Rapport Findykill à analyser

Résolu
Bonjour,

SVP est ce que vous pouvez analyser ce rapport Findykill mon pc est attaqué et je ne sais pas koi fair

############################## [ FindyKill V4.718 ]

# User : Ahmed (Administrateurs) # MIDOO
# Update on 01/03/09
# Start at: 18:25:57 | 02/03/2009

# Genuine Intel(R) CPU T2250 @ 1.73GHz
# Microsoft Windows XP dition familiale (5.1.2600 32-bit) # Service Pack 3
# Internet Explorer 7.0.5730.13
# Windows Firewall Status : Enabled
# AV : AVG Anti-Virus 8.0 [ Enabled | Updated ]
# AV : Lavasoft Ad-Watch Live! AntiVirus [ Enabled | Updated ]

# C:\ # Disque fixe local # 92,91 Go (34,39 Go free) # NTFS
# D:\ # Disque CD-ROM
# F:\ # Disque amovible # 1,88 Go (632,76 Mo free) [MIDOO] # FAT32

############################## [ Processus actifs ]

C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
C:\PROGRA~1\AVG\AVG8\avgam.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Toshiba\TOSHIBA Applet\TAPPSRV.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\system32\wbem\unsecapp.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\system32\TDispVol.exe
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\TOSHIBA\Utilitaire de zoom TOSHIBA\SmoothView.exe
C:\Program Files\TOSHIBA\Tvs\TvsTray.exe
C:\WINDOWS\system32\TPSMain.exe
C:\Program Files\Toshiba\Toshiba Applet\thotkey.exe
C:\Program Files\TOSHIBA\Commandes TOSHIBA\TFncKy.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\PixArt\PAC7311\Monitor.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\WINDOWS\system32\TPSBattM.exe
C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Synaptics\SynTP\Toshiba.exe
C:\Program Files\Internet Download Manager\IDMan.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Fichiers communs\Ahead\lib\NMBgMonitor.exe
C:\Program Files\Internet Download Manager\IEMonitor.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe

################## [ Fichiers / Dossiers infectieux C:\ ]

################## [ C:\WINDOWS ]

################## [ C:\WINDOWS\system32 ]

################## [ C:\WINDOWS\system32\drivers ]

################## [ C:\.. Application Data ... ]

################## [ Registre / Clés infectieuses ]

################## [ Recherche dans supports amovibles]

# Presence des fichiers :

################## [ Registre / Mountpoint2 ]

# -> Not found !

################## [ ! Fin du rapport # FindyKill V4.718 ! ]
Configuration: Windows XP
Firefox 3.0.6

35 réponses

Résumé de la discussion

Analyse d'un rapport de sécurité signale une infection potentielle sur un PC et présente les processus, les répertoires et les fichiers potentiellement malveillants relevés dans le système. Des éléments de solution essentiels incluent l’utilisation d’un scan Kaspersky qui détecte Trojan.Win32.Genome.hqg et signale un fichier infecté dans le profil Firefox, ainsi que l’analyse HijackThis montrant des processus système légitimes. Des résultats d’analyse indiquent des objets infectés et fichiers verrouillés, notamment des éléments dans Firefox et des archives RAR contenant Eviews_key.exe, ce qui suggère une contamination orientée vers des données personnelles. En dernier lieu, les rapports listent des éléments réseau et des outils de sécurité actifs qui peuvent nécessiter une intervention plus approfondie et une vérification systématique des sauvegardes et des restaurations.

Bobot (l’IA à votre service)
  1. Modérateur
    Tu peux supprimer ToolsCleaner.
    0
    1. [ Rapport ToolsCleaner version 2.3.2 (par A.Rothstein & dj QUIOU) ]

      -->- Recherche:

      C:\VundoFix.txt: trouvé !
      C:\Combofix.txt: trouvé !
      C:\fixnavi.txt: trouvé !
      C:\FindyKill.txt: trouvé !
      C:\_OtMoveIt: trouvé !
      C:\Rsit: trouvé !
      C:\Documents and Settings\Ahmed\Bureau\OTMoveIt3.exe: trouvé !
      C:\Documents and Settings\Ahmed\Bureau\virus_softwares\SdFix.exe: trouvé !
      C:\Documents and Settings\Ahmed\Bureau\virus_softwares\VirtumundoBeGone.exe: trouvé !
      C:\Documents and Settings\Ahmed\Bureau\virus_softwares\Navilog1.exe: trouvé !
      C:\Documents and Settings\Ahmed\Bureau\virus_softwares\ComboFix.exe: trouvé !
      C:\Documents and Settings\Ahmed\Bureau\virus_softwares\vundoFix.exe: trouvé !
      C:\Documents and Settings\Ahmed\Bureau\virus_softwares\HijackThis.exe: trouvé !
      C:\Documents and Settings\Ahmed\Bureau\virus_softwares\SmitFraudFix.exe: trouvé !
      C:\Documents and Settings\Ahmed\Bureau\virus_softwares\Rsit.exe: trouvé !
      C:\Documents and Settings\Ahmed\Bureau\virus_softwares\OTViewIt.exe: trouvé !
      C:\Documents and Settings\All Users\Bureau\Navilog1.lnk: trouvé !
      C:\Documents and Settings\All Users\Bureau\VBG.txt: trouvé !
      C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Navilog1: trouvé !
      C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Navilog1\Navilog1.lnk: trouvé !
      C:\Program Files\Navilog1: trouvé !
      C:\Program Files\FindyKill: trouvé !
      C:\Program Files\Navilog1\Navilog1.bat: trouvé !
      C:\Program Files\Trend Micro\HijackThis: trouvé !
      C:\Program Files\Trend Micro\HijackThis\HijackThis.exe: trouvé !
      C:\Program Files\Trend Micro\HijackThis\hijackthis.log: trouvé !

      ---------------------------------
      -->- Suppression:

      C:\Documents and Settings\Ahmed\Bureau\virus_softwares\SdFix.exe: supprimé !
      C:\Documents and Settings\Ahmed\Bureau\virus_softwares\VirtumundoBeGone.exe: supprimé !
      C:\Documents and Settings\Ahmed\Bureau\virus_softwares\Navilog1.exe: supprimé !
      C:\Documents and Settings\Ahmed\Bureau\virus_softwares\ComboFix.exe: supprimé !
      C:\Documents and Settings\Ahmed\Bureau\virus_softwares\vundoFix.exe: supprimé !
      C:\Documents and Settings\Ahmed\Bureau\virus_softwares\HijackThis.exe: supprimé !
      C:\Documents and Settings\Ahmed\Bureau\virus_softwares\SmitFraudFix.exe: supprimé !
      C:\Documents and Settings\All Users\Bureau\Navilog1.lnk: supprimé !
      C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Navilog1\Navilog1.lnk: supprimé !
      C:\Program Files\Navilog1\Navilog1.bat: supprimé !
      C:\Program Files\Trend Micro\HijackThis\HijackThis.exe: supprimé !
      C:\VundoFix.txt: supprimé !
      C:\Combofix.txt: supprimé !
      C:\fixnavi.txt: supprimé !
      C:\FindyKill.txt: supprimé !
      C:\Documents and Settings\Ahmed\Bureau\OTMoveIt3.exe: supprimé !
      C:\Documents and Settings\Ahmed\Bureau\virus_softwares\Rsit.exe: supprimé !
      C:\Documents and Settings\Ahmed\Bureau\virus_softwares\OTViewIt.exe: supprimé !
      C:\Documents and Settings\All Users\Bureau\VBG.txt: supprimé !
      C:\Program Files\Trend Micro\HijackThis\hijackthis.log: supprimé !
      C:\_OtMoveIt: supprimé !
      C:\Rsit: supprimé !
      C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Navilog1: supprimé !
      C:\Program Files\Navilog1: supprimé !
      C:\Program Files\FindyKill: supprimé !
      C:\Program Files\Trend Micro\HijackThis: supprimé !
      0
      1. Modérateur
        1/

        ---> Désinstalle HijackThis.

        ---> Télécharge ToolsCleaner2 sur ton Bureau.
        * Double-clique sur ToolsCleaner2.exe pour le lancer.
        * Clique sur Recherche et laisse le scan agir.
        * Clique sur Suppression pour finaliser.
        * Tu peux, si tu le souhaites, te servir des Options Facultatives.
        * Clique sur Quitter pour obtenir le rapport.
        * Poste le rapport (TCleaner.txt) qui se trouve à la racine de ton disque dur (C:\).

        2/

        ---> Télécharge et installe CCleaner Slim.
        * Lance-le. Va dans Options puis Avancé et décoche la case Effacer uniquement les fichiers etc....
        * Va dans Nettoyeur, choisis Analyse. Une fois terminé, lance le nettoyage.
        * Ensuite, choisis Registre, puis Chercher des erreurs. Une fois terminé, répare toutes les erreurs (Sauvegarde la base de registre).

        3/

        ---> Il est nécessaire de désactiver puis réactiver la restauration système pour la purger.

        ---> Je te conseille de créer un point de restauration que tu pourras utiliser plus tard si tu as un problème.

        ==Prévention==

        Conserve MBAM. Il te servira à scanner les fichiers douteux en complément de l'antivirus et scanne le disque dur régulièrement.

        Comme navigateur, utilise plutôt Mozilla Firefox qu'Internet Explorer. Tu peux utiliser l'extension NoScript pour plus de sécurité.

        Vérifie que les mises à jour automatiques sont bien activées (Menu Démarrer, clique droit sur Poste de travail, onglet Mises à jour automatiques).

        Tu peux aussi modifier le fichier Hosts pour améliorer la sécurité de ton PC : Lien

        Par rapport au P2P : Lien

        Voici un dossier complet (A lire avec Adobe Reader ou Foxit Reader) : Lien

        Sois plus vigilant(e) sur Internet ;)
        0
        1. Oui je pense que tt va bien. Thank you so much You are the best Destrio5 ;)
          0
          1. log.txt

            Logfile of random's system information tool 1.05 (written by random/random)
            Run by Ahmed at 2009-03-04 19:12:32
            Microsoft Windows XP Édition familiale Service Pack 3
            System drive C: has 38 GB (40%) free of 95 GB
            Total RAM: 2046 MB (56% free)

            Logfile of Trend Micro HijackThis v2.0.2
            Scan saved at 19:12:40, on 04/03/2009
            Platform: Windows XP SP3 (WinNT 5.01.2600)
            MSIE: Internet Explorer v7.00 (7.00.6000.16791)
            Boot mode: Normal

            Running processes:
            C:\WINDOWS\System32\smss.exe
            C:\WINDOWS\system32\winlogon.exe
            C:\WINDOWS\system32\services.exe
            C:\WINDOWS\system32\lsass.exe
            C:\WINDOWS\system32\Ati2evxx.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\System32\svchost.exe
            C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
            C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
            C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
            C:\WINDOWS\system32\spoolsv.exe
            C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
            C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
            C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
            C:\WINDOWS\system32\Ati2evxx.exe
            C:\WINDOWS\system32\svchost.exe
            C:\Program Files\Toshiba\TOSHIBA Applet\TAPPSRV.exe
            C:\WINDOWS\Explorer.EXE
            C:\PROGRA~1\AVG\AVG8\avgam.exe
            C:\PROGRA~1\AVG\AVG8\avgrsx.exe
            C:\PROGRA~1\AVG\AVG8\avgnsx.exe
            C:\WINDOWS\system32\TDispVol.exe
            C:\WINDOWS\System32\DLA\DLACTRLW.EXE
            C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
            C:\Program Files\TOSHIBA\Utilitaire de zoom TOSHIBA\SmoothView.exe
            C:\Program Files\TOSHIBA\Tvs\TvsTray.exe
            C:\WINDOWS\system32\TPSMain.exe
            C:\Program Files\Toshiba\Toshiba Applet\thotkey.exe
            C:\Program Files\TOSHIBA\Commandes TOSHIBA\TFncKy.exe
            C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
            C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe
            C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
            C:\WINDOWS\AGRSMMSG.exe
            C:\WINDOWS\PixArt\PAC7311\Monitor.exe
            C:\PROGRA~1\AVG\AVG8\avgtray.exe
            C:\WINDOWS\system32\ctfmon.exe
            C:\Program Files\Internet Download Manager\IDMan.exe
            C:\Program Files\Synaptics\SynTP\Toshiba.exe
            C:\Program Files\Skype\Phone\Skype.exe
            C:\Program Files\Windows Live\Messenger\msnmsgr.exe
            C:\WINDOWS\system32\TPSBattM.exe
            C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
            C:\Program Files\Messenger\msmsgs.exe
            C:\Program Files\Fichiers communs\Ahead\lib\NMBgMonitor.exe
            C:\Program Files\Internet Download Manager\IEMonitor.exe
            C:\Program Files\Skype\Plugin Manager\skypePM.exe
            C:\Program Files\Windows Live\Contacts\wlcomm.exe
            C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
            C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
            C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
            C:\Program Files\Mozilla Firefox\firefox.exe
            C:\WINDOWS\system32\rundll32.exe
            C:\WINDOWS\system32\msiexec.exe
            C:\Program Files\Screamer Radio\screamer.exe
            C:\Program Files\Java\jre6\bin\jqs.exe
            C:\WINDOWS\system32\wbem\wmiapsrv.exe
            C:\Documents and Settings\Ahmed\Bureau\virus_softwares\RSIT.exe
            C:\Program Files\Trend Micro\HijackThis\Ahmed.exe

            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
            R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
            R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://support.norton.com/sp/fr/fr/home/current/solutions/kb20090121104844EN?abproduct=SymNRT&abversion=2009.0.0.41&build=Symantec&ced=true&entsrc=CED_pubweb&error=0&module=2009&src=_mi
            R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
            O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files\Internet Download Manager\IDMIECC.dll
            O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
            O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
            O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
            O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
            O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
            O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
            O4 - HKLM\..\Run: [TDispVol] TDispVol.exe
            O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE
            O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
            O4 - HKLM\..\Run: [SmoothView] C:\Program Files\TOSHIBA\Utilitaire de zoom TOSHIBA\SmoothView.exe
            O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
            O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
            O4 - HKLM\..\Run: [Tvs] C:\Program Files\TOSHIBA\Tvs\TvsTray.exe
            O4 - HKLM\..\Run: [TPSMain] TPSMain.exe
            O4 - HKLM\..\Run: [THotkey] C:\Program Files\Toshiba\Toshiba Applet\thotkey.exe
            O4 - HKLM\..\Run: [TFncKy] TFncKy.exe
            O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
            O4 - HKLM\..\Run: [NDSTray.exe] NDSTray.exe
            O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
            O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
            O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
            O4 - HKLM\..\Run: [Monitor] C:\WINDOWS\PixArt\PAC7311\Monitor.exe
            O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
            O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
            O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
            O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
            O4 - HKCU\..\Run: [IDMan] C:\Program Files\Internet Download Manager\IDMan.exe /onboot
            O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
            O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
            O4 - HKCU\..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
            O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
            O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Ahead\lib\NMBgMonitor.exe"
            O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
            O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
            O8 - Extra context menu item: Download all links with IDM - C:\Program Files\Internet Download Manager\IEGetAll.htm
            O8 - Extra context menu item: Download FLV video content with IDM - C:\Program Files\Internet Download Manager\IEGetVL.htm
            O8 - Extra context menu item: Download with IDM - C:\Program Files\Internet Download Manager\IEExt.htm
            O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
            O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
            O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
            O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
            O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
            O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
            O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - https://www.kaspersky.fr/?domain=webscanner.kaspersky.fr
            O17 - HKLM\System\CCS\Services\Tcpip\..\{F34E8A4D-DA5A-4E87-9352-87D82CF4FE91}: NameServer = 193.95.66.10
            O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
            O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
            O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
            O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
            O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
            O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
            O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
            O23 - Service: Google Desktop Manager 5.8.809.23506 (GoogleDesktopManager-092308-165331) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
            O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
            O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
            O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
            O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
            O23 - Service: TOSHIBA Application Service (TAPPSRV) - TOSHIBA Corp. - C:\Program Files\Toshiba\TOSHIBA Applet\TAPPSRV.exe
            0
            1. Modérateur
              ---> Désinstalle les programmes suivants :
              - J2SE Runtime Environment 5.0 Update 4
              - Java 6 Update 6

              ---> Mets à jour Java.

              ---> Mets à jour Adobe Reader.

              ---> Mets à jour AVG Anti-Virus Free Edition.

              ---> Refais un scan RSIT et poste le rapport log.
              0
              1. Voici le rapport

                ========== PROCESSES ==========
                Process explorer.exe killed successfully.
                ========== REGISTRY ==========
                Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WindowsTelephony\\ deleted successfully.
                Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WindowsTelephony\\ deleted successfully.
                ========== COMMANDS ==========
                File delete failed. C:\DOCUME~1\Ahmed\LOCALS~1\Temp\etilqs_nGDUevtvmt6PftNvJZFS scheduled to be deleted on reboot.
                File delete failed. C:\DOCUME~1\Ahmed\LOCALS~1\Temp\Perflib_Perfdata_808.dat scheduled to be deleted on reboot.
                File delete failed. C:\DOCUME~1\Ahmed\LOCALS~1\Temp\Perflib_Perfdata_c80.dat scheduled to be deleted on reboot.
                File delete failed. C:\DOCUME~1\Ahmed\LOCALS~1\Temp\Perflib_Perfdata_cb4.dat scheduled to be deleted on reboot.
                File delete failed. C:\DOCUME~1\Ahmed\LOCALS~1\Temp\~DF3DBD.tmp scheduled to be deleted on reboot.
                File delete failed. C:\DOCUME~1\Ahmed\LOCALS~1\Temp\~DFF51E.tmp scheduled to be deleted on reboot.
                User's Temp folder emptied.
                User's Temporary Internet Files folder emptied.
                User's Internet Explorer cache folder emptied.
                File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temp\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
                File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temp\History\History.IE5\index.dat scheduled to be deleted on reboot.
                File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temp\Cookies\index.dat scheduled to be deleted on reboot.
                Local Service Temp folder emptied.
                File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
                Local Service Temporary Internet Files folder emptied.
                File delete failed. C:\WINDOWS\temp\24e50817-74f0-41fe-9da0-a459e863e829.tmp scheduled to be deleted on reboot.
                File delete failed. C:\WINDOWS\temp\2d40f24c-5e75-4cf5-89c3-abe0e9838348.tmp scheduled to be deleted on reboot.
                File delete failed. C:\WINDOWS\temp\31242217-1e45-4e26-b4f9-4f1229b3d88d.tmp scheduled to be deleted on reboot.
                File delete failed. C:\WINDOWS\temp\338f4769-1316-4ab5-8389-d5cc4102d4cc.tmp scheduled to be deleted on reboot.
                File delete failed. C:\WINDOWS\temp\39b9f349-adfe-4fce-a059-cb0fe91a39fa.tmp scheduled to be deleted on reboot.
                File delete failed. C:\WINDOWS\temp\3ed87bac-7dd1-40f2-be14-93860a580d7e.tmp scheduled to be deleted on reboot.
                File delete failed. C:\WINDOWS\temp\43c62500-7e0a-442a-aac4-95f25dc8f4d8.tmp scheduled to be deleted on reboot.
                File delete failed. C:\WINDOWS\temp\44f4071a-f06f-4b11-b2f5-e55b19a81241.tmp scheduled to be deleted on reboot.
                File delete failed. C:\WINDOWS\temp\4efa2f12-557d-4207-8577-0ef2be9e2741.tmp scheduled to be deleted on reboot.
                File delete failed. C:\WINDOWS\temp\666f4c3e-7982-4a16-9872-f2bc304acc42.tmp scheduled to be deleted on reboot.
                File delete failed. C:\WINDOWS\temp\6724a2f6-bf89-4bf2-8257-7f813c377133.tmp scheduled to be deleted on reboot.
                File delete failed. C:\WINDOWS\temp\6ea3054b-e3cd-4937-960f-d429ec4972a8.tmp scheduled to be deleted on reboot.
                File delete failed. C:\WINDOWS\temp\701709b4-a3b6-4bd5-8cd7-56a5bf0c4668.tmp scheduled to be deleted on reboot.
                File delete failed. C:\WINDOWS\temp\75691334-6933-499a-9cab-aad4d39386c4.tmp scheduled to be deleted on reboot.
                File delete failed. C:\WINDOWS\temp\791dbcf0-10ac-4fb0-a4b2-3841460ab481.tmp scheduled to be deleted on reboot.
                File delete failed. C:\WINDOWS\temp\8c2a8f17-078d-464e-afeb-4b6422baaa22.tmp scheduled to be deleted on reboot.
                File delete failed. C:\WINDOWS\temp\8f7221fb-e62f-49e9-94fc-3626b362fe21.tmp scheduled to be deleted on reboot.
                File delete failed. C:\WINDOWS\temp\a410bf8c-87a3-4985-8a8f-7361b495d717.tmp scheduled to be deleted on reboot.
                File delete failed. C:\WINDOWS\temp\b8f09084-1c2c-42bc-ae0d-40e52be7791f.tmp scheduled to be deleted on reboot.
                File delete failed. C:\WINDOWS\temp\d55b0603-005c-41d6-b8e2-677e315f6e28.tmp scheduled to be deleted on reboot.
                File delete failed. C:\WINDOWS\temp\e4f56ac2-87fc-4cd2-81cf-4475257f9e69.tmp scheduled to be deleted on reboot.
                Windows Temp folder emptied.
                Java cache emptied.
                File delete failed. C:\Documents and Settings\Ahmed\Local Settings\Application Data\Mozilla\Firefox\Profiles\xbksflkg.default\Cache\_CACHE_001_ scheduled to be deleted on reboot.
                File delete failed. C:\Documents and Settings\Ahmed\Local Settings\Application Data\Mozilla\Firefox\Profiles\xbksflkg.default\Cache\_CACHE_002_ scheduled to be deleted on reboot.
                File delete failed. C:\Documents and Settings\Ahmed\Local Settings\Application Data\Mozilla\Firefox\Profiles\xbksflkg.default\Cache\_CACHE_003_ scheduled to be deleted on reboot.
                File delete failed. C:\Documents and Settings\Ahmed\Local Settings\Application Data\Mozilla\Firefox\Profiles\xbksflkg.default\Cache\_CACHE_MAP_ scheduled to be deleted on reboot.
                File delete failed. C:\Documents and Settings\Ahmed\Local Settings\Application Data\Mozilla\Firefox\Profiles\xbksflkg.default\urlclassifier3.sqlite scheduled to be deleted on reboot.
                FireFox cache emptied.
                Temp folders emptied.

                OTMoveIt3 by OldTimer - Version 1.0.8.0 log created on 03042009_183549

                Files moved on Reboot...
                File C:\DOCUME~1\Ahmed\LOCALS~1\Temp\etilqs_nGDUevtvmt6PftNvJZFS not found!
                File C:\DOCUME~1\Ahmed\LOCALS~1\Temp\Perflib_Perfdata_808.dat not found!
                File C:\DOCUME~1\Ahmed\LOCALS~1\Temp\Perflib_Perfdata_c80.dat not found!
                File C:\DOCUME~1\Ahmed\LOCALS~1\Temp\Perflib_Perfdata_cb4.dat not found!
                C:\DOCUME~1\Ahmed\LOCALS~1\Temp\~DF3DBD.tmp moved successfully.
                C:\DOCUME~1\Ahmed\LOCALS~1\Temp\~DFF51E.tmp moved successfully.
                File move failed. C:\Documents and Settings\LocalService\Local Settings\Temp\Temporary Internet Files\Content.IE5\index.dat scheduled to be moved on reboot.
                File move failed. C:\Documents and Settings\LocalService\Local Settings\Temp\History\History.IE5\index.dat scheduled to be moved on reboot.
                File move failed. C:\Documents and Settings\LocalService\Local Settings\Temp\Cookies\index.dat scheduled to be moved on reboot.
                File move failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be moved on reboot.
                C:\WINDOWS\temp\24e50817-74f0-41fe-9da0-a459e863e829.tmp moved successfully.
                C:\WINDOWS\temp\2d40f24c-5e75-4cf5-89c3-abe0e9838348.tmp moved successfully.
                C:\WINDOWS\temp\31242217-1e45-4e26-b4f9-4f1229b3d88d.tmp moved successfully.
                C:\WINDOWS\temp\338f4769-1316-4ab5-8389-d5cc4102d4cc.tmp moved successfully.
                C:\WINDOWS\temp\39b9f349-adfe-4fce-a059-cb0fe91a39fa.tmp moved successfully.
                C:\WINDOWS\temp\3ed87bac-7dd1-40f2-be14-93860a580d7e.tmp moved successfully.
                C:\WINDOWS\temp\43c62500-7e0a-442a-aac4-95f25dc8f4d8.tmp moved successfully.
                C:\WINDOWS\temp\44f4071a-f06f-4b11-b2f5-e55b19a81241.tmp moved successfully.
                C:\WINDOWS\temp\4efa2f12-557d-4207-8577-0ef2be9e2741.tmp moved successfully.
                C:\WINDOWS\temp\666f4c3e-7982-4a16-9872-f2bc304acc42.tmp moved successfully.
                C:\WINDOWS\temp\6724a2f6-bf89-4bf2-8257-7f813c377133.tmp moved successfully.
                C:\WINDOWS\temp\6ea3054b-e3cd-4937-960f-d429ec4972a8.tmp moved successfully.
                C:\WINDOWS\temp\701709b4-a3b6-4bd5-8cd7-56a5bf0c4668.tmp moved successfully.
                C:\WINDOWS\temp\75691334-6933-499a-9cab-aad4d39386c4.tmp moved successfully.
                C:\WINDOWS\temp\791dbcf0-10ac-4fb0-a4b2-3841460ab481.tmp moved successfully.
                C:\WINDOWS\temp\8c2a8f17-078d-464e-afeb-4b6422baaa22.tmp moved successfully.
                C:\WINDOWS\temp\8f7221fb-e62f-49e9-94fc-3626b362fe21.tmp moved successfully.
                C:\WINDOWS\temp\a410bf8c-87a3-4985-8a8f-7361b495d717.tmp moved successfully.
                C:\WINDOWS\temp\b8f09084-1c2c-42bc-ae0d-40e52be7791f.tmp moved successfully.
                C:\WINDOWS\temp\d55b0603-005c-41d6-b8e2-677e315f6e28.tmp moved successfully.
                C:\WINDOWS\temp\e4f56ac2-87fc-4cd2-81cf-4475257f9e69.tmp moved successfully.
                C:\Documents and Settings\Ahmed\Local Settings\Application Data\Mozilla\Firefox\Profiles\xbksflkg.default\Cache\_CACHE_001_ moved successfully.
                C:\Documents and Settings\Ahmed\Local Settings\Application Data\Mozilla\Firefox\Profiles\xbksflkg.default\Cache\_CACHE_002_ moved successfully.
                C:\Documents and Settings\Ahmed\Local Settings\Application Data\Mozilla\Firefox\Profiles\xbksflkg.default\Cache\_CACHE_003_ moved successfully.
                C:\Documents and Settings\Ahmed\Local Settings\Application Data\Mozilla\Firefox\Profiles\xbksflkg.default\Cache\_CACHE_MAP_ moved successfully.
                C:\Documents and Settings\Ahmed\Local Settings\Application Data\Mozilla\Firefox\Profiles\xbksflkg.default\urlclassifier3.sqlite moved successfully.
                0
                1. bonjour,

                  voici info.txt en attendant k j effectue l'autre procedure

                  info.txt logfile of random's system information tool 1.05 2009-03-04 07:17:25

                  ======Uninstall list======

                  -->C:\Program Files\Nero\Nero 7\nero\uninstall\UNNERO.exe /UNINSTALL
                  -->C:\WINDOWS\IsUn040c.exe -fC:\WINDOWS\orun32.isu
                  -->C:\WINDOWS\system32\\MSIEXEC.EXE /x {1206EF92-2E83-4859-ACCB-2048C3CB7DA6}
                  -->C:\WINDOWS\system32\\MSIEXEC.EXE /x {9541FED0-327F-4df0-8B96-EF57EF622F19}
                  -->C:\WINDOWS\UNNeroBackItUp.exe /UNINSTALL
                  -->C:\WINDOWS\UNNeroMediaHome.exe /UNINSTALL
                  -->C:\WINDOWS\UNNeroShowTime.exe /UNINSTALL
                  -->C:\WINDOWS\UNNeroVision.exe /UNINSTALL
                  -->C:\WINDOWS\UNRecode.exe /UNINSTALL
                  -->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
                  2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {BEE75E01-DD3F-4D5F-B96C-609E6538D419}
                  2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-0015-040C-0000-0000000FF1CE} /uninstall {A0353900-21A2-42CF-B973-883500A027F7}
                  2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-0016-040C-0000-0000000FF1CE} /uninstall {A0353900-21A2-42CF-B973-883500A027F7}
                  2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-0018-040C-0000-0000000FF1CE} /uninstall {A0353900-21A2-42CF-B973-883500A027F7}
                  2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-0019-040C-0000-0000000FF1CE} /uninstall {A0353900-21A2-42CF-B973-883500A027F7}
                  2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001A-040C-0000-0000000FF1CE} /uninstall {A0353900-21A2-42CF-B973-883500A027F7}
                  2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001B-040C-0000-0000000FF1CE} /uninstall {A0353900-21A2-42CF-B973-883500A027F7}
                  2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001F-0401-0000-0000000FF1CE} /uninstall {5A2F65A4-808F-4A1E-973E-92E17824982D}
                  2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001F-0407-0000-0000000FF1CE} /uninstall {2AB528A5-BB1B-4EBE-8E51-AD0C4CD33CA9}
                  2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001F-0409-0000-0000000FF1CE} /uninstall {3EC77D26-799B-4CD8-914F-C1565E796173}
                  2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001F-040C-0000-0000000FF1CE} /uninstall {430971B1-C31E-45DA-81E0-72C095BAB72C}
                  2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001F-0413-0000-0000000FF1CE} /uninstall {B3F4DC34-7F60-4B7C-A79F-1C13012D99D4}
                  2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001F-0C0A-0000-0000000FF1CE} /uninstall {F7A31780-33C4-4E39-951A-5EC9B91D7BF1}
                  2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-0044-040C-0000-0000000FF1CE} /uninstall {A0353900-21A2-42CF-B973-883500A027F7}
                  Ad-Aware-->"C:\Documents and Settings\All Users\Application Data\{2BAE6915-8510-4B9F-B498-02DA86258AA0}\Ad-AwareAE.exe" REMOVE=TRUE MODIFY=FALSE
                  Ad-Aware-->C:\Documents and Settings\All Users\Application Data\{2BAE6915-8510-4B9F-B498-02DA86258AA0}\Ad-AwareAE.exe
                  Adobe Flash Player Plugin-->C:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe
                  Adobe Reader 7.0.5 - Français-->MsiExec.exe /I{AC76BA86-7AD7-1036-7B44-A70500000002}
                  Adobe Reader Chinese Simplified Fonts-->MsiExec.exe /I{AC76BA86-7AD7-2447-0000-705000000001}
                  Adobe Reader Japanese Fonts-->MsiExec.exe /I{AC76BA86-7AD7-5760-0000-705000000001}
                  Archiveur WinRAR-->C:\Program Files\WinRAR\uninstall.exe
                  Assist TOSHIBA-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{12B3A009-A080-4619-9A2A-C6DB151D8D67}\Setup.exe" -l0x40c
                  Assistant de connexion Windows Live-->MsiExec.exe /I{DCE8CD14-FBF5-4464-B9A4-E18E473546C7}
                  ATI - Utilitaire de désinstallation du logiciel-->C:\Program Files\ATI Technologies\UninstallAll\AtiCimUn.exe
                  ATI Catalyst Control Center-->MsiExec.exe /I{06C71F80-0E30-4E2C-878F-8502AB5AE3BE}
                  ATI Display Driver-->rundll32 C:\WINDOWS\system32\atiiiexx.dll,_InfEngUnInstallINFFile_RunDLL@16 -force_restart -flags:0x2010001 -inf_class:DISPLAY -clean
                  AVG 8.0-->C:\Program Files\AVG\AVG8\setup.exe /UNINSTALL
                  Bluetooth Stack for Windows by Toshiba-->MsiExec.exe /X{CEBB6BFB-D708-4F99-A633-BC2600E01EF6}
                  CCleaner (remove only)-->"C:\Program Files\CCleaner\uninst.exe"
                  Choice Guard-->MsiExec.exe /I{8FFC5648-FAF8-43A3-BC8F-42BA1E275C4E}
                  Commandes TOSHIBA-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{A6690C0E-B96E-4F0F-A8EB-D5B332454AC6}\Setup.exe" -l0x40c UNINSTALL
                  Correctif pour Windows XP (KB952287)-->"C:\WINDOWS\$NtUninstallKB952287$\spuninst\spuninst.exe"
                  Formatage de carte mémoire SD TOSHIBA-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{48CF9A66-5F03-4025-ABD0-B3A3FA095A59}\Setup.exe" -l0x40c
                  Gestion d'énergie TOSHIBA-->C:\WINDOWS\IsUn040c.exe -f"C:\Program Files\TOSHIBA\Power Saver\Uninst.isu" -c"C:\WINDOWS\system32\TPSDel.dll"
                  Google Desktop-->C:\Program Files\Google\Google Desktop Search\GoogleDesktopSetup.exe -uninstall
                  High Definition Audio Driver Package - KB888111-->"C:\WINDOWS\$NtUninstallKB888111WXPSP2$\spuninst\spuninst.exe"
                  HijackThis 2.0.2-->"C:\Program Files\Trend Micro\HijackThis\HijackThis.exe" /uninstall
                  Installation Windows Live-->C:\Program Files\Windows Live\Installer\wlarp.exe
                  Installation Windows Live-->MsiExec.exe /I{7370DF47-B4F9-4279-BFC3-3F09919F720D}
                  Intel(R) PRO Network Connections Drivers-->Prounstl.exe
                  Internet Download Manager-->C:\Program Files\Internet Download Manager\Uninstall.exe
                  InterVideo WinDVD Creator 2-->"C:\Program Files\InstallShield Installation Information\{2FCE4FC5-6930-40E7-A4F1-F862207424EF}\setup.exe" REMOVEALL
                  InterVideo WinDVD for TOSHIBA-->"C:\Program Files\InstallShield Installation Information\{91810AFC-A4F8-4EBA-A5AA-B198BBC81144}\setup.exe" REMOVEALL
                  J2SE Runtime Environment 5.0 Update 4-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0150040}
                  Java DB 10.3.1.4-->MsiExec.exe /X{CD49361E-3FE6-457E-90A1-9C59E29B5D02}
                  Java(TM) 6 Update 6-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160060}
                  Java(TM) SE Development Kit 6 Update 6-->MsiExec.exe /I{32A3A4F4-B792-11D6-A78A-00B0D0160060}
                  jetAudio Basic-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\10\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{DF8195AF-8E6F-4487-A0EE-196F7E3F4B8A}\setup.exe" -l0xc0c -removeonly
                  Kaspersky Online Scanner-->C:\WINDOWS\system32\KASPER~1\KASPER~1\kavuninstall.exe
                  Kaspersky On-line Scanner-->C:\WINDOWS\system32\KASPER~1\KASPER~1\kavuninstall.exe
                  K-Lite Codec Pack 3.5.0 Full-->"C:\Program Files\K-Lite Codec Pack\unins000.exe"
                  Lecteur Windows Media 10-->"C:\Program Files\Windows Media Player\Setup_wm.exe" /Uninstall
                  Logiciel Intel(R) PROSet/Wireless-->C:\WINDOWS\Installer\iProInst.exe
                  Macromedia Flash Player-->MsiExec.exe /X{0456ebd7-5f67-4ab6-852e-63781e3f389c}
                  Malwarebytes' Anti-Malware-->"C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
                  Manuels TOSHIBA-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\10\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{3EB6332B-AF02-457C-A31C-835458C5B48B}\setup.exe" -l0x40c -removeonly
                  mCore-->MsiExec.exe /I{E81667C6-2856-46D6-ABEA-6A2F42166779}
                  mDrWiFi-->MsiExec.exe /I{F6090A17-0967-4A8A-B3C3-422A1B514D49}
                  mHelp-->MsiExec.exe /I{8C6BB412-D3A8-4AAE-A01B-35B681789D68}
                  Microsoft .NET Framework 1.1 French Language Pack-->MsiExec.exe /X{9A394342-4A68-4EBA-85A6-55B559F4E700}
                  Microsoft .NET Framework 1.1 Hotfix (KB928366)-->"C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\hotfix.exe" "C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\M928366\M928366Uninstall.msp"
                  Microsoft .NET Framework 1.1-->msiexec.exe /X {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
                  Microsoft .NET Framework 1.1-->MsiExec.exe /X{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
                  Microsoft Internationalized Domain Names Mitigation APIs-->"C:\WINDOWS\$NtServicePackUninstallIDNMitigationAPIs$\spuninst\spuninst.exe"
                  Microsoft National Language Support Downlevel APIs-->"C:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$\spuninst\spuninst.exe"
                  Microsoft Office Access MUI (French) 2007-->MsiExec.exe /X{90120000-0015-040C-0000-0000000FF1CE}
                  Microsoft Office Excel MUI (French) 2007-->MsiExec.exe /X{90120000-0016-040C-0000-0000000FF1CE}
                  Microsoft Office InfoPath MUI (French) 2007-->MsiExec.exe /X{90120000-0044-040C-0000-0000000FF1CE}
                  Microsoft Office Language Pack 2007 Service Pack 1 (SP1)-->msiexec /package {90120000-006E-040C-0000-0000000FF1CE} /uninstall {EC50B538-CBE1-42E6-B7FE-87AA540AADFB}
                  Microsoft Office OneNote 2003-->MsiExec.exe /I{91A1040C-6000-11D3-8CFE-0150048383C9}
                  Microsoft Office Outlook MUI (French) 2007-->MsiExec.exe /X{90120000-001A-040C-0000-0000000FF1CE}
                  Microsoft Office PowerPoint MUI (French) 2007-->MsiExec.exe /X{90120000-0018-040C-0000-0000000FF1CE}
                  Microsoft Office Professional Plus 2007-->"C:\Program Files\Fichiers communs\Microsoft Shared\OFFICE12\Office Setup Controller\setup.exe" /uninstall PROPLUS /dll OSETUP.DLL
                  Microsoft Office Professional Plus 2007-->MsiExec.exe /X{90120000-0011-0000-0000-0000000FF1CE}
                  Microsoft Office Proof (Arabic) 2007-->MsiExec.exe /X{90120000-001F-0401-0000-0000000FF1CE}
                  Microsoft Office Proof (Dutch) 2007-->MsiExec.exe /X{90120000-001F-0413-0000-0000000FF1CE}
                  Microsoft Office Proof (English) 2007-->MsiExec.exe /X{90120000-001F-0409-0000-0000000FF1CE}
                  Microsoft Office Proof (French) 2007-->MsiExec.exe /X{90120000-001F-040C-0000-0000000FF1CE}
                  Microsoft Office Proof (German) 2007-->MsiExec.exe /X{90120000-001F-0407-0000-0000000FF1CE}
                  Microsoft Office Proof (Spanish) 2007-->MsiExec.exe /X{90120000-001F-0C0A-0000-0000000FF1CE}
                  Microsoft Office Proofing (French) 2007-->MsiExec.exe /X{90120000-002C-040C-0000-0000000FF1CE}
                  Microsoft Office Publisher MUI (French) 2007-->MsiExec.exe /X{90120000-0019-040C-0000-0000000FF1CE}
                  Microsoft Office Shared MUI (French) 2007-->MsiExec.exe /X{90120000-006E-040C-0000-0000000FF1CE}
                  Microsoft Office Word MUI (French) 2007-->MsiExec.exe /X{90120000-001B-040C-0000-0000000FF1CE}
                  Microsoft Silverlight-->MsiExec.exe /X{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
                  Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
                  Mise à jour de sécurité pour Lecteur Windows Media (KB952069)-->"C:\WINDOWS\$NtUninstallKB952069_WM9$\spuninst\spuninst.exe"
                  Mise à jour de sécurité pour Lecteur Windows Media 10 (KB936782)-->"C:\WINDOWS\$NtUninstallKB936782_WMP10$\spuninst\spuninst.exe"
                  Mise à jour de sécurité pour Step by Step Interactive Training (KB898458)-->"C:\WINDOWS\$NtUninstallKB898458$\spuninst\spuninst.exe"
                  Mise à jour de sécurité pour Step by Step Interactive Training (KB923723)-->"C:\WINDOWS\$NtUninstallKB923723$\spuninst\spuninst.exe"
                  Mise à jour de sécurité pour Windows Internet Explorer 7 (KB938127-v2)-->"C:\WINDOWS\ie7updates\KB938127-v2-IE7\spuninst\spuninst.exe"
                  Mise à jour de sécurité pour Windows Internet Explorer 7 (KB956390)-->"C:\WINDOWS\ie7updates\KB956390-IE7\spuninst\spuninst.exe"
                  Mise à jour de sécurité pour Windows Internet Explorer 7 (KB961260)-->"C:\WINDOWS\ie7updates\KB961260-IE7\spuninst\spuninst.exe"
                  Mise à jour de sécurité pour Windows XP (KB938464)-->"C:\WINDOWS\$NtUninstallKB938464$\spuninst\spuninst.exe"
                  Mise à jour de sécurité pour Windows XP (KB941569)-->"C:\WINDOWS\$NtUninstallKB941569$\spuninst\spuninst.exe"
                  Mise à jour de sécurité pour Windows XP (KB946648)-->"C:\WINDOWS\$NtUninstallKB946648$\spuninst\spuninst.exe"
                  Mise à jour de sécurité pour Windows XP (KB950762)-->"C:\WINDOWS\$NtUninstallKB950762$\spuninst\spuninst.exe"
                  Mise à jour de sécurité pour Windows XP (KB950974)-->"C:\WINDOWS\$NtUninstallKB950974$\spuninst\spuninst.exe"
                  Mise à jour de sécurité pour Windows XP (KB951066)-->"C:\WINDOWS\$NtUninstallKB951066$\spuninst\spuninst.exe"
                  Mise à jour de sécurité pour Windows XP (KB951376-v2)-->"C:\WINDOWS\$NtUninstallKB951376-v2$\spuninst\spuninst.exe"
                  Mise à jour de sécurité pour Windows XP (KB951698)-->"C:\WINDOWS\$NtUninstallKB951698$\spuninst\spuninst.exe"
                  Mise à jour de sécurité pour Windows XP (KB951748)-->"C:\WINDOWS\$NtUninstallKB951748$\spuninst\spuninst.exe"
                  Mise à jour de sécurité pour Windows XP (KB952954)-->"C:\WINDOWS\$NtUninstallKB952954$\spuninst\spuninst.exe"
                  Mise à jour de sécurité pour Windows XP (KB954211)-->"C:\WINDOWS\$NtUninstallKB954211$\spuninst\spuninst.exe"
                  Mise à jour de sécurité pour Windows XP (KB954459)-->"C:\WINDOWS\$NtUninstallKB954459$\spuninst\spuninst.exe"
                  Mise à jour de sécurité pour Windows XP (KB954600)-->"C:\WINDOWS\$NtUninstallKB954600$\spuninst\spuninst.exe"
                  Mise à jour de sécurité pour Windows XP (KB955069)-->"C:\WINDOWS\$NtUninstallKB955069$\spuninst\spuninst.exe"
                  Mise à jour de sécurité pour Windows XP (KB956391)-->"C:\WINDOWS\$NtUninstallKB956391$\spuninst\spuninst.exe"
                  Mise à jour de sécurité pour Windows XP (KB956802)-->"C:\WINDOWS\$NtUninstallKB956802$\spuninst\spuninst.exe"
                  Mise à jour de sécurité pour Windows XP (KB956803)-->"C:\WINDOWS\$NtUninstallKB956803$\spuninst\spuninst.exe"
                  Mise à jour de sécurité pour Windows XP (KB956841)-->"C:\WINDOWS\$NtUninstallKB956841$\spuninst\spuninst.exe"
                  Mise à jour de sécurité pour Windows XP (KB957097)-->"C:\WINDOWS\$NtUninstallKB957097$\spuninst\spuninst.exe"
                  Mise à jour de sécurité pour Windows XP (KB958215)-->"C:\WINDOWS\$NtUninstallKB958215$\spuninst\spuninst.exe"
                  Mise à jour de sécurité pour Windows XP (KB958644)-->"C:\WINDOWS\$NtUninstallKB958644$\spuninst\spuninst.exe"
                  Mise à jour de sécurité pour Windows XP (KB958687)-->"C:\WINDOWS\$NtUninstallKB958687$\spuninst\spuninst.exe"
                  Mise à jour de sécurité pour Windows XP (KB960714)-->"C:\WINDOWS\$NtUninstallKB960714$\spuninst\spuninst.exe"
                  Mise à jour de sécurité pour Windows XP (KB960715)-->"C:\WINDOWS\$NtUninstallKB960715$\spuninst\spuninst.exe"
                  Mise à jour pour Windows XP (KB951978)-->"C:\WINDOWS\$NtUninstallKB951978$\spuninst\spuninst.exe"
                  Mise à jour pour Windows XP (KB955839)-->"C:\WINDOWS\$NtUninstallKB955839$\spuninst\spuninst.exe"
                  Mise à jour pour Windows XP (KB967715)-->"C:\WINDOWS\$NtUninstallKB967715$\spuninst\spuninst.exe"
                  mIWA-->MsiExec.exe /I{3E9D596A-61D4-4239-BD19-2DB984D2A16F}
                  mLogView-->MsiExec.exe /I{0E2B0B41-7E08-4F9F-B21F-41C4133F43B7}
                  mMHouse-->MsiExec.exe /I{F0BFC7EF-9CF8-44EE-91B0-158884CD87C5}
                  Mozilla Firefox (3.0.6)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
                  mPfMgr-->MsiExec.exe /I{8B928BA1-EDEC-4227-A2DA-DD83026C36F5}
                  mPfWiz-->MsiExec.exe /I{90B0D222-8C21-4B35-9262-53B042F18AF9}
                  mProSafe-->MsiExec.exe /I{23FB368F-1399-4EAC-817C-4B83ECBE3D83}
                  MSVCRT-->MsiExec.exe /I{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}
                  MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
                  mWlsSafe-->MsiExec.exe /I{FCA651F3-5BDA-4DDA-9E4A-5D87D6914CC4}
                  mXML-->MsiExec.exe /I{9CC89556-3578-48DD-8408-04E66EBEF401}
                  mZConfig-->MsiExec.exe /I{94658027-9F16-4509-BBD7-A59FE57C3023}
                  Navilog1 3.7.5-->"C:\Program Files\Navilog1\unins000.exe"
                  Nero 7 Demo-->MsiExec.exe /I{C93369CB-B4E9-E095-9289-E6B5AE941036}
                  Outil de diagnostic PC TOSHIBA-->C:\WINDOWS\IsUn040c.exe -f"C:\Program Files\TOSHIBA\PCDiag\Uninst.isu"
                  Outil de téléchargement Windows Live-->MsiExec.exe /I{205C6BDD-7B73-42DE-8505-9A093F35A238}
                  PDFCreator-->MsiExec.exe /I{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}
                  R for Windows 2.8.1-->"C:\Program Files\R\R-2.8.1\unins000.exe"
                  Real Alternative 1.9.0-->"C:\Program Files\Real Alternative\unins000.exe"
                  Realtek High Definition Audio Driver-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}\Setup.exe" -l0x40c -removeonly
                  Réducteur de bruit lect. CD/DVD-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{9FE35071-CAB2-4E79-93E7-BFC6A2DC5C5D}\Setup.exe" -l0x40c
                  Security Update for 2007 Microsoft Office System (KB951550)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {B243E9A5-ED77-4F1B-B338-2486FD82DC85}
                  Security Update for 2007 Microsoft Office System (KB951944)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {797AE457-BA17-4BBC-B501-25FB3A0103C7}
                  Security Update for 2007 Microsoft Office System (KB958439)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {6491B8AA-D11C-4648-A461-6234B31EB7E2}
                  Security Update for CAPICOM (KB931906)-->MsiExec.exe /I{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
                  Security Update for CAPICOM (KB931906)-->MsiExec.exe /X{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
                  Security Update for Microsoft Office Excel 2007 (KB958437)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {648FC016-2D6B-4A16-8D87-404533642F4B}
                  Security Update for Microsoft Office PowerPoint 2007 (KB951338)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {558B709B-821B-4FC5-90FC-9A8890641E77}
                  Security Update for Microsoft Office Publisher 2007 (KB950114)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {F9C3CDBA-1F00-4D4D-959D-75C9D3ACDD85}
                  Security Update for Microsoft Office system 2007 (KB954326)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {5F7F6FFF-395D-480E-8450-64F385D82C5F}
                  Security Update for Microsoft Office system 2007 (KB956828)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {885E081B-72BD-4E76-8E98-30B4BE468FAC}
                  Security Update for Microsoft Office Word 2007 (KB956358)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {4551666D-0FD6-4C69-8A81-1C6F2E64517C}
                  Segoe UI-->MsiExec.exe /I{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}
                  Skype™ 3.8-->MsiExec.exe /X{5C82DAE5-6EB0-4374-9254-BE3319BA4E82}
                  Son virtuel TOSHIBA-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{8B12BA86-ADAC-4BA6-B441-FFC591087252}\Setup.exe" /uninstall
                  Sonic DLA-->MsiExec.exe /I{1206EF92-2E83-4859-ACCB-2048C3CB7DA6}
                  Sonic RecordNow!-->MsiExec.exe /I{9541FED0-327F-4DF0-8B96-EF57EF622F19}
                  SuperCopier2-->"C:\Program Files\SuperCopier2\SC2Uninst.exe"
                  Synaptics Pointing Device Driver-->rundll32.exe "C:\Program Files\Synaptics\SynTP\SynISDLL.dll",standAloneUninstall
                  Texas Instruments PCIxx21/x515/xx12 drivers.-->C:\PROGRA~1\FICHIE~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{4497AFF6-98C4-4F49-B073-F48F42BCBF9E} /l1036
                  TOSHIBA ConfigFree-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{BDD83DC9-BEE9-4654-A5DA-CC46C250088D}\setup.exe" -l0x40c UNINSTALL
                  TOSHIBA Hotkey Utility-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{64DD71BC-3109-4C88-9AD3-D5422644B722}\setup.exe" -l0x40c
                  TOSHIBA Software Modem-->Tosmreg -U
                  TOSHIBA TouchPad ON/Off Utility-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{69BE47C2-36FE-4397-8199-85D8EAE69982}\setup.exe" -l0x40c
                  TOSHIBA Utilities-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{78C68CB9-3DF5-44F3-AB9D-FA305C5EB85C}\setup.exe" -l0x40c
                  Update for Microsoft Office Outlook 2007 (KB952142)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {4AD3A076-427C-491F-A5B7-7D1DE788A756}
                  Update for Office 2007 (KB946691)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {A420F522-7395-4872-9882-C591B4B92278}
                  Update for Outlook 2007 Junk Email Filter (kb959634)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {50C77E2F-5C1C-467D-9BC8-3CA07D28C9F2}
                  Utilitaire de zoom TOSHIBA-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{64212898-097F-4F3F-AECA-6D34A7EF82DF}\Setup.exe" -l0x40c
                  VGA USB Camera-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{1DDF840B-A50A-491E-BF44-6D6964C451A8}\Setup.exe" -l0x40c
                  VideoLAN VLC media player 0.8.6d-->C:\Program Files\VideoLAN\VLC\uninstall.exe
                  Visual C++ 2008 x86 Runtime - (v9.0.30729)-->MsiExec.exe /X{F333A33D-125C-32A2-8DCE-5C5D14231E27}
                  Visual C++ 2008 x86 Runtime - v9.0.30729.01-->C:\WINDOWS\system32\msiexec.exe /x {F333A33D-125C-32A2-8DCE-5C5D14231E27} /qb+ REBOOTPROMPT=""
                  VobSub v2.23 (Remove Only)-->"C:\Program Files\Gabest\VobSub\uninstall.exe"
                  Windows Internet Explorer 7-->"C:\WINDOWS\ie7\spuninst\spuninst.exe"
                  Windows Live Call-->MsiExec.exe /I{82C7B308-0BDD-49D8-8EA5-9CD3A3F9DF41}
                  Windows Live Communications Platform-->MsiExec.exe /I{3B4E636E-9D65-4D67-BA61-189800823F52}
                  Windows Live Messenger-->MsiExec.exe /X{059C042E-796A-4ACC-A81A-ECC2010BB78C}
                  Windows Media Format Runtime-->"C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll
                  Windows XP Service Pack 3-->"C:\WINDOWS\$NtServicePackUninstall$\spuninst\spuninst.exe"

                  =====HijackThis Backups=====

                  O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)

                  ======Security center information======

                  AV: AVG Anti-Virus
                  AV: Lavasoft Ad-Watch Live! AntiVirus

                  System event log

                  Computer Name: MIDOO
                  Event Code: 7036
                  Message: Le service Carte de performance WMI est entré dans l'état : arrêté.

                  Record Number: 2361
                  Source Name: Service Control Manager
                  Time Written: 20090226073204.000000+060
                  Event Type: Informations
                  User:

                  Computer Name: MIDOO
                  Event Code: 18
                  Message: Prêt pour l'installation : les mises à jour suivantes ont été téléchargées et sont prêtes pour l'installation. L'installation de ces mises à jour est actuellement planifiée pour le ?jeudi ?26 ?février ?2009 à 20:00 :
                  - Mise à jour de Microsoft Silverlight (KB960353)

                  Record Number: 2360
                  Source Name: Windows Update Agent
                  Time Written: 20090226073019.000000+060
                  Event Type: Informations
                  User:

                  Computer Name: MIDOO
                  Event Code: 7035
                  Message: Un contrôle Démarrer a correctement été envoyé au service Carte de performance WMI.

                  Record Number: 2359
                  Source Name: Service Control Manager
                  Time Written: 20090226072959.000000+060
                  Event Type: Informations
                  User: MIDOO\Ahmed

                  Computer Name: MIDOO
                  Event Code: 7036
                  Message: Le service Carte de performance WMI est entré dans l'état : en cours d'exécution.

                  Record Number: 2358
                  Source Name: Service Control Manager
                  Time Written: 20090226072959.000000+060
                  Event Type: Informations
                  User:

                  Computer Name: MIDOO
                  Event Code: 4201
                  Message: Le système a détecté que la carte réseau \DEVICE\TCPIP_{2D021112-4044-45E6-BFC3-EA86012989AE} était connectée au réseau,
                  et a lancé une opération normale sur la carte réseau.

                  Record Number: 2357
                  Source Name: Tcpip
                  Time Written: 20090226072903.000000+060
                  Event Type: Informations
                  User:

                  Application event log

                  Computer Name: MIDOO
                  Event Code: 4097
                  Message: L'application, C:\WINDOWS\system32\wuauclt.exe, a généré une erreur d'application
                  L'erreur s'est produite le 02/04/2009 à 00:37:11.765
                  L'exception générée était c0000005 à l'adresse 7C883001 (kernel32)

                  Record Number: 212
                  Source Name: DrWatson
                  Time Written: 20090204003711.000000+060
                  Event Type: Informations
                  User:

                  Computer Name: MIDOO
                  Event Code: 4097
                  Message: L'application, C:\Program Files\Skype\Phone\Skype.exe, a généré une erreur d'application
                  L'erreur s'est produite le 02/04/2009 à 00:37:11.187
                  L'exception générée était c0000005 à l'adresse 7C88300C (kernel32)

                  Record Number: 211
                  Source Name: DrWatson
                  Time Written: 20090204003711.000000+060
                  Event Type: Informations
                  User:

                  Computer Name: MIDOO
                  Event Code: 1000
                  Message: Application défaillante jusched.exe, version 6.0.60.2, module défaillant kernel32.dll, version 5.1.2600.2180, adresse de défaillance 0x0008300c.

                  Record Number: 210
                  Source Name: Application Error
                  Time Written: 20090204003710.000000+060
                  Event Type: erreur
                  User:

                  Computer Name: MIDOO
                  Event Code: 4097
                  Message: L'application, C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe, a généré une erreur d'application
                  L'erreur s'est produite le 02/04/2009 à 00:37:10.265
                  L'exception générée était c0000005 à l'adresse 7C883001 (kernel32)

                  Record Number: 209
                  Source Name: DrWatson
                  Time Written: 20090204003710.000000+060
                  Event Type: Informations
                  User:

                  Computer Name: MIDOO
                  Event Code: 1002
                  Message: L'environnement s'est arrêté de façon inattendue et Explorer.exe a redémarré.

                  Record Number: 208
                  Source Name: Winlogon
                  Time Written: 20090204003710.000000+060
                  Event Type: Informations
                  User:

                  ======Environment variables======

                  "ComSpec"=%SystemRoot%\system32\cmd.exe
                  "Path"=%systemroot%\system32;%systemroot%;%systemroot%\system32\wbem;C:\Program Files\ATI Technologies\ATI.ACE
                  "windir"=%SystemRoot%
                  "FP_NO_HOST_CHECK"=NO
                  "OS"=Windows_NT
                  "PROCESSOR_ARCHITECTURE"=x86
                  "PROCESSOR_LEVEL"=6
                  "PROCESSOR_IDENTIFIER"=x86 Family 6 Model 14 Stepping 8, GenuineIntel
                  "PROCESSOR_REVISION"=0e08
                  "NUMBER_OF_PROCESSORS"=2
                  "PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
                  "TEMP"=%SystemRoot%\TEMP
                  "TMP"=%SystemRoot%\TEMP

                  -----------------EOF-----------------
                  0
                  1. Modérateur
                    Peux-tu me poster le rapport info qui se trouve dans C:\rsit ?

                    ---> Désactive ton antivirus le temps de la manipulation car OTMoveIt3 est détecté comme une infection à tort.

                    ---> Télécharge OTMoveIt3 (OldTimer) sur ton Bureau.

                    ---> Double-clique sur OTMoveIt3.exe afin de le lancer.

                    ---> Copie (Ctrl+C) le texte suivant ci-dessous :

                    :processes
                    explorer.exe

                    :reg
                    [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WindowsTelephony]
                    [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WindowsTelephony]

                    :commands
                    [purity]
                    [emptytemp]
                    [reboot]

                    ---> Colle (Ctrl+V) le texte précédemment copié dans le cadre Paste Instructions for Items to be Moved.

                    ---> Clique maintenant sur le bouton MoveIt! puis ferme OTMoveIt3.

                    Si un fichier ou dossier ne peut pas être supprimé immédiatement, le logiciel te demandera de redémarrer.
                    Accepte en cliquant sur YES.

                    ---> Poste le rapport situé dans ce dossier : C:\_OTMoveIt\MovedFiles\
                    Le nom du rapport correspond au moment de sa création : date_heure.log
                    0
                    1. Bonjour

                      log.txt

                      Logfile of random's system information tool 1.05 (written by random/random)
                      Run by Ahmed at 2009-03-04 07:17:14
                      Microsoft Windows XP Édition familiale Service Pack 3
                      System drive C: has 39 GB (41%) free of 95 GB
                      Total RAM: 2046 MB (58% free)

                      Logfile of Trend Micro HijackThis v2.0.2
                      Scan saved at 07:17:23, on 04/03/2009
                      Platform: Windows XP SP3 (WinNT 5.01.2600)
                      MSIE: Internet Explorer v7.00 (7.00.6000.16791)
                      Boot mode: Normal

                      Running processes:
                      C:\WINDOWS\System32\smss.exe
                      C:\WINDOWS\system32\winlogon.exe
                      C:\WINDOWS\system32\services.exe
                      C:\WINDOWS\system32\lsass.exe
                      C:\WINDOWS\system32\Ati2evxx.exe
                      C:\WINDOWS\system32\svchost.exe
                      C:\WINDOWS\System32\svchost.exe
                      C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
                      C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
                      C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
                      C:\WINDOWS\system32\spoolsv.exe
                      C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
                      C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
                      C:\WINDOWS\system32\Ati2evxx.exe
                      C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
                      C:\WINDOWS\system32\svchost.exe
                      C:\WINDOWS\Explorer.EXE
                      C:\Program Files\Toshiba\TOSHIBA Applet\TAPPSRV.exe
                      C:\PROGRA~1\AVG\AVG8\avgam.exe
                      C:\PROGRA~1\AVG\AVG8\avgrsx.exe
                      C:\PROGRA~1\AVG\AVG8\avgnsx.exe
                      C:\WINDOWS\system32\TDispVol.exe
                      C:\WINDOWS\System32\DLA\DLACTRLW.EXE
                      C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
                      C:\Program Files\TOSHIBA\Utilitaire de zoom TOSHIBA\SmoothView.exe
                      C:\Program Files\TOSHIBA\Tvs\TvsTray.exe
                      C:\WINDOWS\system32\TPSMain.exe
                      C:\Program Files\Toshiba\Toshiba Applet\thotkey.exe
                      C:\Program Files\TOSHIBA\Commandes TOSHIBA\TFncKy.exe
                      C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                      C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe
                      C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
                      C:\WINDOWS\AGRSMMSG.exe
                      C:\WINDOWS\PixArt\PAC7311\Monitor.exe
                      C:\Program Files\Synaptics\SynTP\Toshiba.exe
                      C:\PROGRA~1\AVG\AVG8\avgtray.exe
                      C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe
                      C:\WINDOWS\system32\ctfmon.exe
                      C:\Program Files\Internet Download Manager\IDMan.exe
                      C:\WINDOWS\system32\TPSBattM.exe
                      C:\Program Files\Skype\Phone\Skype.exe
                      C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                      C:\Program Files\Internet Download Manager\IEMonitor.exe
                      C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
                      C:\Program Files\Messenger\msmsgs.exe
                      C:\Program Files\Fichiers communs\Ahead\lib\NMBgMonitor.exe
                      C:\Program Files\Skype\Plugin Manager\skypePM.exe
                      C:\Program Files\Windows Live\Contacts\wlcomm.exe
                      C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
                      C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
                      C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
                      C:\Program Files\Mozilla Firefox\firefox.exe
                      C:\Documents and Settings\Ahmed\Bureau\virus_softwares\RSIT.exe
                      C:\Program Files\Trend Micro\HijackThis\Ahmed.exe

                      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
                      R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://support.norton.com/sp/fr/fr/home/current/solutions/kb20090121104844EN?abproduct=SymNRT&abversion=2009.0.0.41&build=Symantec&ced=true&entsrc=CED_pubweb&error=0&module=2009&src=_mi
                      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                      O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files\Internet Download Manager\IDMIECC.dll
                      O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
                      O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
                      O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
                      O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
                      O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                      O4 - HKLM\..\Run: [TDispVol] TDispVol.exe
                      O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE
                      O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
                      O4 - HKLM\..\Run: [SmoothView] C:\Program Files\TOSHIBA\Utilitaire de zoom TOSHIBA\SmoothView.exe
                      O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
                      O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
                      O4 - HKLM\..\Run: [Tvs] C:\Program Files\TOSHIBA\Tvs\TvsTray.exe
                      O4 - HKLM\..\Run: [TPSMain] TPSMain.exe
                      O4 - HKLM\..\Run: [THotkey] C:\Program Files\Toshiba\Toshiba Applet\thotkey.exe
                      O4 - HKLM\..\Run: [TFncKy] TFncKy.exe
                      O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                      O4 - HKLM\..\Run: [NDSTray.exe] NDSTray.exe
                      O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
                      O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
                      O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
                      O4 - HKLM\..\Run: [Monitor] C:\WINDOWS\PixArt\PAC7311\Monitor.exe
                      O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
                      O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe"
                      O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
                      O4 - HKCU\..\Run: [IDMan] C:\Program Files\Internet Download Manager\IDMan.exe /onboot
                      O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
                      O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
                      O4 - HKCU\..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
                      O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
                      O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Ahead\lib\NMBgMonitor.exe"
                      O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
                      O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
                      O8 - Extra context menu item: Download all links with IDM - C:\Program Files\Internet Download Manager\IEGetAll.htm
                      O8 - Extra context menu item: Download FLV video content with IDM - C:\Program Files\Internet Download Manager\IEGetVL.htm
                      O8 - Extra context menu item: Download with IDM - C:\Program Files\Internet Download Manager\IEExt.htm
                      O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
                      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
                      O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
                      O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
                      O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                      O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                      O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - https://www.kaspersky.fr/?domain=webscanner.kaspersky.fr
                      O17 - HKLM\System\CCS\Services\Tcpip\..\{F34E8A4D-DA5A-4E87-9352-87D82CF4FE91}: NameServer = 193.95.66.10
                      O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
                      O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
                      O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
                      O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
                      O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
                      O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
                      O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
                      O23 - Service: Google Desktop Manager 5.8.809.23506 (GoogleDesktopManager-092308-165331) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
                      O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
                      O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
                      O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
                      O23 - Service: TOSHIBA Application Service (TAPPSRV) - TOSHIBA Corp. - C:\Program Files\Toshiba\TOSHIBA Applet\TAPPSRV.exe
                      0
                      1. Modérateur
                        Réessaie cette manip' :

                        --> Télécharge Random's System Information Tool (RSIT) (par random/random) sur ton Bureau.

                        --> Double-clique sur RSIT.exe afin de lancer le programme.
                        (Sous Vista, il faut cliquer droit sur RSIT.exe et choisir Exécuter en tant qu'administrateur)

                        --> Clique sur Continue à l'écran Disclaimer.

                        --> Si l'outil HijackThis (version à jour) n'est pas présent ou non détecté sur l'ordinateur, RSIT le téléchargera (autorise l'accès dans ton pare-feu, si demandé) et tu devras accepter la licence.

                        --> Lorsque l'analyse sera terminée, deux fichiers texte s'ouvriront. Poste le contenu de log.txt (c'est celui qui apparaît à l'écran) ainsi que de info.txt (que tu verras dans la barre des tâches).

                        Note : les rapports sont sauvegardés dans le dossier C:\rsit.
                        0
                        1. Bonjour Destrio5,

                          j'ai fait tt ce k tu m'as demande de faire. qu'est ce k j peu faire apres

                          merci bien
                          0
                          1. Contributeur sécurité
                            Bonjour,

                            non, je te le laisse.

                            Je voulais seulement que tu saches.
                            0
                            1. Modérateur
                              Merci Lyonnais92.

                              Tu t'en occupes ou non ?
                              0
                              1. -------------------------------------------------------------------------------
                                KASPERSKY ON-LINE SCANNER REPORT
                                Tuesday, March 03, 2009 7:01:13 AM
                                Système d'exploitation : Microsoft Windows XP Home Edition, Service Pack 3 (Build 2600)
                                Kaspersky On-line Scanner version : 5.0.84.2
                                Dernière mise à jour de la base antivirus Kaspersky : 2/03/2009
                                Enregistrements dans la base antivirus Kaspersky : 1682625
                                -------------------------------------------------------------------------------

                                Paramètres d'analyse:
                                Analyser avec la base antivirus suivante: standard
                                Analyser les archives: vrai
                                Analyser les bases de messagerie: vrai

                                Cible de l'analyse - Poste de travail:
                                C:\
                                D:\

                                Statistiques de l'analyse:
                                Total d'objets analysés: 82629
                                Nombre de virus trouvés: 1
                                Nombre d'objets infectés: 2 / 0
                                Nombre d'objets suspects: 0
                                Durée de l'analyse: 02:03:10

                                Nom de l'objet infecté / Nom du virus / Dernière action
                                C:\Documents and Settings\Ahmed\Application Data\Mozilla\Firefox\Profiles\xbksflkg.default\cert8.db L'objet est verrouillé ignoré
                                C:\Documents and Settings\Ahmed\Application Data\Mozilla\Firefox\Profiles\xbksflkg.default\content-prefs.sqlite L'objet est verrouillé ignoré
                                C:\Documents and Settings\Ahmed\Application Data\Mozilla\Firefox\Profiles\xbksflkg.default\cookies.sqlite L'objet est verrouillé ignoré
                                C:\Documents and Settings\Ahmed\Application Data\Mozilla\Firefox\Profiles\xbksflkg.default\downloads.sqlite L'objet est verrouillé ignoré
                                C:\Documents and Settings\Ahmed\Application Data\Mozilla\Firefox\Profiles\xbksflkg.default\flashgot.log L'objet est verrouillé ignoré
                                C:\Documents and Settings\Ahmed\Application Data\Mozilla\Firefox\Profiles\xbksflkg.default\formhistory.sqlite L'objet est verrouillé ignoré
                                C:\Documents and Settings\Ahmed\Application Data\Mozilla\Firefox\Profiles\xbksflkg.default\key3.db L'objet est verrouillé ignoré
                                C:\Documents and Settings\Ahmed\Application Data\Mozilla\Firefox\Profiles\xbksflkg.default\parent.lock L'objet est verrouillé ignoré
                                C:\Documents and Settings\Ahmed\Application Data\Mozilla\Firefox\Profiles\xbksflkg.default\permissions.sqlite L'objet est verrouillé ignoré
                                C:\Documents and Settings\Ahmed\Application Data\Mozilla\Firefox\Profiles\xbksflkg.default\places.sqlite L'objet est verrouillé ignoré
                                C:\Documents and Settings\Ahmed\Application Data\Mozilla\Firefox\Profiles\xbksflkg.default\places.sqlite-journal L'objet est verrouillé ignoré
                                C:\Documents and Settings\Ahmed\Application Data\Mozilla\Firefox\Profiles\xbksflkg.default\search.sqlite L'objet est verrouillé ignoré
                                C:\Documents and Settings\Ahmed\Application Data\Mozilla\Firefox\Profiles\xbksflkg.default\StumbleUpon\user6870947.sqlite L'objet est verrouillé ignoré
                                C:\Documents and Settings\Ahmed\Application Data\Skype\midoo.the.best\call256.dbb L'objet est verrouillé ignoré
                                C:\Documents and Settings\Ahmed\Application Data\Skype\midoo.the.best\callmember256.dbb L'objet est verrouillé ignoré
                                C:\Documents and Settings\Ahmed\Application Data\Skype\midoo.the.best\chat512.dbb L'objet est verrouillé ignoré
                                C:\Documents and Settings\Ahmed\Application Data\Skype\midoo.the.best\chatmember256.dbb L'objet est verrouillé ignoré
                                C:\Documents and Settings\Ahmed\Application Data\Skype\midoo.the.best\chatmsg1024.dbb L'objet est verrouillé ignoré
                                C:\Documents and Settings\Ahmed\Application Data\Skype\midoo.the.best\chatmsg256.dbb L'objet est verrouillé ignoré
                                C:\Documents and Settings\Ahmed\Application Data\Skype\midoo.the.best\chatmsg512.dbb L'objet est verrouillé ignoré
                                C:\Documents and Settings\Ahmed\Application Data\Skype\midoo.the.best\contactgroup1024.dbb L'objet est verrouillé ignoré
                                C:\Documents and Settings\Ahmed\Application Data\Skype\midoo.the.best\contactgroup256.dbb L'objet est verrouillé ignoré
                                C:\Documents and Settings\Ahmed\Application Data\Skype\midoo.the.best\dyncontent\bundle.dat L'objet est verrouillé ignoré
                                C:\Documents and Settings\Ahmed\Application Data\Skype\midoo.the.best\index2.dat L'objet est verrouillé ignoré
                                C:\Documents and Settings\Ahmed\Application Data\Skype\midoo.the.best\main.lock L'objet est verrouillé ignoré
                                C:\Documents and Settings\Ahmed\Application Data\Skype\midoo.the.best\profile16384.dbb L'objet est verrouillé ignoré
                                C:\Documents and Settings\Ahmed\Application Data\Skype\midoo.the.best\transfer256.dbb L'objet est verrouillé ignoré
                                C:\Documents and Settings\Ahmed\Application Data\Skype\midoo.the.best\transfer512.dbb L'objet est verrouillé ignoré
                                C:\Documents and Settings\Ahmed\Application Data\Skype\midoo.the.best\user1024.dbb L'objet est verrouillé ignoré
                                C:\Documents and Settings\Ahmed\Application Data\Skype\midoo.the.best\user16384.dbb L'objet est verrouillé ignoré
                                C:\Documents and Settings\Ahmed\Application Data\Skype\midoo.the.best\user256.dbb L'objet est verrouillé ignoré
                                C:\Documents and Settings\Ahmed\Application Data\Skype\midoo.the.best\user32768.dbb L'objet est verrouillé ignoré
                                C:\Documents and Settings\Ahmed\Application Data\Skype\midoo.the.best\user4096.dbb L'objet est verrouillé ignoré
                                C:\Documents and Settings\Ahmed\Application Data\Skype\midoo.the.best\voicemail256.dbb L'objet est verrouillé ignoré
                                C:\Documents and Settings\Ahmed\Cookies\index.dat L'objet est verrouillé ignoré
                                C:\Documents and Settings\Ahmed\Local Settings\Application Data\ApplicationHistory\cli.exe.c88dbd71.ini.inuse L'objet est verrouillé ignoré
                                C:\Documents and Settings\Ahmed\Local Settings\Application Data\Google\Google Desktop\967e80d4a96e\dbc2e.ht1 L'objet est verrouillé ignoré
                                C:\Documents and Settings\Ahmed\Local Settings\Application Data\Google\Google Desktop\967e80d4a96e\dbdam L'objet est verrouillé ignoré
                                C:\Documents and Settings\Ahmed\Local Settings\Application Data\Google\Google Desktop\967e80d4a96e\dbdao L'objet est verrouillé ignoré
                                C:\Documents and Settings\Ahmed\Local Settings\Application Data\Google\Google Desktop\967e80d4a96e\dbeam L'objet est verrouillé ignoré
                                C:\Documents and Settings\Ahmed\Local Settings\Application Data\Google\Google Desktop\967e80d4a96e\dbeao L'objet est verrouillé ignoré
                                C:\Documents and Settings\Ahmed\Local Settings\Application Data\Google\Google Desktop\967e80d4a96e\dbm L'objet est verrouillé ignoré
                                C:\Documents and Settings\Ahmed\Local Settings\Application Data\Google\Google Desktop\967e80d4a96e\dbu2d.ht1 L'objet est verrouillé ignoré
                                C:\Documents and Settings\Ahmed\Local Settings\Application Data\Google\Google Desktop\967e80d4a96e\dbvm.cf1 L'objet est verrouillé ignoré
                                C:\Documents and Settings\Ahmed\Local Settings\Application Data\Google\Google Desktop\967e80d4a96e\dbvmh.ht1 L'objet est verrouillé ignoré
                                C:\Documents and Settings\Ahmed\Local Settings\Application Data\Google\Google Desktop\967e80d4a96e\fii.cf1 L'objet est verrouillé ignoré
                                C:\Documents and Settings\Ahmed\Local Settings\Application Data\Google\Google Desktop\967e80d4a96e\fiih.ht1 L'objet est verrouillé ignoré
                                C:\Documents and Settings\Ahmed\Local Settings\Application Data\Google\Google Desktop\967e80d4a96e\fim1i.cf1 L'objet est verrouillé ignoré
                                C:\Documents and Settings\Ahmed\Local Settings\Application Data\Google\Google Desktop\967e80d4a96e\fim1ih.ht1 L'objet est verrouillé ignoré
                                C:\Documents and Settings\Ahmed\Local Settings\Application Data\Google\Google Desktop\967e80d4a96e\hp L'objet est verrouillé ignoré
                                C:\Documents and Settings\Ahmed\Local Settings\Application Data\Google\Google Desktop\967e80d4a96e\hpt2i.ht1 L'objet est verrouillé ignoré
                                C:\Documents and Settings\Ahmed\Local Settings\Application Data\Google\Google Desktop\967e80d4a96e\rpm.cf1 L'objet est verrouillé ignoré
                                C:\Documents and Settings\Ahmed\Local Settings\Application Data\Google\Google Desktop\967e80d4a96e\rpm1m.cf1 L'objet est verrouillé ignoré
                                C:\Documents and Settings\Ahmed\Local Settings\Application Data\Google\Google Desktop\967e80d4a96e\rpm1mh.ht1 L'objet est verrouillé ignoré
                                C:\Documents and Settings\Ahmed\Local Settings\Application Data\Google\Google Desktop\967e80d4a96e\rpmh.ht1 L'objet est verrouillé ignoré
                                C:\Documents and Settings\Ahmed\Local Settings\Application Data\Google\Google Desktop\967e80d4a96e\safeweb\goog-black-enchashm.cf1 L'objet est verrouillé ignoré
                                C:\Documents and Settings\Ahmed\Local Settings\Application Data\Google\Google Desktop\967e80d4a96e\safeweb\goog-black-enchashmh.ht1 L'objet est verrouillé ignoré
                                C:\Documents and Settings\Ahmed\Local Settings\Application Data\Google\Google Desktop\967e80d4a96e\safeweb\goog-black-urlm.cf1 L'objet est verrouillé ignoré
                                C:\Documents and Settings\Ahmed\Local Settings\Application Data\Google\Google Desktop\967e80d4a96e\safeweb\goog-black-urlmh.ht1 L'objet est verrouillé ignoré
                                C:\Documents and Settings\Ahmed\Local Settings\Application Data\Google\Google Desktop\967e80d4a96e\safeweb\goog-malware-domainm.cf1 L'objet est verrouillé ignoré
                                C:\Documents and Settings\Ahmed\Local Settings\Application Data\Google\Google Desktop\967e80d4a96e\safeweb\goog-malware-domainmh.ht1 L'objet est verrouillé ignoré
                                C:\Documents and Settings\Ahmed\Local Settings\Application Data\Google\Google Desktop\967e80d4a96e\safeweb\goog-white-domainm.cf1 L'objet est verrouillé ignoré
                                C:\Documents and Settings\Ahmed\Local Settings\Application Data\Google\Google Desktop\967e80d4a96e\safeweb\goog-white-domainmh.ht1 L'objet est verrouillé ignoré
                                C:\Documents and Settings\Ahmed\Local Settings\Application Data\Microsoft\Messenger\ContactsLog.txt L'objet est verrouillé ignoré
                                C:\Documents and Settings\Ahmed\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat L'objet est verrouillé ignoré
                                C:\Documents and Settings\Ahmed\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG L'objet est verrouillé ignoré
                                C:\Documents and Settings\Ahmed\Local Settings\Application Data\Microsoft\Windows Live Contacts\{a9035d68-690d-4586-b892-9abff8b3d402}\DBStore\contacts.edb L'objet est verrouillé ignoré
                                C:\Documents and Settings\Ahmed\Local Settings\Application Data\Microsoft\Windows Live Contacts\{a9035d68-690d-4586-b892-9abff8b3d402}\DBStore\LogFiles\edb.log L'objet est verrouillé ignoré
                                C:\Documents and Settings\Ahmed\Local Settings\Application Data\Microsoft\Windows Live Contacts\{a9035d68-690d-4586-b892-9abff8b3d402}\DBStore\LogFiles\edbtmp.log L'objet est verrouillé ignoré
                                C:\Documents and Settings\Ahmed\Local Settings\Application Data\Microsoft\Windows Live Contacts\{a9035d68-690d-4586-b892-9abff8b3d402}\DBStore\tempedb.edb L'objet est verrouillé ignoré
                                C:\Documents and Settings\Ahmed\Local Settings\Application Data\Microsoft\Windows Live Contacts\{e4e08a6a-38e8-46c9-a345-c2dcdced9177}\DBStore\contacts.edb L'objet est verrouillé ignoré
                                C:\Documents and Settings\Ahmed\Local Settings\Application Data\Microsoft\Windows Live Contacts\{e4e08a6a-38e8-46c9-a345-c2dcdced9177}\DBStore\LogFiles\edb.log L'objet est verrouillé ignoré
                                C:\Documents and Settings\Ahmed\Local Settings\Application Data\Microsoft\Windows Live Contacts\{e4e08a6a-38e8-46c9-a345-c2dcdced9177}\DBStore\LogFiles\edbtmp.log L'objet est verrouillé ignoré
                                C:\Documents and Settings\Ahmed\Local Settings\Application Data\Microsoft\Windows Live Contacts\{e4e08a6a-38e8-46c9-a345-c2dcdced9177}\DBStore\tempedb.edb L'objet est verrouillé ignoré
                                C:\Documents and Settings\Ahmed\Local Settings\Application Data\Mozilla\Firefox\Profiles\xbksflkg.default\Cache\_CACHE_001_ L'objet est verrouillé ignoré
                                C:\Documents and Settings\Ahmed\Local Settings\Application Data\Mozilla\Firefox\Profiles\xbksflkg.default\Cache\_CACHE_002_ L'objet est verrouillé ignoré
                                C:\Documents and Settings\Ahmed\Local Settings\Application Data\Mozilla\Firefox\Profiles\xbksflkg.default\Cache\_CACHE_003_ L'objet est verrouillé ignoré
                                C:\Documents and Settings\Ahmed\Local Settings\Application Data\Mozilla\Firefox\Profiles\xbksflkg.default\Cache\_CACHE_MAP_ L'objet est verrouillé ignoré
                                C:\Documents and Settings\Ahmed\Local Settings\Application Data\Mozilla\Firefox\Profiles\xbksflkg.default\urlclassifier3.sqlite L'objet est verrouillé ignoré
                                C:\Documents and Settings\Ahmed\Local Settings\Historique\History.IE5\index.dat L'objet est verrouillé ignoré
                                C:\Documents and Settings\Ahmed\Local Settings\Historique\History.IE5\MSHist012009030220090303\index.dat L'objet est verrouillé ignoré
                                C:\Documents and Settings\Ahmed\Local Settings\temp\etilqs_Omr6T8Wn0mQ859iyLS4p L'objet est verrouillé ignoré
                                C:\Documents and Settings\Ahmed\Local Settings\temp\Perflib_Perfdata_63c.dat L'objet est verrouillé ignoré
                                C:\Documents and Settings\Ahmed\Local Settings\temp\Perflib_Perfdata_904.dat L'objet est verrouillé ignoré
                                C:\Documents and Settings\Ahmed\Local Settings\temp\Perflib_Perfdata_9c8.dat L'objet est verrouillé ignoré
                                C:\Documents and Settings\Ahmed\Local Settings\temp\~DF14B1.tmp L'objet est verrouillé ignoré
                                C:\Documents and Settings\Ahmed\Local Settings\temp\~DFCBB7.tmp L'objet est verrouillé ignoré
                                C:\Documents and Settings\Ahmed\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat L'objet est verrouillé ignoré
                                C:\Documents and Settings\Ahmed\Local Settings\Temporary Internet Files\Content.IE5\index.dat L'objet est verrouillé ignoré
                                C:\Documents and Settings\Ahmed\Mes documents\Downloads\Programs\Eview5.1FullStandard.rar/Eview5.1FullStandard/Eview5.1FullStandard/Eviews_key/Eviews_key.exe Infecté : Trojan.Win32.Genome.hqg ignoré
                                C:\Documents and Settings\Ahmed\Mes documents\Downloads\Programs\Eview5.1FullStandard.rar RAR: infecté - 1 ignoré
                                C:\Documents and Settings\Ahmed\NTUSER.DAT L'objet est verrouillé ignoré
                                C:\Documents and Settings\Ahmed\ntuser.dat.LOG L'objet est verrouillé ignoré
                                C:\Documents and Settings\Ahmed\Tracing\WindowsLiveMessenger-uccapi-0.uccapilog L'objet est verrouillé ignoré
                                C:\Documents and Settings\All Users\Application Data\avg8\AvgAm\avgam.lck L'objet est verrouillé ignoré
                                C:\Documents and Settings\All Users\Application Data\avg8\Log\avgam.log L'objet est verrouillé ignoré
                                C:\Documents and Settings\All Users\Application Data\avg8\Log\avgcfg.log L'objet est verrouillé ignoré
                                C:\Documents and Settings\All Users\Application Data\avg8\Log\avgcore.log L'objet est verrouillé ignoré
                                C:\Documents and Settings\All Users\Application Data\avg8\Log\avgldr.log L'objet est verrouillé ignoré
                                C:\Documents and Settings\All Users\Application Data\avg8\Log\avglng.log L'objet est verrouillé ignoré
                                C:\Documents and Settings\All Users\Application Data\avg8\Log\avgns.log L'objet est verrouillé ignoré
                                C:\Documents and Settings\All Users\Application Data\avg8\Log\avgrs.log L'objet est verrouillé ignoré
                                C:\Documents and Settings\All Users\Application Data\avg8\Log\avgsched.log L'objet est verrouillé ignoré
                                C:\Documents and Settings\All Users\Application Data\avg8\Log\avgsrm.log L'objet est verrouillé ignoré
                                C:\Documents and Settings\All Users\Application Data\avg8\Log\avgwd.log L'objet est verrouillé ignoré
                                C:\Documents and Settings\All Users\Application Data\avg8\Log\commonpriv.log L'objet est verrouillé ignoré
                                C:\Documents and Settings\All Users\Application Data\Lavasoft\Ad-Aware\Logs\RP.log L'objet est verrouillé ignoré
                                C:\Documents and Settings\All Users\Application Data\Lavasoft\Ad-Aware\Logs\RPNetwork.log L'objet est verrouillé ignoré
                                C:\Documents and Settings\All Users\Application Data\Lavasoft\Ad-Aware\Logs\RPProcess.log L'objet est verrouillé ignoré
                                C:\Documents and Settings\All Users\Application Data\Lavasoft\Ad-Aware\Logs\RPRegistry.log L'objet est verrouillé ignoré
                                C:\Documents and Settings\All Users\Application Data\Lavasoft\Ad-Aware\Logs\Scan_2009-03-03-00-14-39.log L'objet est verrouillé ignoré
                                C:\Documents and Settings\All Users\Application Data\Lavasoft\Ad-Aware\Logs\Service.log L'objet est verrouillé ignoré
                                C:\Documents and Settings\All Users\Application Data\Lavasoft\Ad-Aware\MiniMessage\2 L'objet est verrouillé ignoré
                                C:\Documents and Settings\LocalService\Cookies\index.dat L'objet est verrouillé ignoré
                                C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat L'objet est verrouillé ignoré
                                C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG L'objet est verrouillé ignoré
                                C:\Documents and Settings\LocalService\Local Settings\Historique\History.IE5\index.dat L'objet est verrouillé ignoré
                                C:\Documents and Settings\LocalService\Local Settings\Temp\Cookies\index.dat L'objet est verrouillé ignoré
                                C:\Documents and Settings\LocalService\Local Settings\Temp\History\History.IE5\index.dat L'objet est verrouillé ignoré
                                C:\Documents and Settings\LocalService\Local Settings\Temp\Temporary Internet Files\Content.IE5\index.dat L'objet est verrouillé ignoré
                                C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat L'objet est verrouillé ignoré
                                C:\Documents and Settings\LocalService\NTUSER.DAT L'objet est verrouillé ignoré
                                C:\Documents and Settings\LocalService\ntuser.dat.LOG L'objet est verrouillé ignoré
                                C:\Documents and Settings\NetworkService\Cookies\index.dat L'objet est verrouillé ignoré
                                C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat L'objet est verrouillé ignoré
                                C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG L'objet est verrouillé ignoré
                                C:\Documents and Settings\NetworkService\Local Settings\Historique\History.IE5\index.dat L'objet est verrouillé ignoré
                                C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\index.dat L'objet est verrouillé ignoré
                                C:\Documents and Settings\NetworkService\NTUSER.DAT L'objet est verrouillé ignoré
                                C:\Documents and Settings\NetworkService\ntuser.dat.LOG L'objet est verrouillé ignoré
                                C:\System Volume Information\_restore{D475D116-DF88-45C4-8BF3-9AB6FC089BD7}\RP1\change.log L'objet est verrouillé ignoré
                                C:\WINDOWS\Debug\PASSWD.LOG L'objet est verrouillé ignoré
                                C:\WINDOWS\SchedLgU.Txt L'objet est verrouillé ignoré
                                C:\WINDOWS\SoftwareDistribution\ReportingEvents.log L'objet est verrouillé ignoré
                                C:\WINDOWS\Sti_Trace.log L'objet est verrouillé ignoré
                                C:\WINDOWS\system32\CatRoot2\edb.log L'objet est verrouillé ignoré
                                C:\WINDOWS\system32\CatRoot2\tmp.edb L'objet est verrouillé ignoré
                                C:\WINDOWS\system32\config\ACEEvent.evt L'objet est verrouillé ignoré
                                C:\WINDOWS\system32\config\AppEvent.Evt L'objet est verrouillé ignoré
                                C:\WINDOWS\system32\config\default L'objet est verrouillé ignoré
                                C:\WINDOWS\system32\config\default.LOG L'objet est verrouillé ignoré
                                C:\WINDOWS\system32\config\Internet.evt L'objet est verrouillé ignoré
                                C:\WINDOWS\system32\config\ODiag.evt L'objet est verrouillé ignoré
                                C:\WINDOWS\system32\config\OSession.evt L'objet est verrouillé ignoré
                                C:\WINDOWS\system32\config\SAM L'objet est verrouillé ignoré
                                C:\WINDOWS\system32\config\SAM.LOG L'objet est verrouillé ignoré
                                C:\WINDOWS\system32\config\SecEvent.Evt L'objet est verrouillé ignoré
                                C:\WINDOWS\system32\config\SECURITY L'objet est verrouillé ignoré
                                C:\WINDOWS\system32\config\SECURITY.LOG L'objet est verrouillé ignoré
                                C:\WINDOWS\system32\config\software L'objet est verrouillé ignoré
                                C:\WINDOWS\system32\config\software.LOG L'objet est verrouillé ignoré
                                C:\WINDOWS\system32\config\SysEvent.Evt L'objet est verrouillé ignoré
                                C:\WINDOWS\system32\config\system L'objet est verrouillé ignoré
                                C:\WINDOWS\system32\config\system.LOG L'objet est verrouillé ignoré
                                C:\WINDOWS\system32\h323log.txt L'objet est verrouillé ignoré
                                C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR L'objet est verrouillé ignoré
                                C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP L'objet est verrouillé ignoré
                                C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER L'objet est verrouillé ignoré
                                C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP L'objet est verrouillé ignoré
                                C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP L'objet est verrouillé ignoré
                                C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA L'objet est verrouillé ignoré
                                C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP L'objet est verrouillé ignoré
                                C:\WINDOWS\temp\03ea43f8-c9f8-49f8-a0ac-f29288964b7d.tmp L'objet est verrouillé ignoré
                                C:\WINDOWS\temp\9e984eed-b98d-4758-ac5a-c2e07903d4c8.tmp L'objet est verrouillé ignoré
                                C:\WINDOWS\wiadebug.log L'objet est verrouillé ignoré
                                C:\WINDOWS\wiaservc.log L'objet est verrouillé ignoré
                                C:\WINDOWS\WindowsUpdate.log L'objet est verrouillé ignoré

                                Analyse terminée.
                                0
                                1. Modérateur
                                  Je suis là demain si tu veux.
                                  0
                                  1. Est ce que je dois faire une autre chose mon ami?
                                    0
                                    1. le kasperky est entrain de faire mise a jour en telechargeant près de 50Mo et mon debit n'est pas très rapide chui à 20% mnt et donc ça va prendre un peu du temps j'espere que tu seras connecté plus tard sinon est ce que tu peux me donner des instructions à effectuer après l'analyse? je remarque des ameliorations dans mon PC mais au niveau de WEB il y a encore quelques problemes.

                                      Merciiiiiiiiiiiiiiiiiiii
                                      0
                                  • 1
                                  • 2