {91A7F72A-3273-4C1E-8BE0-BC9DD0D9345C}
                            Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-006E-0409-0000-0000000FF1CE} /uninstall {DE5A002D-8122-4278-A7EE-3121E7EA254E}
                            Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-006E-040C-0000-0000000FF1CE} /uninstall {B165D3C2-40AE-4D39-86F7-E5C87C4264C0}
                            Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-006E-0410-0000-0000000FF1CE} /uninstall {0A75DA12-55CB-4DE5-8B6A-74D97847204E}
                            Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-006E-0816-0000-0000000FF1CE} /uninstall {A8523DA4-5563-4F0E-BD9D-4E4CC3CF7239}
                            Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-006E-0C0A-0000-0000000FF1CE} /uninstall {6113C11D-BACA-4D8E-8002-03C8D06FD5E6}
                            Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-00A1-0409-0000-0000000FF1CE} /uninstall {2FC4457D-409E-466F-861F-FB0CB796B53E}
                            Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-00A1-040C-0000-0000000FF1CE} /uninstall {AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
                            Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-00A1-0410-0000-0000000FF1CE} /uninstall {71CCE0F1-A3B4-49C9-A328-1DABE845E0C4}
                            Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-00A1-0816-0000-0000000FF1CE} /uninstall {C2EC91A8-CC39-45F7-9E46-62B85ADF9DF5}
                            Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-00A1-0C0A-0000-0000000FF1CE} /uninstall {91A7F72A-3273-4C1E-8BE0-BC9DD0D9345C}
                            Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0115-0409-0000-0000000FF1CE} /uninstall {DE5A002D-8122-4278-A7EE-3121E7EA254E}
                            Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}
                            Microsoft Office Excel 2007 Help - Aggiornamento (KB963678)-->msiexec /package {90120000-0016-0410-0000-0000000FF1CE} /uninstall {9F57BDED-B51B-4D2F-B360-5B4EFAAF0F1A}
                            Microsoft Office Excel 2007 Help Actualización (KB963678)-->msiexec /package {90120000-0016-0C0A-0000-0000000FF1CE} /uninstall {59E09C3D-4878-47D9-87DB-6D0018026889}
                            Microsoft Office Excel MUI (English) 2007-->MsiExec.exe /X{90120000-0016-0409-0000-0000000FF1CE}
                            Microsoft Office Excel MUI (French) 2007-->MsiExec.exe /X{90120000-0016-040C-0000-0000000FF1CE}
                            Microsoft Office Excel MUI (Italian) 2007-->MsiExec.exe /X{90120000-0016-0410-0000-0000000FF1CE}
                            Microsoft Office Excel MUI (Portuguese (Portugal)) 2007-->MsiExec.exe /X{90120000-0016-0816-0000-0000000FF1CE}
                            Microsoft Office Excel MUI (Spanish) 2007-->MsiExec.exe /X{90120000-0016-0C0A-0000-0000000FF1CE}
                            Microsoft Office Home and Student 2007-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE12\Office Setup Controller\setup.exe" /uninstall HOMESTUDENTR /dll OSETUP.DLL
                            Microsoft Office Home and Student 2007-->MsiExec.exe /X{91120000-002F-0000-0000-0000000FF1CE}
                            Microsoft Office Live Add-in 1.3-->MsiExec.exe /I{57F0ED40-8F11-41AA-B926-4A66D0D1A9CC}
                            Microsoft Office OneNote MUI (English) 2007-->MsiExec.exe /X{90120000-00A1-0409-0000-0000000FF1CE}
                            Microsoft Office OneNote MUI (French) 2007-->MsiExec.exe /X{90120000-00A1-040C-0000-0000000FF1CE}
                            Microsoft Office OneNote MUI (Italian) 2007-->MsiExec.exe /X{90120000-00A1-0410-0000-0000000FF1CE}
                            Microsoft Office OneNote MUI (Portuguese (Portugal)) 2007-->MsiExec.exe /X{90120000-00A1-0816-0000-0000000FF1CE}
                            Microsoft Office OneNote MUI (Spanish) 2007-->MsiExec.exe /X{90120000-00A1-0C0A-0000-0000000FF1CE}
                            Microsoft Office Powerpoint 2007 Help - Aggiornamento (KB963669)-->msiexec /package {90120000-0018-0410-0000-0000000FF1CE} /uninstall {C76C02F1-B07F-4974-876A-A18DEC9887C8}
                            Microsoft Office Powerpoint 2007 Help Actualización (KB963669)-->msiexec /package {90120000-0018-0C0A-0000-0000000FF1CE} /uninstall {F318245D-05AE-4681-A749-A036CE44AF29}
                            Microsoft Office PowerPoint MUI (English) 2007-->MsiExec.exe /X{90120000-0018-0409-0000-0000000FF1CE}
                            Microsoft Office PowerPoint MUI (French) 2007-->MsiExec.exe /X{90120000-0018-040C-0000-0000000FF1CE}
                            Microsoft Office PowerPoint MUI (Italian) 2007-->MsiExec.exe /X{90120000-0018-0410-0000-0000000FF1CE}
                            Microsoft Office PowerPoint MUI (Portuguese (Portugal)) 2007-->MsiExec.exe /X{90120000-0018-0816-0000-0000000FF1CE}
                            Microsoft Office PowerPoint MUI (Spanish) 2007-->MsiExec.exe /X{90120000-0018-0C0A-0000-0000000FF1CE}
                            Microsoft Office Proof (Arabic) 2007-->MsiExec.exe /X{90120000-001F-0401-0000-0000000FF1CE}
                            Microsoft Office Proof (Basque) 2007-->MsiExec.exe /X{90120000-001F-042D-0000-0000000FF1CE}
                            Microsoft Office Proof (Catalan) 2007-->MsiExec.exe /X{90120000-001F-0403-0000-0000000FF1CE}
                            Microsoft Office Proof (Dutch) 2007-->MsiExec.exe /X{90120000-001F-0413-0000-0000000FF1CE}
                            Microsoft Office Proof (English) 2007-->MsiExec.exe /X{90120000-001F-0409-0000-0000000FF1CE}
                            Microsoft Office Proof (French) 2007-->MsiExec.exe /X{90120000-001F-040C-0000-0000000FF1CE}
                            Microsoft Office Proof (Galician) 2007-->MsiExec.exe /X{90120000-001F-0456-0000-0000000FF1CE}
                            Microsoft Office Proof (German) 2007-->MsiExec.exe /X{90120000-001F-0407-0000-0000000FF1CE}
                            Microsoft Office Proof (Italian) 2007-->MsiExec.exe /X{90120000-001F-0410-0000-0000000FF1CE}
                            Microsoft Office Proof (Portuguese (Brazil)) 2007-->MsiExec.exe /X{90120000-001F-0416-0000-0000000FF1CE}
                            Microsoft Office Proof (Portuguese (Portugal)) 2007-->MsiExec.exe /X{90120000-001F-0816-0000-0000000FF1CE}
                            Microsoft Office Proof (Spanish) 2007-->MsiExec.exe /X{90120000-001F-0C0A-0000-0000000FF1CE}
                            Microsoft Office Proofing (English) 2007-->MsiExec.exe /X{90120000-002C-0409-0000-0000000FF1CE}
                            Microsoft Office Proofing (French) 2007-->MsiExec.exe /X{90120000-002C-040C-0000-0000000FF1CE}
                            Microsoft Office Proofing (Italian) 2007-->MsiExec.exe /X{90120000-002C-0410-0000-0000000FF1CE}
                            Microsoft Office Proofing (Portuguese (Portugal)) 2007-->MsiExec.exe /X{90120000-002C-0816-0000-0000000FF1CE}
                            Microsoft Office Proofing (Spanish) 2007-->MsiExec.exe /X{90120000-002C-0C0A-0000-0000000FF1CE}
                            Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0401-0000-0000000FF1CE} /uninstall {14809F99-C601-4D4A-9391-F1E8FAA964C5}
                            Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0403-0000-0000000FF1CE} /uninstall {4B47C31E-46B0-462B-BEE4-DC383B6A1F2A}
                            Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0407-0000-0000000FF1CE} /uninstall {A0516415-ED61-419A-981D-93596DA74165}
                            Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0409-0000-0000000FF1CE} /uninstall {ABDDE972-355B-4AF1-89A8-DA50B7B5C045}
                            Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-040C-0000-0000000FF1CE} /uninstall {F580DDD5-8D37-4998-968E-EBB76BB86787}
                            Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0410-0000-0000000FF1CE} /uninstall {322296D4-1EAE-4030-9FBC-D2787EB25FA2}
                            Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0413-0000-0000000FF1CE} /uninstall {D66D5A44-E480-4BA4-B4F2-C554F6B30EBB}
                            Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0416-0000-0000000FF1CE} /uninstall {75EBE365-7FC5-4720-A7D3-804BF550D1BC}
                            Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0816-0000-0000000FF1CE} /uninstall {C312E1CD-EC19-4270-A072-F36F634DFF79}
                            Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0C0A-0000-0000000FF1CE} /uninstall {187308AB-5FA7-4F14-9AB9-D290383A10D9}
                            Microsoft Office Shared MUI (English) 2007-->MsiExec.exe /X{90120000-006E-0409-0000-0000000FF1CE}
                            Microsoft Office Shared MUI (French) 2007-->MsiExec.exe /X{90120000-006E-040C-0000-0000000FF1CE}
                            Microsoft Office Shared MUI (Italian) 2007-->MsiExec.exe /X{90120000-006E-0410-0000-0000000FF1CE}
                            Microsoft Office Shared MUI (Portuguese (Portugal)) 2007-->MsiExec.exe /X{90120000-006E-0816-0000-0000000FF1CE}
                            Microsoft Office Shared MUI (Spanish) 2007-->MsiExec.exe /X{90120000-006E-0C0A-0000-0000000FF1CE}
                            Microsoft Office Shared Setup Metadata MUI (English) 2007-->MsiExec.exe /X{90120000-0115-0409-0000-0000000FF1CE}
                            Microsoft Office Suite Activation Assistant-->MsiExec.exe /X{E50AE784-FABE-46DA-A1F8-7B6B56DCB22E}
                            Microsoft Office Word 2007 Help - Aggiornamento (KB963665)-->msiexec /package {90120000-001B-0410-0000-0000000FF1CE} /uninstall {E5B82DB3-DD7D-4C45-BC5E-09864B26F9BC}
                            Microsoft Office Word 2007 Help Actualización (KB963665)-->msiexec /package {90120000-001B-0C0A-0000-0000000FF1CE} /uninstall {377BA42A-1C84-45D6-94B8-6D00887D172D}
                            Microsoft Office Word MUI (English) 2007-->MsiExec.exe /X{90120000-001B-0409-0000-0000000FF1CE}
                            Microsoft Office Word MUI (French) 2007-->MsiExec.exe /X{90120000-001B-040C-0000-0000000FF1CE}
                            Microsoft Office Word MUI (Italian) 2007-->MsiExec.exe /X{90120000-001B-0410-0000-0000000FF1CE}
                            Microsoft Office Word MUI (Portuguese (Portugal)) 2007-->MsiExec.exe /X{90120000-001B-0816-0000-0000000FF1CE}
                            Microsoft Office Word MUI (Spanish) 2007-->MsiExec.exe /X{90120000-001B-0C0A-0000-0000000FF1CE}
                            Microsoft Search Enhancement Pack-->MsiExec.exe /X{4CBA3D4C-8F51-4D60-B27E-F6B641C571E7}
                            Microsoft Silverlight-->MsiExec.exe /X{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
                            Microsoft SQL Server 2005 Compact Edition [ENU]-->MsiExec.exe /I{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}
                            Microsoft Sync Framework Runtime Native v1.0 (x86)-->MsiExec.exe /I{8A74E887-8F0F-4017-AF53-CBA42211AAA5}
                            Microsoft Sync Framework Services Native v1.0 (x86)-->MsiExec.exe /I{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}
                            Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053-->MsiExec.exe /X{770657D0-A123-3C07-8E44-1C83EC895118}
                            Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
                            Microsoft Works-->MsiExec.exe /I{6B1CB38D-E2E4-4A30-933D-EFDEBA76AD9C}
                            Mise à jour Microsoft Office Excel 2007 Help (KB963678)-->msiexec /package {90120000-0016-040C-0000-0000000FF1CE} /uninstall {B761869A-B85C-40E2-994C-A1CE78AC8F2C}
                            Mise à jour Microsoft Office Powerpoint 2007 Help (KB963669)-->msiexec /package {90120000-0018-040C-0000-0000000FF1CE} /uninstall {C3DCA38E-005E-41BA-A52A-7C3429F351C3}
                            Mise à jour Microsoft Office Word 2007 Help (KB963665)-->msiexec /package {90120000-001B-040C-0000-0000000FF1CE} /uninstall {81536A04-DBFB-4DB3-978F-0F284590C223}
                            Module linguistique Microsoft .NET Framework 3.5 SP1- fra-->C:\Windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 Language Pack SP1 - fra\setup.exe
                            MSI Software Install-->MsiExec.exe /I{07690F1C-04B1-4060-9691-6748ED1826B9}
                            MSVCRT-->MsiExec.exe /I{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}
                            MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
                            MSXML 4.0 SP2 (KB973688)-->MsiExec.exe /I{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}
                            Norton Internet Security-->C:\Program Files\NortonInstaller\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS\A5E82D02\16.7.2.11\InstStub.exe /X
                            Norton Internet Security-->MsiExec.exe /I{7B15D70E-9449-4CFB-B9BC-798465B2BD5C}
                            OpenOffice.org 3.1-->MsiExec.exe /I{B2E581DB-C4DD-432C-AC84-ED761AC056BC}
                            Outil de téléchargement Windows Live-->MsiExec.exe /I{205C6BDD-7B73-42DE-8505-9A093F35A238}
                            QuickTime-->MsiExec.exe /I{A429C2AE-EBF1-4F81-A221-1C115CAADDAD}
                            Realtek 8169 8168 8101E 8102E Ethernet Driver-->C:\Program Files\InstallShield Installation Information\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}\setup.exe -runfromtemp -l0x0009 -removeonly
                            Realtek High Definition Audio Driver-->C:\Program Files\Realtek\Audio\HDA\RtlUpd.exe -r -m -nrg2709
                            Realtek USB 2.0 Card Reader-->C:\Program Files\InstallShield Installation Information\{DC24971E-1946-445D-8A82-CE685433FA7D}\setup.exe -runfromtemp -l0x0009 -removeonly
                            Security Update for 2007 Microsoft Office System (KB969559)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {69F52148-9BF6-4CDC-BF76-103DEAF3DD08}
                            Security Update for 2007 Microsoft Office System (KB973704)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {E626DC89-A787-4553-9BB3-DC2EC7E1593F}
                            Security Update for Microsoft Office Excel 2007 (KB973593)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {7D6255E3-3423-4D8B-A328-F6F8D28DD5FE}
                            Security Update for Microsoft Office PowerPoint 2007 (KB957789)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {7559E742-FF9F-4FAE-B279-008ED296CB4D}
                            Security Update for Microsoft Office system 2007 (972581)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {3D019598-7B59-447A-80AE-815B703B84FF}
                            Security Update for Microsoft Office system 2007 (KB969613)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {5ECEB317-CBE9-4E08-AB10-756CB6F0FB6C}
                            Security Update for Microsoft Office system 2007 (KB974234)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {FCD742B9-7A55-44BC-A776-F795F21FEDDC}
                            Security Update for Microsoft Office Visio Viewer 2007 (KB973709)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {71127777-8B2C-4F97-AF7A-6CF8CAC8224D}
                            System Control Manager-->C:\Program Files\InstallShield Installation Information\{ED9C5D25-55DF-48D8-9328-2AC0D75DE5D8}\setup.exe -runfromtemp -l0x0009 -removeonly
                            Ulead Burn.Now 4.5 SE-->C:\Program Files\InstallShield Installation Information\{A3BE3F1E-2472-4211-8735-E8239BE49D9F}\setup.exe -runfromtemp -l0x040c
                            Update for 2007 Microsoft Office System (KB967642)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {C444285D-5E4F-48A4-91DD-47AAAA68E92D}
                            Update for Microsoft .NET Framework 3.5 SP1 (KB963707)-->C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {B2AE9C82-DC7B-3641-BFC8-87275C4F3607} /qb+ REBOOTPROMPT=""
                            Update for Microsoft Office 2007 Help for Common Features (KB963673)-->msiexec /package {90120000-006E-0409-0000-0000000FF1CE} /uninstall {AB365889-0395-4FAD-B702-CA5985D53D42}
                            Update for Microsoft Office Excel 2007 Help (KB963678)-->msiexec /package {90120000-0016-0409-0000-0000000FF1CE} /uninstall {199DF7B6-169C-448C-B511-1054101BE9C9}
                            Update for Microsoft Office InfoPath 2007 (KB976416)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {432C5EE4-8096-4FF1-95E1-65219365DFF7}
                            Update for Microsoft Office OneNote 2007 Help (KB963670)-->msiexec /package {90120000-00A1-0409-0000-0000000FF1CE} /uninstall {2744EF05-38E1-4D5D-B333-E021EDAEA245}
                            Update for Microsoft Office Powerpoint 2007 Help (KB963669)-->msiexec /package {90120000-0018-0409-0000-0000000FF1CE} /uninstall {397B1D4F-ED7B-4ACA-A637-43B670843876}
                            Update for Microsoft Office Script Editor Help (KB963671)-->msiexec /package {90120000-006E-0409-0000-0000000FF1CE} /uninstall {CD11C6A2-FFC6-4271-8EAB-79C3582F505C}
                            Update for Microsoft Office Word 2007 (KB974561)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {0CDDBAA2-2111-4A0E-A1B0-76C40C635331}
                            Update for Microsoft Office Word 2007 Help (KB963665)-->msiexec /package {90120000-001B-0409-0000-0000000FF1CE} /uninstall {80E762AA-C921-4839-9D7D-DB62A72C0726}
                            Windows Live Call-->MsiExec.exe /I{82C7B308-0BDD-49D8-8EA5-9CD3A3F9DF41}
                            Windows Live Communications Platform-->MsiExec.exe /I{3B4E636E-9D65-4D67-BA61-189800823F52}
                            Windows Live Contrôle parental-->MsiExec.exe /X{D5D81435-B8DE-4CAF-867F-7998F2B92CFC}
                            Windows Live FolderShare-->MsiExec.exe /X{2075CB0A-D26F-4DAA-B424-5079296B43BA}
                            Windows Live Mail-->MsiExec.exe /I{5DD76286-9BE7-4894-A990-E905E91AC818}
                            Windows Live Messenger-->MsiExec.exe /X{770F1BEC-2871-4E70-B837-FB8525FFA3B1}
                            Windows Live Movie Maker-->MsiExec.exe /X{53B20C18-D8D4-4588-8737-9BBFE303C354}
                            Windows Live Toolbar-->MsiExec.exe /X{F7D27C70-90F5-49B9-B188-0A133C0CE353}
                            Windows Live Writer-->MsiExec.exe /X{4634B21A-CC07-4396-890C-2B8168661FEA}
                            WinRAR archiver-->C:\Program Files\WinRAR 3.61 Multi\Uninstall.exe
                            Zwunzi 1.0 build 133-->C:\Program Files\Zwunzi\uninstall.exe

                            ======Security center information======

                            AS: Windows Defender

                            ======System event log======

                            Computer Name: PC-de-marokina
                            Event Code: 4376
                            Message: Servicing a requis un redémarrage pour terminer la définition du package KB935509_2(Update) à l’état Permanent(Permanent)
                            Record Number: 28856
                            Source Name: Microsoft-Windows-Servicing
                            Time Written: 20091101165814.000000-000
                            Event Type: Avertissement
                            User: AUTORITE NT\SYSTEM

                            Computer Name: PC-de-marokina
                            Event Code: 4376
                            Message: Servicing a requis un redémarrage pour terminer la définition du package KB935509_1(Update) à l’état Permanent(Permanent)
                            Record Number: 28855
                            Source Name: Microsoft-Windows-Servicing
                            Time Written: 20091101165814.000000-000
                            Event Type: Avertissement
                            User: AUTORITE NT\SYSTEM

                            Computer Name: PC-de-marokina
                            Event Code: 4376
                            Message: Servicing a requis un redémarrage pour terminer la définition du package KB935509(Update) à l’état Permanent(Permanent)
                            Record Number: 28824
                            Source Name: Microsoft-Windows-Servicing
                            Time Written: 20091101165813.000000-000
                            Event Type: Avertissement
                            User: AUTORITE NT\SYSTEM

                            Computer Name: PC-de-marokina
                            Event Code: 4376
                            Message: Servicing a requis un redémarrage pour terminer la définition du package Language Pack(Language Pack) à l’état Désinstallation demandée(Uninstall Requested)
                            Record Number: 28822
                            Source Name: Microsoft-Windows-Servicing
                            Time Written: 20091101165813.000000-000
                            Event Type: Avertissement
                            User: AUTORITE NT\SYSTEM

                            Computer Name: PC-de-marokina
                            Event Code: 4376
                            Message: Servicing a requis un redémarrage pour terminer la définition du package Language Pack(Language Pack) à l’état Désinstallation demandée(Uninstall Requested)
                            Record Number: 28767
                            Source Name: Microsoft-Windows-Servicing
                            Time Written: 20091101165812.000000-000
                            Event Type: Avertissement
                            User: AUTORITE NT\SYSTEM

                            =====Application event log=====

                            Computer Name: PC-de-marokina
                            Event Code: 3086
                            Message: Les paramètres régionaux du système ont changé. Les données existantes vont être supprimées et l'index doit être recréé.

                            Contexte : Application , Catalogue SystemIndex

                            Record Number: 887
                            Source Name: Microsoft-Windows-Search
                            Time Written: 20091030202008.000000-000
                            Event Type: Avertissement
                            User:

                            Computer Name: PC-de-marokina
                            Event Code: 63
                            Message: Le fournisseur WmiPerfClass a été inscrit dans l’espace de noms Windows Management Instrumentation root\cimv2, afin d’utiliser le compte LocalSystem. Ce compte bénéficie de privilèges et le fournisseur peut provoquer une violation de sécurité s’il ne représente pas correctement les demandes utilisateur.
                            Record Number: 875
                            Source Name: Microsoft-Windows-WMI
                            Time Written: 20091030201645.000000-000
                            Event Type: Avertissement
                            User: AUTORITE NT\SYSTEM

                            Computer Name: PC-de-marokina
                            Event Code: 63
                            Message: Le fournisseur WmiPerfClass a été inscrit dans l’espace de noms Windows Management Instrumentation root\cimv2, afin d’utiliser le compte LocalSystem. Ce compte bénéficie de privilèges et le fournisseur peut provoquer une violation de sécurité s’il ne représente pas correctement les demandes utilisateur.
                            Record Number: 874
                            Source Name: Microsoft-Windows-WMI
                            Time Written: 20091030201645.000000-000
                            Event Type: Avertissement
                            User: AUTORITE NT\SYSTEM

                            Computer Name: PC-de-marokina
                            Event Code: 10
                            Message: Le filtre d’événement avec la requête « SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99 » n’a pas pu être réactivé dans l’espace de noms « //./root/CIMV2 » à cause de l’erreur 0x80041003. Les événements ne peuvent pas être délivrés à travers ce filtre tant que le problème ne sera pas corrigé.
                            Record Number: 863
                            Source Name: Microsoft-Windows-WMI
                            Time Written: 20091031122003.000000-000
                            Event Type: Erreur
                            User:

                            Computer Name: WIN-WZMJD8FMARN
                            Event Code: 1008
                            Message: Le service Windows Search tente de supprimer l’ancien catalogue.

                            Record Number: 847
                            Source Name: Microsoft-Windows-Search
                            Time Written: 20091031121448.000000-000
                            Event Type: Avertissement
                            User:

                            =====Security event log=====

                            Computer Name: WIN-WZMJD8FMARN
                            Event Code: 4648
                            Message: Tentative d’ouverture de session en utilisant des informations d’identification explicites.

                            Sujet :
                            ID de sécurité : S-1-5-18
                            Nom du compte : WIN-WZMJD8FMARN$
                            Domaine du compte : WORKGROUP
                            ID d’ouverture de session : 0x3e7
                            GUID d’ouverture de session : {00000000-0000-0000-0000-000000000000}

                            Compte dont les informations d’identification ont été utilisées :
                            Nom du compte : SYSTEM
                            Domaine du compte : NT AUTHORITY
                            GUID d’ouverture de session : {00000000-0000-0000-0000-000000000000}

                            Serveur cible :
                            Nom du serveur cible : localhost
                            Informations supplémentaires : localhost

                            Informations sur le processus :
                            ID du processus : 0x28c
                            Nom du processus : C:\Windows\System32\services.exe

                            Informations sur le réseau :
                            Adresse du réseau : -
                            Port : -

                            Cet événement est généré lorsqu’un processus tente d’ouvrir une session pour un compte en spécifiant explicitement les informations d’identification de ce compte. Ceci se produit le plus souvent dans les configurations par lot comme les tâches planifiées, ou avec l’utilisation de la commande RUNAS.
                            Record Number: 1232
                            Source Name: Microsoft-Windows-Security-Auditing
                            Time Written: 20020222100551.688582-000
                            Event Type: Succès de l'audit
                            User:

                            Computer Name: WIN-WZMJD8FMARN
                            Event Code: 4672
                            Message: Privilèges spéciaux attribués à la nouvelle ouverture de session.

                            Sujet :
                            ID de sécurité : S-1-5-18
                            Nom du compte : SYSTEM
                            Domaine du compte : NT AUTHORITY
                            ID d’ouverture de session : 0x3e7

                            Privilèges : SeAssignPrimaryTokenPrivilege
                            SeTcbPrivilege
                            SeSecurityPrivilege
                            SeTakeOwnershipPrivilege
                            SeLoadDriverPrivilege
                            SeBackupPrivilege
                            SeRestorePrivilege
                            SeDebugPrivilege
                            SeAuditPrivilege
                            SeSystemEnvironmentPrivilege
                            SeImpersonatePrivilege
                            Record Number: 1231
                            Source Name: Microsoft-Windows-Security-Auditing
                            Time Written: 20020222100551.376582-000
                            Event Type: Succès de l'audit
                            User:

                            Computer Name: WIN-WZMJD8FMARN
                            Event Code: 4624
                            Message: L’ouverture de session d’un compte s’est correctement déroulée.

                            Sujet :
                            ID de sécurité : S-1-5-18
                            Nom du compte : WIN-WZMJD8FMARN$
                            Domaine du compte : WORKGROUP
                            ID d’ouverture de session : 0x3e7

                            Type d’ouverture de session : 5

                            Nouvelle ouverture de session :
                            ID de sécurité : S-1-5-18
                            Nom du compte : SYSTEM
                            Domaine du compte : NT AUTHORITY
                            ID d’ouverture de session : 0x3e7
                            GUID d’ouverture de session : {00000000-0000-0000-0000-000000000000}

                            Informations sur le processus :
                            ID du processus : 0x28c
                            Nom du processus : C:\Windows\System32\services.exe

                            Informations sur le réseau :
                            Nom de la station de travail :
                            Adresse du réseau source : -
                            Port source : -

                            Informations détaillées sur l’authentification :
                            Processus d’ouverture de session : Advapi
                            Package d’authentification : Negotiate
                            Services en transit : -
                            Nom du package (NTLM uniquement) : -
                            Longueur de la clé : 0

                            Cet événement est généré lors de la création d’une ouverture de session. Il est généré sur l’ordinateur sur lequel l’ouverture de session a été effectuée.

                            Le champ Objet indique le compte sur le système local qui a demandé l’ouverture de session. Il s’agit le plus souvent d’un service, comme le service Serveur, ou un processus local tel que Winlogon.exe ou Services.exe.

                            Le champ Type d’ouverture de session indique le type d’ouverture de session qui s’est produit. Les types les plus courants sont 2 (interactif) et 3 (réseau).

                            Le champ Nouvelle ouverture de session indique le compte pour lequel la nouvelle ouverture de session a été créée, par exemple, le compte qui s’est connecté.

                            Les champs relatifs au réseau indiquent la provenance d’une demande d’ouverture de session à distance. Le nom de la station de travail n’étant pas toujours disponible, peut être laissé vide dans certains cas.

                            Les champs relatifs aux informations d’authentification fournissent des détails sur cette demande d’ouverture de session spécifique.
                            - Le GUID d’ouverture de session est un identificateur unique pouvant servir à associer cet événement à un événement KDC .
                            - Les services en transit indiquent les services intermédiaires qui ont participé à cette demande d’ouverture de session.
                            - Nom du package indique quel est le sous-protocole qui a été utilisé parmi les protocoles NTLM.
                            - La longueur de la clé indique la longueur de la clé de session générée. Elle a la valeur 0 si aucune clé de session n’a été demandée.
                            Record Number: 1230
                            Source Name: Microsoft-Windows-Security-Auditing
                            Time Written: 20020222100551.376582-000
                            Event Type: Succès de l'audit
                            User:

                            Computer Name: WIN-WZMJD8FMARN
                            Event Code: 4648
                            Message: Tentative d’ouverture de session en utilisant des informations d’identification explicites.

                            Sujet :
                            ID de sécurité : S-1-5-18
                            Nom du compte : WIN-WZMJD8FMARN$
                            Domaine du compte : WORKGROUP
                            ID d’ouverture de session : 0x3e7
                            GUID d’ouverture de session : {00000000-0000-0000-0000-000000000000}

                            Compte dont les informations d’identification ont été utilisées :
                            Nom du compte : SYSTEM
                            Domaine du compte : NT AUTHORITY
                            GUID d’ouverture de session : {00000000-0000-0000-0000-000000000000}

                            Serveur cible :
                            Nom du serveur cible : localhost
                            Informations supplémentaires : localhost

                            Informations sur le processus :
                            ID du processus : 0x28c
                            Nom du processus : C:\Windows\System32\services.exe

                            Informations sur le réseau :
                            Adresse du réseau : -
                            Port : -

                            Cet événement est généré lorsqu’un processus tente d’ouvrir une session pour un compte en spécifiant explicitement les informations d’identification de ce compte. Ceci se produit le plus souvent dans les configurations par lot comme les tâches planifiées, ou avec l’utilisation de la commande RUNAS.
                            Record Number: 1229
                            Source Name: Microsoft-Windows-Security-Auditing
                            Time Written: 20020222100551.376582-000
                            Event Type: Succès de l'audit
                            User:

                            Computer Name: WIN-WZMJD8FMARN
                            Event Code: 1102
                            Message: Le journal d’audit a été effacé.
                            Objet :
                            ID de sécurité : S-1-5-21-3546302732-4203108313-610080474-500
                            Nom de compte : Administrator
                            Nom de domaine : WIN-WZMJD8FMARN
                            ID de connexion : 0x2ded2
                            Record Number: 1228
                            Source Name: Microsoft-Windows-Eventlog
                            Time Written: 20020222100546.680982-000
                            Event Type: Succès de l'audit
                            User:

                            ======Environment variables======

                            "ComSpec"=%SystemRoot%\system32\cmd.exe
                            "FP_NO_HOST_CHECK"=NO
                            "OS"=Windows_NT
                            "Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;C:\Program Files\Toshiba\Bluetooth Toshiba Stack\sys\;C:\Program Files\Common Files\Ulead Systems\MPEG;C:\Program Files\QuickTime\QTSystem\
                            "PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC
                            "PROCESSOR_ARCHITECTURE"=x86
                            "TEMP"=%SystemRoot%\TEMP
                            "TMP"=%SystemRoot%\TEMP
                            "USERNAME"=SYSTEM
                            "windir"=%SystemRoot%
                            "PROCESSOR_LEVEL"=6
                            "PROCESSOR_IDENTIFIER"=x86 Family 6 Model 23 Stepping 10, GenuineIntel
                            "PROCESSOR_REVISION"=170a
                            "NUMBER_OF_PROCESSORS"=1
                            "TRACE_FORMAT_SEARCH_PATH"=\\NTREL202.ntdev.corp.microsoft.com\4F18C3A5-CA09-4DBD-B6FC-219FDD4C6BE0\TraceFormat
                            "DFSTRACINGON"=FALSE
                            "configsetroot"=%SystemRoot%\ConfigSetRoot
                            "CLASSPATH"=.;C:\Program Files\QuickTime\QTSystem\QTJava.zip
                            "QTJAVA"=C:\Program Files\QuickTime\QTSystem\QTJava.zip

                            -----------------EOF-----------------
                            0
                            1. Contributeur sécurité
                              télécharge OTM
                              http://www.geekstogo.com/forum/files/file/402-otm-oldtimers-move-it/ (de Old_Timer) sur ton Bureau.

                              double-clique sur OTM.exe pour le lancer.
                              copie la liste qui se trouve en citation ci-dessous,
                              et colle-la dans le cadre de gauche de OTM :Paste instruction for items to be moved.

                              :processes
                              explorer.exe
                              :services
                              Zwunzi Service
                              :files
                              C:\ProgramData\Zwunzi\zwunzi133.exe
                              C:\ProgramData\Zwunzi
                              :commands
                              [purity]
                              [emptytemp]
                              [start explorer]

                              clique sur MoveIt! pour lancer la suppression.
                              le résultat apparaitra dans le cadre "Results".
                              clique sur Exit pour fermer.
                              poste le rapport situé dans C:\_OTM\MovedFiles.

                              il te sera peut-être demander de redémarrer le pc pour achever la suppression.si c'est le cas accepte par Yes.

                              _________________________________

                              scan avec malwarebyte , fais un scan minutieux et colle le rapport obtenu et vire ce qui est trouvé:

                              https://www.malekal.com/tutoriel-malwarebyte-anti-malware/­

                              ______________________

                              a plus
                              0