PC qui rame

Résolu
Bonjour,

Depuis quelques temps mon PC est d'une lenteur incroyable. Pour rebooter il lui faut un temps infini et pour ouvrir la moindre application c'est la même chose.
Je joins un rapport HijackThis. Je l'ai copié sut le site HijackThis et il ne semble pas y avoir de problème majeur.
Quelqu'un pourrait-il m'aider.
Par avance merci.

Max
Configuration: Windows XP
Firefox 3.0.8
Bitdefender 9


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 09:39:08, on 07/04/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Fichiers communs\BitDefender\BitDefender Update Service\livesrv.exe
C:\Program Files\BitDefender\BitDefender 2009\vsserv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\Logitech\Video\LogiTray.exe
C:\Program Files\BroadJump\Client Foundation\CFD.exe
C:\PROGRA~1\CLUB-I~1\LECOMP~1\SMARTB~1\MotiveSB.exe
C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Club-Internet\Agent Wi-Fi V2.1\McciTrayApp.exe
C:\Program Files\BitDefender\BitDefender 2009\bdagent.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Microsoft ActiveSync\wcescomm.exe
C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe
C:\Program Files\Logitech\Video\FxSvr2.exe
C:\PROGRA~1\MI3AA1~1\rapimgr.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\MediaKey\Versato.exe
C:\Program Files\Club-Internet\Le Compagnon Club\bin\mpbtn.exe
C:\Program Files\MediaKey\MePlayer.exe
C:\Program Files\MediaKey\OSD.EXE
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\BitDefender\BitDefender 2009\seccenter.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://actus.sfr.fr
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.files-ftp.com/~unicorni/phpBB2/index.php
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer avec Club-Internet
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Smart Web Printing\hpswp_printenhancer.dll
O2 - BHO: HP Print Clips - {053F9267-DC04-4294-A72C-58F732D338C0} - C:\Program Files\HP\Smart Web Printing\hpswp_framework.dll
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: EoRezoBHO - {64F56FC1-1272-44CD-BA6E-39723696E350} - (no file)
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
O3 - Toolbar: BitDefender Toolbar - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - C:\Program Files\BitDefender\BitDefender 2009\IEToolbar.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [OpwareSE2] "C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe"
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [BJCFD] C:\Program Files\BroadJump\Client Foundation\CFD.exe
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\CLUB-I~1\LECOMP~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Club-Internet_McciTrayApp] C:\Program Files\Club-Internet\Agent Wi-Fi V2.1\McciTrayApp.exe
O4 - HKLM\..\Run: [Workflow] D:\install\Workflow.exe
O4 - HKLM\..\Run: [BDAgent] "C:\Program Files\BitDefender\BitDefender 2009\bdagent.exe"
O4 - HKLM\..\Run: [BitDefender Antiphishing Helper] "C:\Program Files\BitDefender\BitDefender 2009\IEShow.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
O4 - HKCU\..\Run: [TomTomHOME.exe] "C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe"
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: LE COMPAGNON CLUB.lnk = C:\Program Files\Club-Internet\Le Compagnon Club\bin\matcli.exe
O4 - Global Startup: Versato.lnk = C:\Program Files\MediaKey\Versato.exe
O8 - Extra context menu item: &Recherche AOL Toolbar - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra 'Tools' menuitem: Créer un Favori de l'appareil mobile... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: Livre de reliures HP - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: Sélection intelligente HP - {700259D7-1666-479a-93B1-3250410481E8} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.files-ftp.com/~unicorni/phpBB2/index.php
O16 - DPF: CabBuilder - http://kiw.imgag.com/imgag/kiw/toolbar/download/InstallerControl.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - http://download.divx.com/player/DivXBrowserPlugin.cab
O16 - DPF: {EBF85371-A38F-485B-B28F-0B4C82D25937} (CUpdateCtl Object) - http://update.hpphoto.com/download/HPSWUpdate.ocx
O23 - Service: BitDefender Arrakis Server (Arrakis3) - BitDefender S.R.L. https://www.bitdefender.fr/ - C:\Program Files\Fichiers communs\BitDefender\BitDefender Arrakis Server\bin\Arrakis3.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: BitDefender Desktop Update Service (LIVESRV) - BitDefender SRL - C:\Program Files\Fichiers communs\BitDefender\BitDefender Update Service\livesrv.exe
O23 - Service: TomTomHOMEService - TomTom - C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe
O23 - Service: BitDefender Virus Shield (VSSERV) - BitDefender S. R. L. - C:\Program Files\BitDefender\BitDefender 2009\vsserv.exe

--
End of file - 10696 bytes

14 réponses

Résumé de la discussion

Problème central : un PC sous Windows XP est extrêmement lent, le redémarrage et l'ouverture des applications demandent un temps infini et un rapport HijackThis est fourni pour dépistage. La meilleure première réponse conseille d'effectuer un scan en ligne avec Kaspersky Online Scanner via Internet Explorer, d'accepter les contrôles ActiveX, puis de sauvegarder et partager le rapport pour analyse. En complément, les rapports révèlent des éléments issus de HijackThis et RSIT, avec des listes d’exécutables et de services, mais aucune amélioration nette après les premiers scans. Pour progresser, l'examen des programmes au démarrage et des composants lourds peut être nécessaire, notamment la désinstallation de modules non essentiels et la gestion des services, afin d'identifier une source de lenteur.

Bobot (l’IA à votre service)
  1. Contributeur sécurité
    Ok je reste a ta disposition c' est peut etre un probléme matériel car il n' y a pas d' infections tu peux toujours faire un topic sur le forum windows ou matériel
    n' hesite pas si tu as besoin d' aide
    bonne soirée salut
    1. Contributeur sécurité
      et bien apres verif je ne vois rien de plus fait un scan en ligne pour etre certain

      - Fais un scan en ligne ici https://www.kaspersky.fr/?domain=webscanner.kaspersky.fr (Avec Internet Explorer).

      - En bas à droite, clique sur Démarrer Online-scanner.

      - Dans la nouvelle fenêtre qui s'affiche, clique sur J'accepte.

      - Accepte les Contrôles ActiveX.

      - Choisis Poste de travail pour le scan.

      - Celui-ci terminé, sauvegarde (Choisis fichier texte) et poste le rapport.

      - Pour t'aider à utiliser le scan en ligne : Lien

      Note : Si tu reçois le message La licence de Kaspersky On-line Scanner est périmée, va dans Ajout/Suppression de programmes puis désinstalle On-Line Scanner, reconnecte-toi sur le site de Kaspersky pour retenter le scan en ligne.
      1. Bonsoir,

        Voici l'ultime rapport de Kaspersky.
        Je pense que nous allons arrêter là les investigations.
        Il semble que mon PC se comporte un petit peu mieux, a suivre...
        Alors, je te remercie pour l'aide que tu m'as apporté.
        Si les symptômes persistent je reprendrai contact avec toi.
        Encore une fois merci.

        Bonne soirée.

        Max

        -------------------------------------------------------------------------------
        KASPERSKY ON-LINE SCANNER REPORT
        Wednesday, April 15, 2009 7:37:08 PM
        Système d'exploitation : Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
        Kaspersky On-line Scanner version : 5.0.84.2
        Dernière mise à jour de la base antivirus Kaspersky : 15/04/2009
        Enregistrements dans la base antivirus Kaspersky : 1851513
        -------------------------------------------------------------------------------

        Paramètres d'analyse:
        Analyser avec la base antivirus suivante: standard
        Analyser les archives: vrai
        Analyser les bases de messagerie: vrai

        Cible de l'analyse - Poste de travail:
        A:\
        C:\
        D:\
        E:\
        F:\

        Statistiques de l'analyse:
        Total d'objets analysés: 54435
        Nombre de virus trouvés: 0
        Nombre d'objets infectés: 0 / 0
        Nombre d'objets suspects: 0
        Durée de l'analyse: 01:31:34

        Nom de l'objet infecté / Nom du virus / Dernière action
        C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat L'objet est verrouillé ignoré
        C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat L'objet est verrouillé ignoré
        C:\Documents and Settings\LocalService\Cookies\index.dat L'objet est verrouillé ignoré
        C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat L'objet est verrouillé ignoré
        C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG L'objet est verrouillé ignoré
        C:\Documents and Settings\LocalService\Local Settings\Historique\History.IE5\index.dat L'objet est verrouillé ignoré
        C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat L'objet est verrouillé ignoré
        C:\Documents and Settings\LocalService\NTUSER.DAT L'objet est verrouillé ignoré
        C:\Documents and Settings\LocalService\ntuser.dat.LOG L'objet est verrouillé ignoré
        C:\Documents and Settings\Maxwell\Application Data\$_hpcst$.hpc L'objet est verrouillé ignoré
        C:\Documents and Settings\Maxwell\Application Data\BitDefender\Desktop\Profiles\asdict.dat L'objet est verrouillé ignoré
        C:\Documents and Settings\Maxwell\Application Data\Microsoft\Modèles\Normal.dot L'objet est verrouillé ignoré
        C:\Documents and Settings\Maxwell\Application Data\Microsoft\Word\Enregistrement automatique deDocument1.asd L'objet est verrouillé ignoré
        C:\Documents and Settings\Maxwell\Cookies\index.dat L'objet est verrouillé ignoré
        C:\Documents and Settings\Maxwell\Local Settings\Application Data\Microsoft\Messenger\max9525@hotmail.com\SharingMetadata\Logs\Dfsr00005.log L'objet est verrouillé ignoré
        C:\Documents and Settings\Maxwell\Local Settings\Application Data\Microsoft\Messenger\max9525@hotmail.com\SharingMetadata\pending.dat L'objet est verrouillé ignoré
        C:\Documents and Settings\Maxwell\Local Settings\Application Data\Microsoft\Messenger\max9525@hotmail.com\SharingMetadata\Working\database_14EC_3413_EC33_ED9C\dfsr.db L'objet est verrouillé ignoré
        C:\Documents and Settings\Maxwell\Local Settings\Application Data\Microsoft\Messenger\max9525@hotmail.com\SharingMetadata\Working\database_14EC_3413_EC33_ED9C\fsr.log L'objet est verrouillé ignoré
        C:\Documents and Settings\Maxwell\Local Settings\Application Data\Microsoft\Messenger\max9525@hotmail.com\SharingMetadata\Working\database_14EC_3413_EC33_ED9C\fsrtmp.log L'objet est verrouillé ignoré
        C:\Documents and Settings\Maxwell\Local Settings\Application Data\Microsoft\Messenger\max9525@hotmail.com\SharingMetadata\Working\database_14EC_3413_EC33_ED9C\tmp.edb L'objet est verrouillé ignoré
        C:\Documents and Settings\Maxwell\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat L'objet est verrouillé ignoré
        C:\Documents and Settings\Maxwell\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG L'objet est verrouillé ignoré
        C:\Documents and Settings\Maxwell\Local Settings\Application Data\Microsoft\Windows Live Contacts\max9525@hotmail.com\real\members.stg L'objet est verrouillé ignoré
        C:\Documents and Settings\Maxwell\Local Settings\Application Data\Microsoft\Windows Live Contacts\max9525@hotmail.com\shadow\members.stg L'objet est verrouillé ignoré
        C:\Documents and Settings\Maxwell\Local Settings\Historique\History.IE5\index.dat L'objet est verrouillé ignoré
        C:\Documents and Settings\Maxwell\Local Settings\Temp\WCESLog.log L'objet est verrouillé ignoré
        C:\Documents and Settings\Maxwell\Local Settings\Temp\~DFA9B4.tmp L'objet est verrouillé ignoré
        C:\Documents and Settings\Maxwell\Local Settings\Temp\~DFAA48.tmp L'objet est verrouillé ignoré
        C:\Documents and Settings\Maxwell\Local Settings\Temp\~DFB94D.tmp L'objet est verrouillé ignoré
        C:\Documents and Settings\Maxwell\Local Settings\Temp\~DFFCC0.tmp L'objet est verrouillé ignoré
        C:\Documents and Settings\Maxwell\Local Settings\Temp\~DFFD3.tmp L'objet est verrouillé ignoré
        C:\Documents and Settings\Maxwell\Local Settings\Temp\~DFFF9.tmp L'objet est verrouillé ignoré
        C:\Documents and Settings\Maxwell\Local Settings\Temporary Internet Files\Content.IE5\index.dat L'objet est verrouillé ignoré
        C:\Documents and Settings\Maxwell\NTUSER.DAT L'objet est verrouillé ignoré
        C:\Documents and Settings\Maxwell\ntuser.dat.LOG L'objet est verrouillé ignoré
        C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat L'objet est verrouillé ignoré
        C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG L'objet est verrouillé ignoré
        C:\Documents and Settings\NetworkService\NTUSER.DAT L'objet est verrouillé ignoré
        C:\Documents and Settings\NetworkService\ntuser.dat.LOG L'objet est verrouillé ignoré
        C:\Program Files\Club-Internet\Le Compagnon Club\log\mpbtn.log L'objet est verrouillé ignoré
        C:\Program Files\Club-Internet\Le Compagnon Club\SmartBridge\AlertFilter.log L'objet est verrouillé ignoré
        C:\Program Files\Club-Internet\Le Compagnon Club\SmartBridge\log\httpclient.log L'objet est verrouillé ignoré
        C:\Program Files\Club-Internet\Le Compagnon Club\SmartBridge\SmartBridge.log L'objet est verrouillé ignoré
        C:\Program Files\Fichiers communs\BitDefender\BitDefender Firewall\bdfirewall.txt L'objet est verrouillé ignoré
        C:\Program Files\Fichiers communs\BitDefender\BitDefender Threat Scanner\av32bit_11613\Plugins\cache.000 L'objet est verrouillé ignoré
        C:\System Volume Information\MountPointManagerRemoteDatabase L'objet est verrouillé ignoré
        C:\System Volume Information\_restore{8259EF9F-A142-4881-BE5A-E3E86FD3E5A2}\RP1213\change.log L'objet est verrouillé ignoré
        C:\WINDOWS\Debug\PASSWD.LOG L'objet est verrouillé ignoré
        C:\WINDOWS\SchedLgU.Txt L'objet est verrouillé ignoré
        C:\WINDOWS\SoftwareDistribution\DataStore\DataStore.edb L'objet est verrouillé ignoré
        C:\WINDOWS\SoftwareDistribution\DataStore\Logs\edb.log L'objet est verrouillé ignoré
        C:\WINDOWS\SoftwareDistribution\DataStore\Logs\tmp.edb L'objet est verrouillé ignoré
        C:\WINDOWS\SoftwareDistribution\ReportingEvents.log L'objet est verrouillé ignoré
        C:\WINDOWS\Sti_Trace.log L'objet est verrouillé ignoré
        C:\WINDOWS\system32\CatRoot2\edb.log L'objet est verrouillé ignoré
        C:\WINDOWS\system32\CatRoot2\tmp.edb L'objet est verrouillé ignoré
        C:\WINDOWS\system32\config\AppEvent.Evt L'objet est verrouillé ignoré
        C:\WINDOWS\system32\config\default L'objet est verrouillé ignoré
        C:\WINDOWS\system32\config\default.LOG L'objet est verrouillé ignoré
        C:\WINDOWS\system32\config\Internet.evt L'objet est verrouillé ignoré
        C:\WINDOWS\system32\config\SAM L'objet est verrouillé ignoré
        C:\WINDOWS\system32\config\SAM.LOG L'objet est verrouillé ignoré
        C:\WINDOWS\system32\config\SecEvent.Evt L'objet est verrouillé ignoré
        C:\WINDOWS\system32\config\SECURITY L'objet est verrouillé ignoré
        C:\WINDOWS\system32\config\SECURITY.LOG L'objet est verrouillé ignoré
        C:\WINDOWS\system32\config\software L'objet est verrouillé ignoré
        C:\WINDOWS\system32\config\software.LOG L'objet est verrouillé ignoré
        C:\WINDOWS\system32\config\SysEvent.Evt L'objet est verrouillé ignoré
        C:\WINDOWS\system32\config\system L'objet est verrouillé ignoré
        C:\WINDOWS\system32\config\system.LOG L'objet est verrouillé ignoré
        C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR L'objet est verrouillé ignoré
        C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP L'objet est verrouillé ignoré
        C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER L'objet est verrouillé ignoré
        C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP L'objet est verrouillé ignoré
        C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP L'objet est verrouillé ignoré
        C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA L'objet est verrouillé ignoré
        C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP L'objet est verrouillé ignoré
        C:\WINDOWS\Temp\Perflib_Perfdata_754.dat L'objet est verrouillé ignoré
        C:\WINDOWS\Temp\tmp00007b41\tmp00000000 L'objet est verrouillé ignoré
        C:\WINDOWS\wiadebug.log L'objet est verrouillé ignoré
        C:\WINDOWS\wiaservc.log L'objet est verrouillé ignoré
        C:\WINDOWS\WindowsUpdate.log L'objet est verrouillé ignoré

        Analyse terminée.
    2. Contributeur sécurité
      salut peut tu telecharger hijackthis et relancer rsit svp
      http://www.trendsecure.com/portal/en-US/_download/HJTInstall.exe

      enregistre le sur le bureau (et pas ailleurs ]sous le nom de hjt.exe
      1. Bonjour,

        Après installation de hjt dans les conditions demandées, j'ai lancé RSIT mais,
        celui-ci n'a généré qu'un seul fichier log. Pas de fichier info ?
        Voici donc ci-dessous le fichier log.
        Bonne journée, à plus tard.

        Max

        Logfile of random's system information tool 1.06 (written by random/random)
        Run by Maxwell at 2009-04-15 08:15:19
        Microsoft Windows XP Professionnel Service Pack 2
        System drive C: has 124 GB (79%) free of 156 GB
        Total RAM: 511 MB (34% free)

        Logfile of Trend Micro HijackThis v2.0.2
        Scan saved at 08:15:21, on 15/04/2009
        Platform: Windows XP SP2 (WinNT 5.01.2600)
        MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
        Boot mode: Normal

        Running processes:
        C:\WINDOWS\System32\smss.exe
        C:\WINDOWS\system32\winlogon.exe
        C:\WINDOWS\system32\services.exe
        C:\WINDOWS\system32\lsass.exe
        C:\WINDOWS\system32\Ati2evxx.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\system32\Ati2evxx.exe
        C:\WINDOWS\Explorer.EXE
        C:\WINDOWS\system32\spoolsv.exe
        C:\WINDOWS\SOUNDMAN.EXE
        C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
        C:\Program Files\QuickTime\qttask.exe
        C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe
        C:\WINDOWS\system32\LVCOMSX.EXE
        C:\Program Files\Logitech\Video\LogiTray.exe
        C:\Program Files\BroadJump\Client Foundation\CFD.exe
        C:\PROGRA~1\CLUB-I~1\LECOMP~1\SMARTB~1\MotiveSB.exe
        C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe
        C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
        C:\Program Files\Club-Internet\Agent Wi-Fi V2.1\McciTrayApp.exe
        C:\Program Files\BitDefender\BitDefender 2009\bdagent.exe
        C:\Program Files\Java\jre6\bin\jusched.exe
        C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
        C:\WINDOWS\system32\ctfmon.exe
        C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
        C:\Program Files\Microsoft ActiveSync\wcescomm.exe
        C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe
        C:\Program Files\filehippo.com\UpdateChecker.exe
        C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
        C:\PROGRA~1\MI3AA1~1\rapimgr.exe
        C:\Program Files\MediaKey\Versato.exe
        C:\Program Files\Club-Internet\Le Compagnon Club\bin\mpbtn.exe
        C:\Program Files\Logitech\Video\FxSvr2.exe
        C:\Program Files\MediaKey\MePlayer.exe
        C:\Program Files\MediaKey\OSD.EXE
        C:\WINDOWS\system32\svchost.exe
        C:\Program Files\Java\jre6\bin\jqs.exe
        C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\system32\svchost.exe
        C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe
        C:\Program Files\BitDefender\BitDefender 2009\seccenter.exe
        C:\WINDOWS\system32\wscntfy.exe
        C:\Program Files\Windows Live\Messenger\usnsvc.exe
        C:\Program Files\BitDefender\BitDefender 2009\vsserv.exe
        C:\Program Files\Fichiers communs\BitDefender\BitDefender Update Service\livesrv.exe
        C:\Documents and Settings\Maxwell\Bureau\RSIT.exe
        C:\Documents and Settings\Maxwell\Bureau\hjt\Maxwell.exe

        R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
        R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
        O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Smart Web Printing\hpswp_printenhancer.dll
        O2 - BHO: HP Print Clips - {053F9267-DC04-4294-A72C-58F732D338C0} - C:\Program Files\HP\Smart Web Printing\hpswp_framework.dll
        O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
        O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
        O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
        O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
        O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll
        O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll
        O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
        O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
        O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
        O3 - Toolbar: BitDefender Toolbar - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - C:\Program Files\BitDefender\BitDefender 2009\IEToolbar.dll
        O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
        O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
        O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
        O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
        O4 - HKLM\..\Run: [OpwareSE2] "C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe"
        O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
        O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
        O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
        O4 - HKLM\..\Run: [BJCFD] C:\Program Files\BroadJump\Client Foundation\CFD.exe
        O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\CLUB-I~1\LECOMP~1\SMARTB~1\MotiveSB.exe
        O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe"
        O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
        O4 - HKLM\..\Run: [Club-Internet_McciTrayApp] C:\Program Files\Club-Internet\Agent Wi-Fi V2.1\McciTrayApp.exe
        O4 - HKLM\..\Run: [Workflow] D:\install\Workflow.exe
        O4 - HKLM\..\Run: [BDAgent] "C:\Program Files\BitDefender\BitDefender 2009\bdagent.exe"
        O4 - HKLM\..\Run: [BitDefender Antiphishing Helper] "C:\Program Files\BitDefender\BitDefender 2009\IEShow.exe"
        O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
        O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
        O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot
        O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
        O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
        O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
        O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
        O4 - HKCU\..\Run: [TomTomHOME.exe] "C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe"
        O4 - HKCU\..\Run: [filehippo.com] "C:\Program Files\filehippo.com\UpdateChecker.exe" /background
        O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
        O4 - Global Startup: LE COMPAGNON CLUB.lnk = C:\Program Files\Club-Internet\Le Compagnon Club\bin\matcli.exe
        O4 - Global Startup: Versato.lnk = C:\Program Files\MediaKey\Versato.exe
        O8 - Extra context menu item: &Recherche AOL Toolbar - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
        O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
        O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
        O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
        O9 - Extra 'Tools' menuitem: Créer un Favori de l'appareil mobile... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
        O9 - Extra button: Livre de reliures HP - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
        O9 - Extra button: Sélection intelligente HP - {700259D7-1666-479a-93B1-3250410481E8} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
        O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
        O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
        O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
        O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
        O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
        O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
        O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O14 - IERESET.INF: START_PAGE_URL=http://www.files-ftp.com/~unicorni/phpBB2/index.php
        O16 - DPF: CabBuilder - http://kiw.imgag.com/imgag/kiw/toolbar/download/InstallerControl.cab
        O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
        O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - http://download.divx.com/player/DivXBrowserPlugin.cab
        O16 - DPF: {EBF85371-A38F-485B-B28F-0B4C82D25937} (CUpdateCtl Object) - http://update.hpphoto.com/download/HPSWUpdate.ocx
        O23 - Service: BitDefender Arrakis Server (Arrakis3) - BitDefender S.R.L. https://www.bitdefender.fr/ - C:\Program Files\Fichiers communs\BitDefender\BitDefender Arrakis Server\bin\Arrakis3.exe
        O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
        O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
        O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
        O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe
        O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
        O23 - Service: BitDefender Desktop Update Service (LIVESRV) - BitDefender SRL - C:\Program Files\Fichiers communs\BitDefender\BitDefender Update Service\livesrv.exe
        O23 - Service: TomTomHOMEService - TomTom - C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe
        O23 - Service: BitDefender Virus Shield (VSSERV) - BitDefender S. R. L. - C:\Program Files\BitDefender\BitDefender 2009\vsserv.exe
    3. Contributeur sécurité
      post un dernier rsit svp
      1. Bonjour,

        Alors voilà les deux fichiers générés par RSIT
        A bientôt.

        Max

        Logfile of random's system information tool 1.06 (written by random/random)
        Run by Maxwell at 2009-04-14 18:05:58
        Microsoft Windows XP Professionnel Service Pack 2
        System drive C: has 124 GB (79%) free of 156 GB
        Total RAM: 511 MB (37% free)

        HijackThis download failed

        ======Registry dump======

        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0347C33E-8762-4905-BF09-768834316C61}]
        HP Print Enhancer - C:\Program Files\HP\Smart Web Printing\hpswp_printenhancer.dll [2007-03-02 1298024]

        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{053F9267-DC04-4294-A72C-58F732D338C0}]
        HP Print Clips - C:\Program Files\HP\Smart Web Printing\hpswp_framework.dll [2007-03-02 177768]

        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
        Adobe PDF Link Helper - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-02-27 75128]

        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3049C3E9-B461-4BC5-8870-4C09146192CA}]
        RealPlayer Download and Record Plugin for Internet Explorer - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll [2008-08-16 308856]

        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7E853D72-626A-48EC-A868-BA8D5E23E045}]

        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
        Programme d'aide de l'Assistant de connexion Windows Live - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2007-09-20 328752]

        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
        Google Toolbar Helper - c:\program files\google\googletoolbar4.dll [2007-01-20 2436160]

        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
        Google Toolbar Notifier BHO - C:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll [2008-10-05 737776]

        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
        Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2009-03-09 35840]

        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
        JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2009-03-09 73728]

        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
        {2318C2B1-4965-11d4-9B18-009027A5CD4F} - &Google - c:\program files\google\googletoolbar4.dll [2007-01-20 2436160]
        {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - BitDefender Toolbar - C:\Program Files\BitDefender\BitDefender 2009\IEToolbar.dll [2009-04-06 95536]

        [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
        "SoundMan"=C:\WINDOWS\SOUNDMAN.EXE [2004-06-18 67584]
        "ATIPTA"=C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe [2005-03-22 339968]
        "NeroFilterCheck"=C:\WINDOWS\system32\NeroCheck.exe [2001-07-09 155648]
        "QuickTime Task"=C:\Program Files\QuickTime\qttask.exe [2005-04-23 98304]
        "OpwareSE2"=C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe [2003-05-08 49152]
        "LVCOMSX"=C:\WINDOWS\system32\LVCOMSX.EXE [2004-10-08 221184]
        "LogitechVideoRepair"=C:\Program Files\Logitech\Video\ISStart.exe [2004-10-08 458752]
        "LogitechVideoTray"=C:\Program Files\Logitech\Video\LogiTray.exe [2004-10-08 217088]
        "BJCFD"=C:\Program Files\BroadJump\Client Foundation\CFD.exe [2003-01-27 376912]
        "Motive SmartBridge"=C:\PROGRA~1\CLUB-I~1\LECOMP~1\SMARTB~1\MotiveSB.exe [2005-08-24 438359]
        "StandardInstall"= []
        "Adobe Photo Downloader"=C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe [2007-03-16 63712]
        "HP Software Update"=C:\Program Files\HP\HP Software Update\HPWuSchd2.exe [2007-03-11 49152]
        "Club-Internet_McciTrayApp"=C:\Program Files\Club-Internet\Agent Wi-Fi V2.1\McciTrayApp.exe [2005-11-15 543232]
        "Workflow"=D:\install\Workflow.exe []
        "BDAgent"=C:\Program Files\BitDefender\BitDefender 2009\bdagent.exe [2009-04-06 778240]
        "BitDefender Antiphishing Helper"=C:\Program Files\BitDefender\BitDefender 2009\IEShow.exe [2009-04-06 69632]
        "SunJavaUpdateSched"=C:\Program Files\Java\jre6\bin\jusched.exe [2009-03-09 148888]
        "Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2009-02-27 35696]

        [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
        "LogitechSoftwareUpdate"=C:\Program Files\Logitech\Video\ManifestEngine.exe [2004-10-08 196608]
        "MsnMsgr"=C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe [2007-10-18 5724184]
        "ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2004-08-04 15360]
        "swg"=C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2008-04-13 68856]
        "H/PC Connection Agent"=C:\Program Files\Microsoft ActiveSync\wcescomm.exe [2006-11-13 1289000]
        "TomTomHOME.exe"=C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe [2009-03-18 251240]
        "filehippo.com"=C:\Program Files\filehippo.com\UpdateChecker.exe [2009-03-23 146432]

        [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RecoverFromReboot]
        []

        C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage
        HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
        LE COMPAGNON CLUB.lnk - C:\Program Files\Club-Internet\Le Compagnon Club\bin\matcli.exe
        Versato.lnk - C:\Program Files\MediaKey\Versato.exe

        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
        C:\WINDOWS\system32\Ati2evxx.dll [2005-03-23 46080]

        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
        C:\WINDOWS\system32\WgaLogon.dll [2007-02-15 200064]

        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
        WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

        [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
        "dontdisplaylastusername"=0
        "legalnoticecaption"=
        "legalnoticetext"=
        "shutdownwithoutlogon"=1
        "undockwithoutlogon"=1

        [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
        "NoDriveTypeAutoRun"=145

        [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
        "%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
        "C:\Program Files\Messenger\msmsgs.exe"="C:\Program Files\Messenger\msmsgs.exe:*:Enabled:Windows Messenger"
        "C:\Program Files\Fichiers communs\AOL\ACS\AOLDial.exe"="C:\Program Files\Fichiers communs\AOL\ACS\AOLDial.exe:*:Enabled:AOL"
        "C:\Program Files\Fichiers communs\AOL\ACS\AOLAcsd.exe"="C:\Program Files\Fichiers communs\AOL\ACS\AOLAcsd.exe:*:Enabled:AOL"
        "C:\Program Files\AOL 9.0\waol.exe"="C:\Program Files\AOL 9.0\waol.exe:*:Enabled:AOL 9.0"
        "C:\Program Files\eMule\emule.exe"="C:\Program Files\eMule\emule.exe:*:Enabled:eMule"
        "C:\Program Files\AIM\aim.exe"="C:\Program Files\AIM\aim.exe:*:Enabled:AOL Instant Messenger"
        "C:\Program Files\BitTorrent\bittorrent.exe"="C:\Program Files\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent"
        "C:\Program Files\Real\RealPlayer\realplay.exe"="C:\Program Files\Real\RealPlayer\realplay.exe:*:Enabled:RealPlayer"
        "C:\TEMP\CI_HITACHI\MAJ_Hitachi.exe"="C:\TEMP\CI_HITACHI\MAJ_Hitachi.exe:*:Enabled:Firmware Upgrader Hitachi"
        "C:\Program Files\Microsoft ActiveSync\rapimgr.exe"="C:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager"
        "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"="C:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager"
        "C:\Program Files\Microsoft ActiveSync\WCESMgr.exe"="C:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application"
        "C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"
        "C:\Program Files\Windows Live\Messenger\livecall.exe"="C:\Program Files\Windows Live\Messenger\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"
        "%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

        [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
        "%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
        "C:\Program Files\Fichiers communs\AOL\ACS\AOLDial.exe"="C:\Program Files\Fichiers communs\AOL\ACS\AOLDial.exe:*:Enabled:AOL"
        "C:\Program Files\Fichiers communs\AOL\ACS\AOLAcsd.exe"="C:\Program Files\Fichiers communs\AOL\ACS\AOLAcsd.exe:*:Enabled:AOL"
        "C:\Program Files\AOL 9.0\waol.exe"="C:\Program Files\AOL 9.0\waol.exe:*:Enabled:AOL 9.0"
        "C:\Program Files\Microsoft ActiveSync\rapimgr.exe"="C:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager"
        "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"="C:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager"
        "C:\Program Files\Microsoft ActiveSync\WCESMgr.exe"="C:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application"
        "C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"
        "C:\Program Files\Windows Live\Messenger\livecall.exe"="C:\Program Files\Windows Live\Messenger\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"
        "%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

        ======File associations======

        .scr - open - "C:\WINDOWS\notepad.exe" "%1"
        .scr - install -
        .scr - config -

        ======List of files/folders created in the last 1 months======

        2009-04-14 18:05:58 ----D---- C:\rsit
        2009-04-13 20:40:22 ----D---- C:\Program Files\NOS
        2009-04-13 20:40:22 ----D---- C:\Documents and Settings\All Users\Application Data\NOS
        2009-04-13 11:56:50 ----D---- C:\Program Files\Autodesk
        2009-04-13 11:55:58 ----D---- C:\Program Files\AnswerWorks 4.0
        2009-04-13 11:55:02 ----D---- C:\Program Files\Fichiers communs\Autodesk Shared
        2009-04-10 22:45:15 ----D---- C:\Program Files\filehippo.com
        2009-04-10 21:03:32 ----D---- C:\Rapports
        2009-04-08 08:32:30 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
        2009-04-07 09:56:24 ----D---- C:\Program Files\Ad-remover
        2009-04-01 20:53:05 ----A---- C:\WINDOWS\bdagent.INI
        2009-03-27 17:56:30 ----D---- C:\Program Files\TomTom International B.V
        2009-03-27 08:47:15 ----A---- C:\WINDOWS\system32\javaws.exe
        2009-03-27 08:47:15 ----A---- C:\WINDOWS\system32\javaw.exe
        2009-03-27 08:47:15 ----A---- C:\WINDOWS\system32\java.exe

        ======List of files/folders modified in the last 1 months======

        2009-04-14 18:06:03 ----D---- C:\WINDOWS\Prefetch
        2009-04-14 18:06:01 ----D---- C:\WINDOWS\system32\CatRoot2
        2009-04-14 18:00:43 ----D---- C:\Program Files\Mozilla Firefox
        2009-04-14 17:22:53 ----D---- C:\WINDOWS\Temp
        2009-04-14 17:17:57 ----D---- C:\WINDOWS\system32
        2009-04-13 23:19:14 ----A---- C:\WINDOWS\SchedLgU.Txt
        2009-04-13 23:19:01 ----D---- C:\WINDOWS
        2009-04-13 22:44:04 ----SHD---- C:\System Volume Information
        2009-04-13 22:44:04 ----D---- C:\WINDOWS\system32\Restore
        2009-04-13 22:27:10 ----SHD---- C:\WINDOWS\Installer
        2009-04-13 22:23:23 ----HD---- C:\Config.Msi
        2009-04-13 22:19:16 ----D---- C:\Documents and Settings\All Users\Application Data\Adobe
        2009-04-13 21:41:14 ----D---- C:\Program Files\Fichiers communs\Adobe
        2009-04-13 21:15:31 ----D---- C:\Program Files\Adobe
        2009-04-13 20:40:22 ----RD---- C:\Program Files
        2009-04-13 16:51:59 ----D---- C:\WINDOWS\ERUNT
        2009-04-13 11:56:12 ----D---- C:\Program Files\AutoCAD LT 2004
        2009-04-13 11:55:43 ----RSD---- C:\WINDOWS\Fonts
        2009-04-13 11:55:13 ----D---- C:\WINDOWS\Help
        2009-04-13 11:55:02 ----D---- C:\Program Files\Fichiers communs
        2009-04-10 21:02:44 ----D---- C:\Program Files\Trend Micro
        2009-04-10 20:58:41 ----SD---- C:\WINDOWS\Downloaded Program Files
        2009-04-10 20:58:41 ----RD---- C:\WINDOWS\Offline Web Pages
        2009-04-10 20:58:41 ----D---- C:\VIDEO
        2009-04-10 20:58:41 ----D---- C:\Toutes video
        2009-04-10 20:58:41 ----D---- C:\Studio
        2009-04-10 20:58:41 ----D---- C:\Program Files\Windows Media Connect 2
        2009-04-10 20:58:41 ----D---- C:\Photos de Bessay
        2009-04-10 20:58:41 ----D---- C:\Photos
        2009-04-10 20:58:41 ----D---- C:\LOL
        2009-04-10 20:58:41 ----D---- C:\Etiquettes confitures
        2009-04-10 20:58:41 ----D---- C:\Electricité
        2009-04-10 20:58:40 ----D---- C:\DCFC0137c
        2009-04-10 20:58:40 ----D---- C:\DCFC0136c
        2009-04-10 20:58:40 ----D---- C:\CADFILES
        2009-04-10 20:58:40 ----D---- C:\Autocad Dwg
        2009-04-10 20:58:36 ----HD---- C:\WINDOWS\$hf_mig$
        2009-04-10 18:23:39 ----D---- C:\Recettes
        2009-04-10 13:45:19 ----A---- C:\WINDOWS\NeroDigital.ini
        2009-04-08 14:25:31 ----A---- C:\WINDOWS\win.ini
        2009-04-08 08:32:35 ----D---- C:\WINDOWS\system32\drivers
        2009-03-30 17:30:32 ----A---- C:\Lisez moi.txt
        2009-03-30 07:45:39 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
        2009-03-27 17:55:14 ----D---- C:\Program Files\TomTom HOME 2
        2009-03-27 08:47:13 ----D---- C:\Program Files\Java
        2009-03-24 15:22:19 ----D---- C:\Dixi

        ======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

        R1 bdftdif;bdftdif; \??\C:\Program Files\Fichiers communs\BitDefender\BitDefender Firewall\bdftdif.sys []
        R1 kbfilter;Keyboard Filter Driver; C:\WINDOWS\system32\drivers\kbfilter.sys [1999-08-27 14624]
        R2 BDVEDISK;BDVEDISK; \??\C:\Program Files\BitDefender\BitDefender 2009\BDVEDISK.sys []
        R2 DK2DRV;DK2 WindowsNT Driver; \??\C:\WINDOWS\system32\Drivers\DK2DRV.SYS []
        R2 haspnt;haspnt; \??\C:\WINDOWS\system32\haspnt.sys []
        R2 mdmxsdk;mdmxsdk; C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys [2003-11-24 9855]
        R3 ALCXSENS;Service for WDM 3D Audio Driver; C:\WINDOWS\system32\drivers\ALCXSENS.SYS [2004-02-24 400384]
        R3 ALCXWDM;Service for Realtek AC97 Audio (WDM); C:\WINDOWS\system32\drivers\ALCXWDM.SYS [2004-06-21 626204]
        R3 ati2mtag;ati2mtag; C:\WINDOWS\system32\DRIVERS\ati2mtag.sys [2005-03-23 1034752]
        R3 bdfm;BDFM; C:\WINDOWS\system32\drivers\bdfm.sys [2008-09-18 111112]
        R3 Bdfndisf;BitDefender Firewall NDIS Filter Service; C:\WINDOWS\system32\DRIVERS\bdfndisf.sys [2009-04-06 104328]
        R3 bdfsfltr;bdfsfltr; C:\WINDOWS\system32\drivers\bdfsfltr.sys [2008-12-10 242184]
        R3 BDSelfPr;BDSelfPr; \??\C:\Program Files\BitDefender\BitDefender 2009\bdselfpr.sys []
        R3 LVUSBSta;Logitech USB Monitor Filter; C:\WINDOWS\system32\drivers\lvusbsta.sys [2004-10-08 22016]
        R3 MRENDIS5;MRENDIS5 NDIS Protocol Driver; \??\C:\PROGRA~1\COMMON~1\Motive\MRENDIS5.SYS []
        R3 ms_mpu401;Pilote UART MIDI MPU-401 Microsoft; C:\WINDOWS\system32\drivers\msmpu401.sys [2001-08-18 2944]
        R3 NVENETFD;NVIDIA nForce Networking Controller Driver; C:\WINDOWS\system32\DRIVERS\NVENETFD.sys [2004-07-28 33024]
        R3 nvnetbus;NVIDIA Network Bus Enumerator; C:\WINDOWS\system32\DRIVERS\nvnetbus.sys [2004-07-28 12928]
        R3 QCMerced;Logitech QuickCam Communicate; C:\WINDOWS\system32\DRIVERS\LVCM.sys [2004-10-08 585824]
        R3 usbaudio;Pilote USB audio (WDM); C:\WINDOWS\system32\drivers\usbaudio.sys [2004-08-03 59264]
        R3 usbccgp;Pilote parent générique USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2004-08-03 31616]
        R3 usbehci;Pilote miniport de contrôleur d'hôte amélioré Microsoft USB 2.0; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2004-08-03 26624]
        R3 usbhub;Concentrateur USB2; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2004-08-03 57600]
        R3 usbohci;Pilote miniport de contrôleur hôte ouvert USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbohci.sys [2004-08-03 17024]
        R3 USBSTOR;Pilote de stockage de masse USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-03 26496]
        S1 DK12DRV;DK12 WindowsNT Driver; C:\WINDOWS\SYSTEM32\DRIVERS\DK12DRV.SYS []
        S3 catchme;catchme; \??\C:\DOCUME~1\Maxwell\LOCALS~1\Temp\catchme.sys []
        S3 CCDECODE;Décodeur sous-titre fermé; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2004-08-03 17024]
        S3 hardlock;hardlock; \??\C:\WINDOWS\system32\hardlock.sys []
        S3 HidUsb;Pilote de classe HID Microsoft; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2001-08-17 9600]
        S3 HPZid412;IEEE-1284.4 Driver HPZid412; C:\WINDOWS\system32\DRIVERS\HPZid412.sys [2007-03-08 49920]
        S3 HPZipr12;Print Class Driver for IEEE-1284.4 HPZipr12; C:\WINDOWS\system32\DRIVERS\HPZipr12.sys [2007-03-08 16496]
        S3 HPZius12;USB to IEEE-1284.4 Translation Driver HPZius12; C:\WINDOWS\system32\DRIVERS\HPZius12.sys [2007-03-08 21568]
        S3 HSF_DP;HSF_DP; C:\WINDOWS\system32\DRIVERS\HSF_DP.sys [2003-11-24 1174384]
        S3 HSFHWCD2;HSFHWCD2; C:\WINDOWS\system32\DRIVERS\HSFHWCD2.sys [2003-11-24 169700]
        S3 lg3gbus;LGE KU580 driver (WDM); C:\WINDOWS\system32\DRIVERS\lg3gbus.sys [2007-04-26 83080]
        S3 lg3gmdfl;LGE KU580 USB WMC Modem Filter; C:\WINDOWS\system32\DRIVERS\lg3gmdfl.sys [2007-04-26 15112]
        S3 lg3gmdm;LGE KU580 USB WMC Modem Driver; C:\WINDOWS\system32\DRIVERS\lg3gmdm.sys [2007-04-26 108552]
        S3 lg3gmgmt;LGE KU580 USB WMC Device Management Drivers (WDM); C:\WINDOWS\system32\DRIVERS\lg3gmgmt.sys [2007-04-26 100360]
        S3 lg3gnd5;LGE KU580 USB Ethernet Emulation (NDIS); C:\WINDOWS\system32\DRIVERS\lg3gnd5.sys [2007-04-26 23176]
        S3 lg3gobex;LGE KU580 USB WMC OBEX Interface; C:\WINDOWS\system32\DRIVERS\lg3gobex.sys [2007-04-26 98568]
        S3 lg3gunic;LGE KU580 USB Ethernet Emulation (WDM); C:\WINDOWS\system32\DRIVERS\lg3gunic.sys [2007-04-26 98952]
        S3 MSTEE;Convertisseur en T/site-à-site de répartition Microsoft; C:\WINDOWS\system32\drivers\MSTEE.sys [2004-08-03 5504]
        S3 NABTSFEC;Codec NABTS/FEC VBI; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2004-08-03 85376]
        S3 Navcar;Navman In-car Navigator USB Driver Service; C:\WINDOWS\system32\DRIVERS\Navcar.sys [2006-09-18 30329]
        S3 NdisIP;Connection TV/vidéo Microsoft; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2004-08-03 10880]
        S3 Profos;Profos; \??\C:\Program Files\Fichiers communs\BitDefender\BitDefender Threat Scanner\profos.sys []
        S3 ROOTMODEM;Microsoft Legacy Modem Driver; C:\WINDOWS\System32\Drivers\RootMdm.sys [2001-08-24 5888]
        S3 SLIP;Détrameur décalage BDA; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2004-08-03 11136]
        S3 SONYPVU1;Pilote de filtrage Sony USB (SONYPVU1); C:\WINDOWS\system32\DRIVERS\SONYPVU1.SYS [2001-08-17 7552]
        S3 StillCam;Pilote d'appareil photo numérique série; C:\WINDOWS\system32\DRIVERS\serscan.sys [2001-08-23 6912]
        S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2004-08-03 15360]
        S3 SymIM;Symantec Network Security Intermediate Filter Service; C:\WINDOWS\system32\DRIVERS\SymIM.sys []
        S3 SymIMMP;SymIMMP; C:\WINDOWS\system32\DRIVERS\SymIM.sys []
        S3 Trufos;Trufos; \??\C:\Program Files\Fichiers communs\BitDefender\BitDefender Threat Scanner\trufos.sys []
        S3 USB_RNDIS_51;Broadcom USB Remote NDIS Device Driver; C:\WINDOWS\system32\DRIVERS\usb8023.sys [2005-10-21 12800]
        S3 usb_rndisx;USB RNDIS Adapter; C:\WINDOWS\system32\DRIVERS\usb8023x.sys [2005-10-21 12800]
        S3 usbprint;Classe d'imprimantes USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2004-08-03 25856]
        S3 usbscan;Pilote de scanneur USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2004-08-03 15104]
        S3 wanatw;WAN Miniport (ATW); C:\WINDOWS\system32\DRIVERS\wanatw4.sys []
        S3 winachsf;winachsf; C:\WINDOWS\system32\DRIVERS\HSF_CNXT.sys [2003-11-24 602480]
        S3 WSTCODEC;Codec Teletext standard; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2004-08-03 19328]
        S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
        S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
        S3 ZD1211BU(3COM Corporation);3Com OfficeConnect Wireless 54Mbps 11g Compact USB Adapter(3COM Corporation); C:\WINDOWS\system32\DRIVERS\zd1211Bu.sys [2006-01-17 402944]
        S3 ZDPSp50;ZDPSp50 NDIS Protocol Driver; C:\WINDOWS\System32\Drivers\ZDPSp50.sys [2004-10-25 17664]
        S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []

        ======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

        R2 Ati HotKey Poller;Ati HotKey Poller; C:\WINDOWS\system32\Ati2evxx.exe [2005-03-23 360448]
        R2 hpqddsvc;Service HP CUE DeviceDiscovery; C:\WINDOWS\system32\svchost.exe [2004-08-04 14336]
        R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2009-03-09 152984]
        R2 LIVESRV;BitDefender Desktop Update Service; C:\Program Files\Fichiers communs\BitDefender\BitDefender Update Service\livesrv.exe [2009-04-06 415024]
        R2 MDM;Machine Debug Manager; C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE [2003-06-19 322120]
        R2 Net Driver HPZ12;Net Driver HPZ12; C:\WINDOWS\System32\svchost.exe [2004-08-04 14336]
        R2 Pml Driver HPZ12;Pml Driver HPZ12; C:\WINDOWS\System32\svchost.exe [2004-08-04 14336]
        R2 TomTomHOMEService;TomTomHOMEService; C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe [2009-03-18 92008]
        R2 VSSERV;BitDefender Virus Shield; C:\Program Files\BitDefender\BitDefender 2009\vsserv.exe [2009-04-06 1626112]
        R3 hpqcxs08;hpqcxs08; C:\WINDOWS\system32\svchost.exe [2004-08-04 14336]
        R3 usnjsvc;Service Messenger Sharing Folders USN Journal Reader; C:\Program Files\Windows Live\Messenger\usnsvc.exe [2007-10-18 98328]
        S2 ATI Smart;ATI Smart; C:\WINDOWS\system32\ati2sgag.exe [2005-03-22 516096]
        S3 Arrakis3;BitDefender Arrakis Server; C:\Program Files\Fichiers communs\BitDefender\BitDefender Arrakis Server\bin\Arrakis3.exe [2008-07-17 118784]
        S3 aspnet_state;Service d'état ASP.NET; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2007-10-24 33800]
        S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2007-10-24 70144]
        S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe [2006-10-20 36864]
        S3 gusvc;Google Updater Service; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2007-02-14 138168]
        S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe [2004-10-22 73728]
        S3 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2006-10-30 741376]
        S3 ose;Office Source Engine; C:\Program Files\Fichiers communs\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
        S3 scan;BitDefender Threat Scanner; C:\WINDOWS\System32\svchost.exe [2004-08-04 14336]
        S3 WLSetupSvc;Windows Live Setup Service; C:\Program Files\Windows Live\installer\WLSetupSvc.exe [2007-10-25 266240]
        S3 WMPNetworkSvc;Service Partage réseau du Lecteur Windows Media; C:\Program Files\Windows Media Player\WMPNetwk.exe [2006-11-03 918016]
        S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2004-08-04 14336]
        S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2006-10-30 122880]

        -----------------EOF-----------------

        info.txt logfile of random's system information tool 1.06 2009-04-14 18:06:25

        ======Uninstall list======

        -->C:\PROGRA~1\CLUB-I~1\LECOMP~1\Uninstall.exe TONLFR
        -->C:\Program Files\Ahead\nero\uninstall\UNNERO.exe /UNINSTALL
        -->C:\Program Files\Fichiers communs\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
        -->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
        32 Bit HP CIO Components Installer-->MsiExec.exe /I{F1E63043-54FC-429B-AB2C-31AF9FBA4BC7}
        Adobe Flash Player 10 Plugin-->C:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe
        Adobe Flash Player 9 ActiveX-->C:\WINDOWS\system32\Macromed\Flash\FlashUtil9b.exe -uninstallDelete
        Adobe Flash Player ActiveX-->C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
        Adobe Reader 9.1 - Français-->MsiExec.exe /I{AC76BA86-7AD7-1036-7B44-A91000000001}
        Adobe Shockwave Player 11-->C:\WINDOWS\system32\adobe\SHOCKW~1\UNWISE.EXE C:\WINDOWS\system32\Adobe\SHOCKW~1\Install.log
        Adobe® Photoshop® Album Edition Découverte 3.2-->MsiExec.exe /I{A654A805-41D9-40C7-AA46-4AF04F044D61}
        Ad-remover-->C:\Program Files\Ad-remover\Uninstall ADR.exe
        AlphaCAM V5-->C:\WINDOWS\uninst.exe -f"C:\Program Files\ALPHAV5\DeIsL1.isu" -c"C:\Program Files\ALPHAV5\UnInst\Uninst.dll"
        ArcSoft PhotoStudio 5.5-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{230CCBE9-14B0-4008-97AF-30C10F99E42C}\setup.exe" -l0x40c
        Assistant de connexion Windows Live-->MsiExec.exe /I{AFA4E5FD-ED70-4D92-99D0-162FD56DC986}
        ATI - Utilitaire de désinstallation du logiciel-->C:\Program Files\ATI Technologies\UninstallAll\AtiCimUn.exe
        ATI Control Panel-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{0BEDBD4E-2D34-47B5-9973-57E62B29307C}\setup.exe"
        ATI Display Driver-->rundll32 C:\WINDOWS\system32\atiiiexx.dll,_InfEngUnInstallINFFile_RunDLL@16 -force_restart -flags:0x2010001 -inf_class:DISPLAY -clean
        AutoCAD LT 2004-->MsiExec.exe /I{5783F2D7-0209-040C-0000-0060B0CE6BBA}
        Autodesk Express Viewer-->C:\PROGRA~1\Autodesk\AUTODE~1\Setup.exe /remove
        BitDefender Internet Security 2009-->MsiExec.exe /X{C85FDDDE-B087-48FB-B0B2-52ABB465C304}
        BroadJump Client Foundation-->C:\WINDOWS\IsUninst.exe -f"C:\Program Files\BroadJump\Client Foundation\Uninst.isu" -c"C:\Program Files\BroadJump\Client Foundation\RmvBJCFD.dll" -b"CFD" -h"CFD" -a
        CamfrogWEB Advanced ActiveX Plugin (remove only)-->"C:\Program Files\CFWebAdvancedU\Uninstall.exe"
        CCleaner (remove only)-->"C:\Program Files\CCleaner\uninst.exe"
        Club Internet Agent Wi-Fi V2.1-->C:\Program Files\Club-Internet\Agent Wi-Fi V2.1\uninstall.exe
        Club Internet Service Photos-->C:\PROGRA~1\CLUB-I~1\SERVIC~1\UNWISE.EXE C:\PROGRA~1\CLUB-I~1\SERVIC~1\INSTALL.LOG
        Codeur Windows Media Série 9-->msiexec.exe /I {E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}
        Codeur Windows Media Série 9-->MsiExec.exe /I{E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}
        Configurateur Modem-->"C:\Program Files\Club-Internet\Assistance\uninstall.exe"
        dBpoweramp Music Converter-->"C:\WINDOWS\system32\SpoonUninstall.exe" <uninstall>C:\WINDOWS\system32\SpoonUninstall-dBpoweramp Music Converter.dat
        Digital MultiCam Driver-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F2483E13-2229-4448-AFDF-B675E83F812D}\Setup.exe" -l0x40c
        DK2 DESkey Drivers-->C:\WINDOWS\ISUNINST.EXE -f"C:\Program Files\DESkey\DK2 DESkey Drivers\Uninst.isu" -cC:\WINDOWS\system32\DKxUINST.DLL -KeyType:2 -Type:0
        Ecran de veille AOL Photos-->C:\Program Files\Fichiers communs\AOL\Screensaver\uninst_ygpss.exe
        Express Burn-->C:\Program Files\NCH Swift Sound\ExpressBurn\uninst.exe
        Fast Covers Maker-->C:\WINDOWS\st6unst.exe -n "c:\Gravure CD\ST6UNST.000"
        filehippo.com Update Checker-->"C:\Program Files\filehippo.com\uninstall.exe"
        FMS-->C:\Program Files\FMS\Uninstall.exe
        Google Toolbar for Internet Explorer-->regsvr32 /u /s "c:\program files\google\googletoolbar4.dll"
        Google Video Player-->"C:\Program Files\Google\Google Video Player\Uninstall.exe"
        HASP Device Driver-->C:\WINDOWS\system32\UNWISE.EXE C:\WINDOWS\system32\hdd32.log
        Hotfix for Windows Media Format 11 SDK (KB929399)-->"C:\WINDOWS\$NtUninstallKB929399$\spuninst\spuninst.exe"
        HP Customer Participation Program 9.0-->C:\Program Files\HP\Digital Imaging\ExtCapUninstall\hpzscr01.exe -datfile hpqhsc01.dat
        HP Imaging Device Functions 9.0-->C:\Program Files\HP\Digital Imaging\DeviceManagement\hpzscr01.exe -datfile hpqbud01.dat
        HP OCR Software 9.0-->C:\Program Files\HP\Digital Imaging\OCR\hpzscr01.exe -datfile hpqbud11.dat
        HP Photosmart All-In-One Software 9.0-->C:\Program Files\HP\Digital Imaging\{B09BCBF6-87EE-4403-A336-3A9510856535}\setup\hpzscr01.exe -datfile hposcr15.dat
        HP Photosmart Essential 2.01-->C:\Program Files\HP\Digital Imaging\PhotoSmartEssential\hpzscr01.exe -datfile hpqbud13.dat
        HP Product Assistant-->MsiExec.exe /I{36FDBE6E-6684-462B-AE98-9A39A1B200CC}
        HP Smart Web Printing-->MsiExec.exe /X{415CDA53-9100-476F-A7B2-476691E117C7}
        HP Solution Center 9.0-->C:\Program Files\HP\Digital Imaging\eSupport\hpzscr01.exe -datfile hpqbud05.dat
        HP Update-->MsiExec.exe /X{7059BDA7-E1DB-442C-B7A1-6144596720A4}
        HPSSupply-->MsiExec.exe /X{487B0B9B-DCD4-440D-89A0-A6EDE1A545A3}
        J2SE Runtime Environment 5.0 Update 10-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0150100}
        J2SE Runtime Environment 5.0 Update 2-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0150020}
        J2SE Runtime Environment 5.0 Update 4-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0150040}
        J2SE Runtime Environment 5.0 Update 6-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0150060}
        Japanese Fonts Support For Adobe Reader 8-->MsiExec.exe /I{AC76BA86-7AD7-5760-0000-800000000003}
        Java(TM) 6 Update 13-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216010FF}
        Java(TM) 6 Update 5-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160050}
        Java(TM) 6 Update 7-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160070}
        Korean Fonts Support For Adobe Reader 8-->MsiExec.exe /I{AC76BA86-7AD7-5670-0000-800000000003}
        LE COMPAGNON CLUB-->C:\WINDOWS\Motive\TONLFR\MCCUninst.exe
        Learn2 Player (Uninstall Only)-->C:\Program Files\Learn2.com\StRunner\stuninst.exe
        Lecteur Windows Media 11-->"C:\Program Files\Windows Media Player\Setup_wm.exe" /Uninstall
        LG USB Modem driver [KU580]-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\10\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{510EB43C-2D49-4E9A-8448-DD2E89D6E182}\setup.exe" -l0x40c -removeonly
        Logiciel QuickCam de Logitech-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\09\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{C43048A9-742C-4DAD-90D2-E3B53C9DB825}\setup.exe" -l0x40c
        Logitech Print Service-->C:\PROGRA~1\Logitech\PRINTS~1\UNWISE.EXE C:\PROGRA~1\Logitech\PRINTS~1\INSTALL.LOG
        Malwarebytes' Anti-Malware-->"C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
        Manual CanoScan LiDE 35-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{6AA4C799-BF98-4573-9C83-0C8E4EA46D14}\setup.exe" -l0x40c
        MGI PhotoSuite 8.1 (suppression seulement)-->C:\WINDOWS\IsUn040c.exe -f"C:\Program Files\MGI\PhotoSuite 8.1\Uninst.isu"
        Microsoft .NET Framework 2.0 Service Pack 1-->MsiExec.exe /I{B508B3F1-A24A-32C0-B310-85786919EF28}
        Microsoft .NET Framework 3.0 French Language Pack-->MsiExec.exe /X{E3C080B0-23F5-49AF-89F8-8E8DBC89E659}
        Microsoft .NET Framework 3.0-->C:\WINDOWS\Microsoft.NET\Framework\v3.0\Microsoft .NET Framework 3.0\setup.exe
        Microsoft ActiveSync-->MsiExec.exe /I{99052DB7-9592-4522-A558-5417BBAD48EE}
        Microsoft Office Professional Edition 2003-->MsiExec.exe /I{9011040C-6000-11D3-8CFE-0150048383C9}
        Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
        Mise à jour pour Windows XP (KB929338)-->"C:\WINDOWS\$NtUninstallKB929338$\spuninst\spuninst.exe"
        Module de prise en charge linguistique de Microsoft .NET Framework 2.0 - FRA-->C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0 Language Pack - FRA\install.exe
        Module de prise en charge linguistique du français de Microsoft .NET Framework 3.0-->c:\WINDOWS\Microsoft.NET\Framework\v3.0\Microsoft .NET Framework 3.0 French Language Pack\setup.exe
        Mozilla Firefox (3.0.8)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
        MSN-->C:\Program Files\MSN\MsnInstaller\msninst.exe /Action:ARP
        MSXML 4.0 SP2 (KB936181)-->MsiExec.exe /I{C04E32E0-0416-434D-AFB9-6969D703A9EF}
        MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
        MSXML 6 Service Pack 2 (KB954459)-->MsiExec.exe /I{1A528690-6A2D-4BC5-B143-8C4AE8D19D96}
        Navman F20 Service Pack-->C:\Program Files\InstallShield Installation Information\{D972C4DC-0E76-4698-A2B4-ABEFA25FFB9E}\setup.exe -runfromtemp -l0x040c -removeonly
        Nero Suite-->C:\Program Files\Fichiers communs\Nero\Uninstall\Setupx.exe /uninstall ExtraUninstallID=""
        NVIDIA Drivers-->C:\WINDOWS\system32\NVUNINST.EXE UninstallGUI
        Olitec Speed'Com USB V92 Ready-->C:\Program Files\CONEXANT\CNXT_MODEM_USB_VID_08E3&PID_0111\HXFSETUP.EXE -U -IVID_08E3&PID_0111
        OmniPage SE 2.0-->MsiExec.exe /I{79D5997E-BF79-48BB-8B41-9BE59C15C2D7}
        OpenOffice.org Installer 1.0-->MsiExec.exe /X{3A2AF807-9F9F-43C9-A24A-17B617238B74}
        Paint.NET v3.36-->MsiExec.exe /X{43602F34-1AA3-44FB-AEB2-D08C2C73743F}
        Programme de gestion Camera de Logitech®-->"C:\Program Files\Fichiers communs\Logitech\QCDRV\BIN\SETUP.EXE" UNINSTALL REMOVEPROMPT
        QuickTime-->C:\WINDOWS\unvise32qt.exe C:\WINDOWS\system32\QuickTime\Uninstall.log
        RealPlayer-->C:\Program Files\Fichiers communs\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
        Rhapsody Player Engine-->MsiExec.exe /I{30C2FCD0-FF7B-4FFA-8DDE-43A22E01A1E7}
        Security Update for CAPICOM (KB931906)-->MsiExec.exe /I{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
        Security Update for CAPICOM (KB931906)-->MsiExec.exe /X{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
        TomTom HOME 2.6.1.1549-->C:\Program Files\TomTom HOME 2\Uninstall TomTom HOME.exe
        TomTom HOME Visual Studio Merge Modules-->MsiExec.exe /I{8F3C31C5-9C3A-4AA8-8EFA-71290A7AD533}
        upapp-->MsiExec.exe /I{4EF69D40-4DC9-485E-95D3-B1C22F218FC8}
        Versato 1.9.1-->C:\WINDOWS\IsUn040c.exe -f"C:\Program Files\MediaKey\Uninst.isu"
        VideoLAN VLC media player 0.8.6b-->C:\Program Files\VideoLAN\VLC\uninstall.exe
        Viewpoint Media Player-->C:\Program Files\Viewpoint\Viewpoint Experience Technology\mtsAxInstaller.exe /u
        WavePad Uninstall-->C:\Program Files\NCH Swift Sound\WavePad\uninst.exe
        Windows Communication Foundation-->MsiExec.exe /X{491DD792-AD81-429C-9EB4-86DD3D22E333}
        Windows Live installer-->MsiExec.exe /X{FD44E544-E7D0-4DBA-9FA0-8AE1A1300390}
        Windows Live Messenger-->MsiExec.exe /X{BADF6744-3787-48F6-B8C9-4C4995401D65}
        Windows Media Format 11 runtime-->"C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll
        Windows Presentation Foundation Language Pack (FRA)-->MsiExec.exe /X{6901DD22-527A-41EF-9059-E81FEDE9E494}
        Windows Presentation Foundation-->MsiExec.exe /X{BAF78226-3200-4DB4-BE33-4D922A799840}
        Windows Workflow Foundation FR Language Pack-->MsiExec.exe /I{B84C141C-9A13-44BE-9A69-301D7B11D836}
        Windows Workflow Foundation-->MsiExec.exe /I{7D1B85BD-AA07-48B8-808D-67A4067FC6BD}
        WinRAR archiver-->C:\Program Files\WinRAR\uninstall.exe

        ======Hosts File======

        127.0.0.1 localhost

        ======Security center information======

        AV: Antivirus BitDefender
        FW: Pare-feu BitDefender

        ======System event log======

        Computer Name: MAXWELL
        Event Code: 7023
        Message: Le service Gestionnaire de connexions d'accès distant s'est arrêté avec l'erreur :
        Accès refusé.

        Record Number: 78475
        Source Name: Service Control Manager
        Time Written: 20090407173326.000000+120
        Event Type: erreur
        User:

        Computer Name: MAXWELL
        Event Code: 7036
        Message: Le service Gestionnaire de connexions d'accès distant est entré dans l'état : arrêté.

        Record Number: 78474
        Source Name: Service Control Manager
        Time Written: 20090407173326.000000+120
        Event Type: Informations
        User:

        Computer Name: MAXWELL
        Event Code: 7035
        Message: Un contrôle Démarrer a correctement été envoyé au service Gestionnaire de connexions d'accès distant.

        Record Number: 78473
        Source Name: Service Control Manager
        Time Written: 20090407173326.000000+120
        Event Type: Informations
        User: MAXWELL\Maxwell

        Computer Name: MAXWELL
        Event Code: 20035
        Message: Le Gestionnaire de connexion d'accès distant n'a pas pu démarrer car il n'a pas pu créer
        de tampons mémoire. Redémarrez l'ordinateur. Accès refusé.

        Record Number: 78472
        Source Name: Rasman
        Time Written: 20090407173326.000000+120
        Event Type: erreur
        User:

        Computer Name: MAXWELL
        Event Code: 7023
        Message: Le service Gestionnaire de connexions d'accès distant s'est arrêté avec l'erreur :
        Accès refusé.

        Record Number: 78471
        Source Name: Service Control Manager
        Time Written: 20090407172304.000000+120
        Event Type: erreur
        User:

        =====Application event log=====

        Computer Name: MAXWELL
        Event Code: 301
        Message: MsnMsgr (2528) \\.\C:\Documents and Settings\Maxwell\Local Settings\Application Data\Microsoft\Messenger\max9525@hotmail.com\SharingMetadata\Working\database_14EC_3413_EC33_ED9C\dfsr.db: Le moteur de base de données commence la relecture du fichier journal \\.\C:\Documents and Settings\Maxwell\Local Settings\Application Data\Microsoft\Messenger\max9525@hotmail.com\SharingMetadata\Working\database_14EC_3413_EC33_ED9C\fsr01AD5.log.

        Record Number: 54010
        Source Name: ESENT
        Time Written: 20090302062907.000000+060
        Event Type: Informations
        User:

        Computer Name: MAXWELL
        Event Code: 300
        Message: MsnMsgr (2528) \\.\C:\Documents and Settings\Maxwell\Local Settings\Application Data\Microsoft\Messenger\max9525@hotmail.com\SharingMetadata\Working\database_14EC_3413_EC33_ED9C\dfsr.db: Le moteur de base de données initialise la procédure de récupération.

        Record Number: 54009
        Source Name: ESENT
        Time Written: 20090302062907.000000+060
        Event Type: Informations
        User:

        Computer Name: MAXWELL
        Event Code: 102
        Message: MsnMsgr (2528) \\.\C:\Documents and Settings\Maxwell\Local Settings\Application Data\Microsoft\Messenger\max9525@hotmail.com\SharingMetadata\Working\database_14EC_3413_EC33_ED9C\dfsr.db: Le moteur de base de données a démarré une nouvelle instance (0).

        Record Number: 54008
        Source Name: ESENT
        Time Written: 20090302062905.000000+060
        Event Type: Informations
        User:

        Computer Name: MAXWELL
        Event Code: 100
        Message: MsnMsgr (2528) Le moteur de base de données 5.01.2600.2780 est démarré.

        Record Number: 54007
        Source Name: ESENT
        Time Written: 20090302062905.000000+060
        Event Type: Informations
        User:

        Computer Name: MAXWELL
        Event Code: 12001
        Message: The Messenger Sharing USN Journal Reader service started successfully.

        Record Number: 54006
        Source Name: usnjsvc
        Time Written: 20090302062902.000000+060
        Event Type:
        User:

        ======Environment variables======

        "ComSpec"=%SystemRoot%\system32\cmd.exe
        "Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;C:\Program Files\ATI Technologies\ATI Control Panel;C:\Program Files\Fichiers communs\Autodesk Shared\
        "windir"=%SystemRoot%
        "FP_NO_HOST_CHECK"=NO
        "OS"=Windows_NT
        "PROCESSOR_ARCHITECTURE"=x86
        "PROCESSOR_LEVEL"=15
        "PROCESSOR_IDENTIFIER"=x86 Family 15 Model 12 Stepping 0, AuthenticAMD
        "PROCESSOR_REVISION"=0c00
        "NUMBER_OF_PROCESSORS"=1
        "PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
        "TEMP"=%SystemRoot%\TEMP
        "TMP"=%SystemRoot%\TEMP

        -----------------EOF-----------------
    4. Bonsoir,

      Eh bien, j'ai refait toutes les manipulations de ton dernier message.
      Il semblerait que mon PC ne se comporte guère mieux qu'avant...
      Je colle ci-dessous les différents rapports obtenus.
      D'autre part, l'installation d'Adobe (après suppression de la version antérieure), a durée plus
      d'une heure... Je doute que ce soit normal.
      A bientôt.
      Bonne nuit.

      Max

      RaProducts' PureRa v1.3
      Log created at 16:47 on 13/04/2009
      ===================================

      C:\Config.msi\670ec6.rbf << Unable to Delete.
      C:\Config.msi\670ec8.rbf << Unable to Delete.
      C:\Config.msi\670f37.rbf << Deleted.
      C:\WINDOWS\system32\fntcache.dat << Deleted.
      C:\WINDOWS\SoftwareDistribution\DataStore\Logs\edb.chk << Deleted.
      C:\WINDOWS\SoftwareDistribution\DataStore\Logs\edb.log << Deleted.
      C:\WINDOWS\SoftwareDistribution\DataStore\Logs\edb00001.log << Deleted.
      C:\WINDOWS\SoftwareDistribution\DataStore\Logs\res1.log << Deleted.
      C:\WINDOWS\SoftwareDistribution\DataStore\Logs\res2.log << Deleted.
      C:\WINDOWS\SoftwareDistribution\DataStore\DataStore.edb << Deleted.C:\Documents and Settings\LocalService\Local Settings\desktop.ini << Deleted.
      C:\Documents and Settings\LocalService\Local Settings\Historique\desktop.ini << Deleted.
      C:\Documents and Settings\LocalService\Local Settings\Historique\History.IE5\desktop.ini << Deleted.
      C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\desktop.ini << Deleted.
      C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\desktop.ini << Deleted.
      C:\Documents and Settings\Maxwell\Application Data\Microsoft\Office\Récent\Desktop.ini << Deleted.
      C:\Documents and Settings\Maxwell\Contacts\Desktop.ini << Deleted.
      C:\Documents and Settings\Maxwell\Local Settings\desktop.ini << Deleted.
      C:\Documents and Settings\Maxwell\Local Settings\Application Data\IconCache.db << Deleted.
      C:\Documents and Settings\Maxwell\Local Settings\Application Data\Microsoft\Windows Live Contacts\Desktop.ini << Deleted.
      C:\Documents and Settings\Maxwell\Local Settings\Historique\desktop.ini << Deleted.
      C:\Documents and Settings\Maxwell\Local Settings\Historique\History.IE5\desktop.ini << Deleted.
      C:\Documents and Settings\Maxwell\Local Settings\Temporary Internet Files\desktop.ini << Deleted.
      C:\Documents and Settings\Maxwell\Local Settings\Temporary Internet Files\Content.IE5\desktop.ini << Deleted.
      C:\Documents and Settings\Maxwell\Local Settings\Temporary Internet Files\Content.IE5\8LABCD23\desktop.ini << Deleted.
      C:\Documents and Settings\Maxwell\Local Settings\Temporary Internet Files\Content.IE5\AHZZUG0D\desktop.ini << Deleted.
      C:\Documents and Settings\Maxwell\Local Settings\Temporary Internet Files\Content.IE5\ENIY6B9N\desktop.ini << Deleted.
      C:\Documents and Settings\Maxwell\Local Settings\Temporary Internet Files\Content.IE5\YHIJ2345\desktop.ini << Deleted.
      C:\Documents and Settings\Maxwell\Recent\Desktop.ini << Deleted.
      C:\Documents and Settings\NetworkService\Local Settings\desktop.ini << Deleted.
      C:\RECYCLER\S-1-5-21-1547161642-412668190-839522115-1003\desktop.ini << Deleted.
      C:\WINDOWS\assembly\Desktop.ini << Unable to Delete.
      C:\WINDOWS\Tasks\desktop.ini << Unable to Delete.

      Total Space Freed: 7229096 bytes

      ===================================
      -EOF-

      [ Rapport ToolsCleaner version 2.3.4 (par A.Rothstein & dj QUIOU) ]

      --> Recherche:

      ---------------------------------
      --> Suppression:

      11 Updates Detected

      ATI Catalyst Drivers 9.4 XP
      Installed Version: Unknown 39.99MB

      CCleaner 2.18.878
      Installed Version: 2.16.0.830 3.04MB

      dBpowerAMP Music Converter 13.2
      Installed Version: 12.0.1.0 5.18MB

      Flash Player 10.0.22.87 (IE)
      Installed Version: 9.0.115.0 1.83MB

      Internet Explorer 8.0 (XP)
      Installed Version: 6.0.2900.2180 16.10MB

      QuickTime Player 7.60.92.0
      Installed Version: 6.5.0.48 20.86MB

      RealPlayer 11.0.0.614
      Installed Version: 11.0.0.446 12.71MB

      Shockwave Player 11.5.0.595
      Installed Version: 11.0.3.471 7.30MB

      VLC Media Player 0.9.9
      Installed Version: 0.8.6.2 15.97MB

      Windows Live Messenger 2009 (14.0.8064)
      Installed Version: 8.5.1302.1018 1.09MB

      WinRAR 3.80
      Installed Version: 3.50.0.0 1.18MB
      1. Contributeur sécurité
        pas de soucis j' attend e tes nouvelles bon WE
        1. Contributeur sécurité
          plus d' infection visible fait les manip suivante et dit moi si tu vois une amélioration svp
          1)Telecharge :
          -------------

          https://www.clubic.com/telecharger-fiche262022-purera.html

          "clean" , coche tout a droite , et "clean"

          si ta souris a des disfonctionnements apres ca, redemarre et c'est resolu

          et puis a faire aussi :

          2)

          ---> Télécharge ToolsCleaner2 sur ton Bureau.
          * Double-clique sur ToolsCleaner2.exe pour le lancer.
          * Clique sur Recherche et laisse le scan agir.
          * Clique sur Suppression pour finaliser.
          * Tu peux, si tu le souhaites, te servir des Options Facultatives.
          * Clique sur Quitter pour obtenir le rapport.
          * Poste le rapport (TCleaner.txt) qui se trouve à la racine de ton disque dur (C:\).

          3/

          ---> Télécharge et installe CCleaner (N'installe pas la Yahoo Toolbar) :

          https://www.commentcamarche.net/telecharger/ 168 ccleaner

          * Lance-le. Va dans Options puis Avancé et décoche la case Effacer uniquement les fichiers etc....
          * Va dans Nettoyeur, choisis Analyse. Une fois terminé, lance le nettoyage.
          * Ensuite, choisis Registre, puis Chercher des erreurs. Une fois terminé, répare toutes les erreurs tant de fois qu il en trouve a l analyse(Sauvegarde la base de registre).
          * Veille a ce que dans les options le reglage soit au demarrage de windows et réglé sur "effacement securisé" 35 passes (guttman)
          * Décoche la case plus vieux que 48 h

          stp poste tous les rapports delivrés

          si tu as deja Ccleaner ne tiens pas compte du N°3 mais fais ce qu il est demande avec

          Attention : ne pas toucher au PC pendant qu'il travaille !

          B-Nettoyage et Défragmentation de tes Disques
          *Nettoyage :
          Clic droit sur "poste de travail" ==>"ouvrir" ==>clic droit sur le disque C ==>Propriétés ==>onglet "Général"
          Cliques sur le bouton "nettoyage de disque", OK
          tu le fais pour chacun de tes disques

          *Vérifications des erreurs :
          Clic droit sur "poste de travail" ==>"ouvrir" ==>clic droit sur le disque C ==>Propriétés ==>onglet "Outil"
          "Vérifier maintenant", une boîte s'ouvre, cocher les cases :
          -réparer automatiquement les erreurs...
          -rechercher et tenter une récupération...
          --->Démarrer, ok
          Note : s'il te dis de redémarrer ton Pc pour le faire , tu redémarres et tu laisses faire, cela prend un peu de temps c'est normal
          tu le fais pour chacun de tes disques

          ensuite toujours dans le même onglet tu choisis :
          *Défragmentation :
          "défragmenter maintenant", OK
          une boîte s'ouvre, tu sélectionnes le disque à défragmenter, et tu cliques sur "analyser", puis après l'analyse, "défragmenter" . OK
          tu le fais pour chacun de tes disques

          Note : si tu as un utilitaire pour défragmenter , utilises le à la place

          pour ce faire ceci est proposé :

          https://www.clubic.com/telecharger-fiche44314-defraggler.html

          > Peux-tu vérifier ta console JAVA ici ? : https://www.java.com/fr/download/uninstalltool.jsp et installer la nouvelle version si besoin est (dans ce cas désinstalle avant l'ancienne version).
          Pour info. ou en cas de problème : http://assiste.com.free.fr/p/abc/c/anti_java.html

          > Mets à jour Acrobat si ce n'est pas le cas (désinstalle avant la version antérieure) : https://get2.adobe.com/reader/otherversions/

          > Télécharge et installe Update Checker : https://filehippo.com/windows/tuning-utilities/
          - Lance le programme. Une page web de ce type va s'ouvrir.
          - Fais les mises à jour de tous les logiciels proposés pour Update. Je ne te conseille pas de faire celles pour les versions béta (elles peuvent être instables).
          - Fais un copier/coller de la liste de éléments "Updates". Puis poste la sur le forum.
          - Une fois les mises à jour effectuées, relance ton PC.
          Tuto si problèmes : https://www.commentcamarche.net/list 9908 update checker vos logiciels sont ils a jour

          > Télécharge et installe Easy Cleaner : https://www.01net.com/telecharger/windows/Utilitaire/registre/fiches/8351.html
          (lien miroir : https://www.clubic.com/telecharger-fiche11170-easycleaner.html )
          - Lance le programme puis clique sur <Registre> puis sur <Trouver>.
          - A la fin du scan clique sur <Supprime tout> puis confirme par <Oui> puis quitte le programme.
          Si besoin tuto ici : https://www.pcparadise.fr
          et http://www.6ma.fr/tuto/easycleaner-nettoyer-windows-des-elements-obsoletes/

          > Tu peux aussi vider ta corbeille,quoi que Ccleaner le fasse tout seul

          > Si nous avons utilisé MalwaresByte's Anti-Malware : vide sa quarantaine.
          - Lance le programme puis clique sur <Quarantaine>.
          - Sélectionne tous les éléments puis clique sur <supprime>.
          - Quitte la programme.

          > Idem pour ton antivirus : vide sa quarantaine si ce n'est pas déjà fait

          > Désactive et réactive la restauration de système, pour cela : suis les instructions de ce lien :

          liens XP:

          http://service1.symantec.com/

          liens Vista :

          http://service1.symantec.com/
          ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

          Quelques conseils et recommandations pour l'avenir :

          > Passe un coup d'AGV et/ou de MalwareByte's Anti-Malware et de Ccleaner de temps en temps (1 fois par semaine à 1 fois par mois, suivant l'utilisation que tu fais de ton PC. Tu peux aussi décocher la casse dans l’onglet "Options" puis clique sur "Avancé" et décoche la case "Effacer uniquement les fichiers, du dossier temp de Windows, plus vieux que 48 heures").
          - Utilise aussi tes autres logiciels de protection (scannes antivirus, antispywares...). N'oublie pas de faire les mises à jour avant de les utiliser.
          - Pense aussi à faire une défragmentation de tes disques durs de temps en temps (garde suffisamment d'espace sur C:\ (1/3 de libre pour être à l'aise))

          > Pour bien protéger ton PC :
          [1 seul Antivirus] + [1 seul Pare feu (/!\ les routeurs et box en possèdent un)] + [Quelques Antispywares] + [Mises à Jour récentes Windows et Logiciels de Protection] + [Utilisation de Firefox -ou autres- (Internet Explorer présente des failles de sécurité qui mettent longtemps avant d'être corrigées mais il faut absolument le conserver pour les mises à jour Windows)] + [Utilisation du PC en mode Invité (= limité). Lors d'une infection en mode administrateur le PC est beaucoup plus vulnérable. Voir ICI]
          PS : En fait la meilleure des protections c'est toi même : ce que tu fais avec ton PC : où tu surfes, télécharges...ect....
          Les virus utilisent les failles de ton PC pour infecter un système. Info : http://assiste.com.free.fr/p/abc/a/zombies_et_botnets.html

          > Quelques liens utiles :
          - https://www.commentcamarche.net/list 2432 securite proteger un ordinateur contre les malwares d internet
          - https://sebsauvage.net/safehex.html
          - https://www.zebulon.fr/telechargements/securite/protection-donnees-personnelles/spywareblaster.html (= petit logiciel qui bloque l'installation d'activ-X nuisibles au PC. Fonctionne en arrière plan)

          1. Bonsoir,

            Je viens de faire le maximum de mes devoirs de vacances...
            Il y a un ou deux liens qui ne fonctionnent pas.
            Je verrai demain le comportement de mon PC et te tiendrais au courant.
            En tout cas, je te remercie de toute l'aide que tu m'as apporté.
            Si le fonctionnement de mon PC n'est toujours pas optimum je te le dirais mais, je doute que ce soit avant lundi car il y a de mes enfants qui viennent pour le week-end.
            Alors, merci pour tout et, de toute façon je te donne des nouvelles lundi.

            Bon week-end et encore merci.

            Max
        2. Contributeur sécurité
          ok peut renvoyer un rsit pour verif merci
          1. Voici les deuc fichiers après avoir éxécuté RSIT.

            Logfile of random's system information tool 1.06 (written by random/random)
            Run by Maxwell at 2009-04-10 17:35:48
            Microsoft Windows XP Professionnel Service Pack 2
            System drive C: has 119 GB (76%) free of 156 GB
            Total RAM: 511 MB (35% free)

            Logfile of Trend Micro HijackThis v2.0.2
            Scan saved at 17:35:49, on 10/04/2009
            Platform: Windows XP SP2 (WinNT 5.01.2600)
            MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
            Boot mode: Normal

            Running processes:
            C:\WINDOWS\System32\smss.exe
            C:\WINDOWS\system32\winlogon.exe
            C:\WINDOWS\system32\services.exe
            C:\WINDOWS\system32\lsass.exe
            C:\WINDOWS\system32\Ati2evxx.exe
            C:\WINDOWS\system32\svchost.exe
            C:\Program Files\Fichiers communs\BitDefender\BitDefender Update Service\livesrv.exe
            C:\Program Files\BitDefender\BitDefender 2009\vsserv.exe
            C:\WINDOWS\System32\svchost.exe
            C:\WINDOWS\system32\Ati2evxx.exe
            C:\WINDOWS\Explorer.EXE
            C:\WINDOWS\system32\spoolsv.exe
            C:\WINDOWS\SOUNDMAN.EXE
            C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
            C:\Program Files\QuickTime\qttask.exe
            C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe
            C:\WINDOWS\system32\LVCOMSX.EXE
            C:\Program Files\Logitech\Video\LogiTray.exe
            C:\Program Files\BroadJump\Client Foundation\CFD.exe
            C:\PROGRA~1\CLUB-I~1\LECOMP~1\SMARTB~1\MotiveSB.exe
            C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe
            C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
            C:\Program Files\Club-Internet\Agent Wi-Fi V2.1\McciTrayApp.exe
            C:\Program Files\BitDefender\BitDefender 2009\bdagent.exe
            C:\Program Files\Java\jre6\bin\jusched.exe
            C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
            C:\WINDOWS\system32\ctfmon.exe
            C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
            C:\Program Files\Microsoft ActiveSync\wcescomm.exe
            C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe
            C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
            C:\Program Files\MediaKey\Versato.exe
            C:\PROGRA~1\MI3AA1~1\rapimgr.exe
            C:\Program Files\Club-Internet\Le Compagnon Club\bin\mpbtn.exe
            C:\Program Files\MediaKey\MePlayer.exe
            C:\Program Files\MediaKey\OSD.EXE
            C:\Program Files\Logitech\Video\FxSvr2.exe
            C:\WINDOWS\system32\svchost.exe
            C:\Program Files\Java\jre6\bin\jqs.exe
            C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
            C:\WINDOWS\System32\svchost.exe
            C:\WINDOWS\System32\svchost.exe
            C:\WINDOWS\system32\svchost.exe
            C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe
            C:\Program Files\BitDefender\BitDefender 2009\seccenter.exe
            C:\WINDOWS\system32\wscntfy.exe
            C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
            C:\Program Files\Windows Live\Messenger\usnsvc.exe
            C:\Program Files\Mozilla Firefox\firefox.exe
            C:\Documents and Settings\Maxwell\Bureau\RSIT.exe
            C:\Program Files\Trend Micro\HijackThis\Maxwell.exe

            R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
            R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
            R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
            O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Smart Web Printing\hpswp_printenhancer.dll
            O2 - BHO: HP Print Clips - {053F9267-DC04-4294-A72C-58F732D338C0} - C:\Program Files\HP\Smart Web Printing\hpswp_framework.dll
            O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
            O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
            O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
            O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
            O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll
            O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll
            O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
            O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
            O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
            O3 - Toolbar: BitDefender Toolbar - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - C:\Program Files\BitDefender\BitDefender 2009\IEToolbar.dll
            O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
            O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
            O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
            O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
            O4 - HKLM\..\Run: [OpwareSE2] "C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe"
            O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
            O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
            O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
            O4 - HKLM\..\Run: [BJCFD] C:\Program Files\BroadJump\Client Foundation\CFD.exe
            O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\CLUB-I~1\LECOMP~1\SMARTB~1\MotiveSB.exe
            O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe"
            O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
            O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
            O4 - HKLM\..\Run: [Club-Internet_McciTrayApp] C:\Program Files\Club-Internet\Agent Wi-Fi V2.1\McciTrayApp.exe
            O4 - HKLM\..\Run: [Workflow] D:\install\Workflow.exe
            O4 - HKLM\..\Run: [BDAgent] "C:\Program Files\BitDefender\BitDefender 2009\bdagent.exe"
            O4 - HKLM\..\Run: [BitDefender Antiphishing Helper] "C:\Program Files\BitDefender\BitDefender 2009\IEShow.exe"
            O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
            O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot
            O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
            O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
            O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
            O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
            O4 - HKCU\..\Run: [TomTomHOME.exe] "C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe"
            O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
            O4 - Global Startup: LE COMPAGNON CLUB.lnk = C:\Program Files\Club-Internet\Le Compagnon Club\bin\matcli.exe
            O4 - Global Startup: Versato.lnk = C:\Program Files\MediaKey\Versato.exe
            O8 - Extra context menu item: &Recherche AOL Toolbar - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
            O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
            O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
            O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
            O9 - Extra 'Tools' menuitem: Créer un Favori de l'appareil mobile... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
            O9 - Extra button: Livre de reliures HP - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
            O9 - Extra button: Sélection intelligente HP - {700259D7-1666-479a-93B1-3250410481E8} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
            O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
            O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
            O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
            O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
            O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
            O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
            O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
            O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
            O14 - IERESET.INF: START_PAGE_URL=http://www.files-ftp.com/~unicorni/phpBB2/index.php
            O16 - DPF: CabBuilder - http://kiw.imgag.com/imgag/kiw/toolbar/download/InstallerControl.cab
            O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
            O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - http://download.divx.com/player/DivXBrowserPlugin.cab
            O16 - DPF: {EBF85371-A38F-485B-B28F-0B4C82D25937} (CUpdateCtl Object) - http://update.hpphoto.com/download/HPSWUpdate.ocx
            O23 - Service: BitDefender Arrakis Server (Arrakis3) - BitDefender S.R.L. https://www.bitdefender.fr/ - C:\Program Files\Fichiers communs\BitDefender\BitDefender Arrakis Server\bin\Arrakis3.exe
            O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
            O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
            O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
            O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe
            O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
            O23 - Service: BitDefender Desktop Update Service (LIVESRV) - BitDefender SRL - C:\Program Files\Fichiers communs\BitDefender\BitDefender Update Service\livesrv.exe
            O23 - Service: TomTomHOMEService - TomTom - C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe
            O23 - Service: BitDefender Virus Shield (VSSERV) - BitDefender S. R. L. - C:\Program Files\BitDefender\BitDefender 2009\vsserv.exe
        3. Contributeur sécurité
          Bonjour on passe a la suppression (desolé pour les temps de reponses je suis assez pris en ce moment)

          Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) suceptible d avoir été infectés sans les ouvrir

          # Double clic sur le raccourci UsbFix présent sur ton bureau

          # choisi l option 2 ( Suppression )

          # Ton bureau disparaitra et le pc redémarrera .

          # Au redémarrage , UsbFix scannera ton pc , laisse travailler l outil.

          # Ensuite post le rapport UsbFix.txt qui apparaitra avec le bureau .

          # Note : Le rapport UsbFix.txt est sauvegardé a la racine du disque.( C:\UsbFix.txt )

          ( CTRL+A Pour tout selectionner , CTRL+C pour copier et CTRL+V pour coller )

          1. Bonjour,

            Pas de problème pour les temps de réponse, il en est de même pour moi.
            Alors ci-après le rapport UsbFix.
            A bientôt.
            Merci.

            Max

            ############################## [ UsbFix V3.005 ]

            # User : Maxwell (Administrateurs) # MAXWELL
            # Update on 08/04/09 by C_XX & Chiquitine29
            # Start at: 16:34:29 | 10/04/2009

            # AMD Athlon(tm) 64 Processor 3000+
            # Microsoft Windows XP Professionnel (5.1.2600 32-bit) # Service Pack 2
            # Internet Explorer 6.0.2900.2180
            # Windows Firewall Status : Disabled
            # AV : Antivirus BitDefender 12.0 [ Enabled | Updated ]
            # FW : Pare-feu BitDefender [ Enabled ]12.0

            # A:\ # Lecteur de disquettes 3 ½ pouces
            # C:\ # Disque fixe local # 152,66 Go (115,94 Go free) # NTFS
            # D:\ # Disque CD-ROM
            # E:\ # Disque amovible
            # G:\ # Disque fixe local # 965,57 Mo (965,34 Mo free) [USB DISK] # FAT32

            ############################## [ Processus actifs ]

            C:\WINDOWS\System32\smss.exe
            C:\WINDOWS\system32\csrss.exe
            C:\WINDOWS\system32\winlogon.exe
            C:\WINDOWS\system32\services.exe
            C:\WINDOWS\system32\lsass.exe
            C:\WINDOWS\system32\Ati2evxx.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\system32\svchost.exe
            C:\Program Files\Fichiers communs\BitDefender\BitDefender Update Service\livesrv.exe
            C:\Program Files\BitDefender\BitDefender 2009\vsserv.exe
            C:\WINDOWS\System32\svchost.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\system32\logonui.exe
            C:\WINDOWS\system32\Ati2evxx.exe
            C:\WINDOWS\Explorer.EXE
            C:\WINDOWS\system32\spoolsv.exe
            C:\WINDOWS\system32\svchost.exe
            C:\Program Files\Java\jre6\bin\jqs.exe
            C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
            C:\WINDOWS\System32\svchost.exe
            C:\WINDOWS\System32\svchost.exe
            C:\WINDOWS\system32\svchost.exe
            C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe
            C:\WINDOWS\system32\wbem\wmiprvse.exe
            C:\WINDOWS\system32\wscntfy.exe
            C:\WINDOWS\System32\alg.exe
            C:\WINDOWS\system32\wbem\wmiprvse.exe

            ################## [ Fichiers # Dossiers infectieux ]

            Deleted ! C:\WINDOWS\system32\autorun.inf
            Deleted ! C:\WINDOWS\system32\tmp.reg
            Deleted ! C:\WINDOWS\system32\tmp.txt

            ################## [ Registre # Clés infectieuses ]

            # -> Not Found !

            ################## [ Registre # Mountpoint2 ]

            Deleted ! HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{23dc735b-b3db-11d9-a7dd-0011d808f71b}\Shell\AutoRun\command
            Deleted ! HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{23dc735b-b3db-11d9-a7dd-0011d808f71b}\Shell\Auto\Command
            Deleted ! HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{289a620c-7bec-11dd-ace4-0011d808f71b}\Shell\AutoRun\command
            Deleted ! HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{289a620c-7bec-11dd-ace4-0011d808f71b}\Shell\Auto\Command
            Deleted ! HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{338e8511-b1b7-11d9-b820-806d6172696f}\Shell\AutoRun\command
            Deleted ! HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{7d2b02a1-96e9-11dd-ad08-0011d808f71b}\Shell\AutoRun\command
            Deleted ! HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{7d2b02a1-96e9-11dd-ad08-0011d808f71b}\Shell\Auto\Command
            Deleted ! HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{8546cb59-00cc-11de-adb8-0011d808f71b}\Shell\AutoRun\command
            Deleted ! HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{8dc68aba-3cf1-11dc-aacf-0011d808f71b}\Shell\AutoRun\command
            Deleted ! HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{8dc68aba-3cf1-11dc-aacf-0011d808f71b}\Shell\Auto\Command

            ################## [ Listing des fichiers présent ]

            C:\AUTOEXEC.BAT
            C:\NTDETECT.COM
            C:\hinstall.exe
            C:\removewga_removewga_1.2_anglais_21437.exe
            C:\boot.ini

            ################## [ ! Fin du rapport # UsbFix V3.005 ! ]
        4. Contributeur sécurité
          le rsit montre la prescence de ADOBE R

          Telecharge et install UsbFix de C_XX & Chiquitine29

          Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) suceptible d avoir été infectés sans les ouvrir

          # Double clic sur le raccourci UsbFix présent sur ton bureau .

          # Choisi l option 1 ( Recherche )

          # Laisse travailler l outil.

          # Ensuite post le rapport UsbFix.txt qui apparaitra.

          # Note : Le rapport UsbFix.txt est sauvegardé a la racine du disque. ( C:\UsbFix.txt )

          ( CTRL+A Pour tout selectionner , CTRL+C pour copier et CTRL+V pour coller )

          # Note : "Process.exe", une composante de l'outil, est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool.
          Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.
          Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall...) d'où l'alerte émise par ces antivirus.
          --
          enseigner c est toujours apprendre
          1. Bonjour,

            Alors voici le rapport d'UsbFix.
            A bientôt.
            Merci.

            Max

            ############################## [ UsbFix V3.005 ]

            # User : Maxwell (Administrateurs) # MAXWELL
            # Update on 08/04/09 by C_XX & Chiquitine29
            # Start at: 08:47:28 | 09/04/2009

            # AMD Athlon(tm) 64 Processor 3000+
            # Microsoft Windows XP Professionnel (5.1.2600 32-bit) # Service Pack 2
            # Internet Explorer 6.0.2900.2180
            # Windows Firewall Status : Disabled
            # AV : Antivirus BitDefender 12.0 [ Enabled | Updated ]
            # FW : Pare-feu BitDefender [ Enabled ]12.0

            # A:\ # Lecteur de disquettes 3 ½ pouces
            # C:\ # Disque fixe local # 152,66 Go (115,92 Go free) # NTFS
            # D:\ # Disque CD-ROM
            # E:\ # Disque amovible # 7,69 Mo (7,66 Mo free) # FAT
            # F:\ # Disque amovible
            # G:\ # Disque fixe local # 965,57 Mo (769,22 Mo free) [USB DISK] # FAT32

            ############################## [ Processus actifs ]

            C:\WINDOWS\System32\smss.exe
            C:\WINDOWS\system32\csrss.exe
            C:\WINDOWS\system32\winlogon.exe
            C:\WINDOWS\system32\services.exe
            C:\WINDOWS\system32\lsass.exe
            C:\WINDOWS\system32\Ati2evxx.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\system32\svchost.exe
            C:\Program Files\Fichiers communs\BitDefender\BitDefender Update Service\livesrv.exe
            C:\Program Files\BitDefender\BitDefender 2009\vsserv.exe
            C:\WINDOWS\System32\svchost.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\system32\Ati2evxx.exe
            C:\WINDOWS\Explorer.EXE
            C:\WINDOWS\system32\spoolsv.exe
            C:\WINDOWS\SOUNDMAN.EXE
            C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
            C:\Program Files\QuickTime\qttask.exe
            C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe
            C:\WINDOWS\system32\LVCOMSX.EXE
            C:\Program Files\Logitech\Video\LogiTray.exe
            C:\Program Files\BroadJump\Client Foundation\CFD.exe
            C:\PROGRA~1\CLUB-I~1\LECOMP~1\SMARTB~1\MotiveSB.exe
            C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe
            C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
            C:\Program Files\Club-Internet\Agent Wi-Fi V2.1\McciTrayApp.exe
            C:\Program Files\BitDefender\BitDefender 2009\bdagent.exe
            C:\Program Files\Java\jre6\bin\jusched.exe
            C:\Program Files\Logitech\Video\FxSvr2.exe
            C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
            C:\WINDOWS\system32\ctfmon.exe
            C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
            C:\Program Files\Microsoft ActiveSync\wcescomm.exe
            C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe
            C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
            C:\Program Files\MediaKey\Versato.exe
            C:\PROGRA~1\MI3AA1~1\rapimgr.exe
            C:\Program Files\Club-Internet\Le Compagnon Club\bin\mpbtn.exe
            C:\Program Files\MediaKey\MePlayer.exe
            C:\Program Files\MediaKey\OSD.EXE
            C:\WINDOWS\system32\svchost.exe
            C:\Program Files\Java\jre6\bin\jqs.exe
            C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
            C:\WINDOWS\System32\svchost.exe
            C:\WINDOWS\System32\svchost.exe
            C:\WINDOWS\system32\svchost.exe
            C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe
            C:\Program Files\BitDefender\BitDefender 2009\seccenter.exe
            C:\WINDOWS\System32\alg.exe
            C:\WINDOWS\system32\wscntfy.exe
            C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
            C:\Program Files\Windows Live\Messenger\usnsvc.exe
            C:\Program Files\BitDefender\BitDefender 2009\uiscan.exe
            C:\WINDOWS\system32\wbem\wmiprvse.exe

            ################## [ Registre # Startup ]

            HKCU_Main: "Local Page"="C:\\WINDOWS\\system32\\blank.htm"
            HKCU_Main: "Search Page"="https://www.google.com/?gws_rd=ssl"
            HKCU_Main: "Start Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome"
            HKCU_Main: "Window Title"=""
            HKLM_logon: "Userinit"="C:\\WINDOWS\\system32\\userinit.exe,"
            HKLM_Run: SoundMan=SOUNDMAN.EXE
            HKLM_Run: ATIPTA=C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
            HKLM_Run: NeroFilterCheck=C:\WINDOWS\system32\NeroCheck.exe
            HKLM_Run: QuickTime Task="C:\Program Files\QuickTime\qttask.exe" -atboottime
            HKLM_Run: OpwareSE2="C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe"
            HKLM_Run: LVCOMSX=C:\WINDOWS\system32\LVCOMSX.EXE
            HKLM_Run: LogitechVideoRepair=C:\Program Files\Logitech\Video\ISStart.exe
            HKLM_Run: LogitechVideoTray=C:\Program Files\Logitech\Video\LogiTray.exe
            HKLM_Run: BJCFD=C:\Program Files\BroadJump\Client Foundation\CFD.exe
            HKLM_Run: Motive SmartBridge=C:\PROGRA~1\CLUB-I~1\LECOMP~1\SMARTB~1\MotiveSB.exe
            HKLM_Run: StandardInstall=
            HKLM_Run: Adobe Photo Downloader="C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe"
            HKLM_Run: HP Software Update=C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
            HKLM_Run: Adobe Reader Speed Launcher="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
            HKLM_Run: Club-Internet_McciTrayApp=C:\Program Files\Club-Internet\Agent Wi-Fi V2.1\McciTrayApp.exe
            HKLM_Run: Workflow=D:\install\Workflow.exe
            HKLM_Run: BDAgent="C:\Program Files\BitDefender\BitDefender 2009\bdagent.exe"
            HKLM_Run: BitDefender Antiphishing Helper="C:\Program Files\BitDefender\BitDefender 2009\IEShow.exe"
            HKLM_Run: SunJavaUpdateSched="C:\Program Files\Java\jre6\bin\jusched.exe"
            HKLM_Run: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents=
            HKCU_Run: LogitechSoftwareUpdate="C:\Program Files\Logitech\Video\ManifestEngine.exe" boot
            HKCU_Run: MsnMsgr="C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
            HKCU_Run: ctfmon.exe=C:\WINDOWS\system32\ctfmon.exe
            HKCU_Run: swg=C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
            HKCU_Run: H/PC Connection Agent="C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
            HKCU_Run: TomTomHOME.exe="C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe"
            HKCU_plorer: "NoDriveTypeAutoRun"=dword:00000091

            ################## [ Informations ]

            ################## [ Fichiers # Dossiers infectieux ]

            Found ! C:\WINDOWS\system32\autorun.inf
            Found ! C:\WINDOWS\system32\tmp.reg
            Found ! C:\WINDOWS\system32\tmp.txt

            ################## [ Registre # Clés infectieuses ]

            # -> Not Found !

            ################## [ Registre # Mountpoint2 ]

            Found ! HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{23dc735b-b3db-11d9-a7dd-0011d808f71b}\Shell\AutoRun\command
            Found ! HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{23dc735b-b3db-11d9-a7dd-0011d808f71b}\Shell\Auto\Command
            Found ! HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{289a620c-7bec-11dd-ace4-0011d808f71b}\Shell\AutoRun\command
            Found ! HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{289a620c-7bec-11dd-ace4-0011d808f71b}\Shell\Auto\Command
            Found ! HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{338e8511-b1b7-11d9-b820-806d6172696f}\Shell\AutoRun\command
            Found ! HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{7d2b02a1-96e9-11dd-ad08-0011d808f71b}\Shell\AutoRun\command
            Found ! HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{7d2b02a1-96e9-11dd-ad08-0011d808f71b}\Shell\Auto\Command
            Found ! HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{8546cb59-00cc-11de-adb8-0011d808f71b}\Shell\AutoRun\command
            Found ! HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{8dc68aba-3cf1-11dc-aacf-0011d808f71b}\Shell\AutoRun\command
            Found ! HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{8dc68aba-3cf1-11dc-aacf-0011d808f71b}\Shell\Auto\Command

            ################## [ ! Fin du rapport # UsbFix V3.005 ! ]
        5. Contributeur sécurité
          bonjour
          vois tu une amélioration?

          - Télécharge Random's System Information Tool (RSIT) (par random/random) sur ton Bureau.
          http://images.malwareremoval.com/random/RSIT.exe

          - Double-clique sur RSIT.exe afin de lancer le programme.

          - Clique sur Continue à l'écran Disclaimer.

          - Si l'outil HijackThis (version à jour) n'est pas présent ou non détecté sur l'ordinateur, RSIT le téléchargera (autorise l'accès dans ton pare-feu, si demandé) et tu devras accepter la licence.

          - Lorsque l'analyse sera terminée, deux fichiers texte s'ouvriront. Poste le contenu de log.txt (c'est celui qui apparaît à l'écran) ainsi que de info.txt (que tu verras dans la barre des tâches).

          Note : Les rapports sont sauvegardés dans le dossier C:\rsit.
          1. Bonjour,

            Hélas, aucune amélioration.
            Ci-dessous les deux fichiers générés pas RSIT
            A plus.

            Max

            Logfile of random's system information tool 1.06 (written by random/random)
            Run by Maxwell at 2009-04-08 14:31:07
            Microsoft Windows XP Professionnel Service Pack 2
            System drive C: has 119 GB (76%) free of 156 GB
            Total RAM: 511 MB (53% free)

            Logfile of Trend Micro HijackThis v2.0.2
            Scan saved at 14:31:20, on 08/04/2009
            Platform: Windows XP SP2 (WinNT 5.01.2600)
            MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
            Boot mode: Normal

            Running processes:
            C:\WINDOWS\System32\smss.exe
            C:\WINDOWS\system32\winlogon.exe
            C:\WINDOWS\system32\services.exe
            C:\WINDOWS\system32\lsass.exe
            C:\WINDOWS\system32\Ati2evxx.exe
            C:\WINDOWS\system32\svchost.exe
            C:\Program Files\Fichiers communs\BitDefender\BitDefender Update Service\livesrv.exe
            C:\Program Files\BitDefender\BitDefender 2009\vsserv.exe
            C:\WINDOWS\System32\svchost.exe
            C:\WINDOWS\system32\Ati2evxx.exe
            C:\WINDOWS\Explorer.EXE
            C:\WINDOWS\system32\spoolsv.exe
            C:\WINDOWS\SOUNDMAN.EXE
            C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
            C:\Program Files\QuickTime\qttask.exe
            C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe
            C:\WINDOWS\system32\LVCOMSX.EXE
            C:\Program Files\Logitech\Video\LogiTray.exe
            C:\Program Files\BroadJump\Client Foundation\CFD.exe
            C:\PROGRA~1\CLUB-I~1\LECOMP~1\SMARTB~1\MotiveSB.exe
            C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe
            C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
            C:\Program Files\Club-Internet\Agent Wi-Fi V2.1\McciTrayApp.exe
            C:\Program Files\BitDefender\BitDefender 2009\bdagent.exe
            C:\Program Files\Java\jre6\bin\jusched.exe
            C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
            C:\WINDOWS\system32\ctfmon.exe
            C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
            C:\Program Files\Microsoft ActiveSync\wcescomm.exe
            C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe
            C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
            C:\Program Files\MediaKey\Versato.exe
            C:\PROGRA~1\MI3AA1~1\rapimgr.exe
            C:\WINDOWS\system32\svchost.exe
            C:\Program Files\Club-Internet\Le Compagnon Club\bin\mpbtn.exe
            C:\Program Files\Java\jre6\bin\jqs.exe
            C:\Program Files\Logitech\Video\FxSvr2.exe
            C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
            C:\Program Files\MediaKey\MePlayer.exe
            C:\Program Files\MediaKey\OSD.EXE
            C:\WINDOWS\System32\svchost.exe
            C:\WINDOWS\System32\svchost.exe
            C:\WINDOWS\system32\svchost.exe
            C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe
            C:\Program Files\BitDefender\BitDefender 2009\seccenter.exe
            C:\WINDOWS\system32\wscntfy.exe
            C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
            C:\Program Files\Windows Live\Messenger\usnsvc.exe
            C:\Program Files\BitDefender\BitDefender 2009\uiscan.exe
            C:\WINDOWS\system32\msiexec.exe
            C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
            C:\Documents and Settings\Maxwell\Bureau\RSIT.exe
            C:\Program Files\Trend Micro\HijackThis\Maxwell.exe

            R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
            R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
            R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
            O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Smart Web Printing\hpswp_printenhancer.dll
            O2 - BHO: HP Print Clips - {053F9267-DC04-4294-A72C-58F732D338C0} - C:\Program Files\HP\Smart Web Printing\hpswp_framework.dll
            O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
            O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
            O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
            O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
            O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll
            O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll
            O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
            O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
            O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
            O3 - Toolbar: BitDefender Toolbar - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - C:\Program Files\BitDefender\BitDefender 2009\IEToolbar.dll
            O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
            O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
            O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
            O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
            O4 - HKLM\..\Run: [OpwareSE2] "C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe"
            O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
            O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
            O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
            O4 - HKLM\..\Run: [BJCFD] C:\Program Files\BroadJump\Client Foundation\CFD.exe
            O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\CLUB-I~1\LECOMP~1\SMARTB~1\MotiveSB.exe
            O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe"
            O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
            O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
            O4 - HKLM\..\Run: [Club-Internet_McciTrayApp] C:\Program Files\Club-Internet\Agent Wi-Fi V2.1\McciTrayApp.exe
            O4 - HKLM\..\Run: [Workflow] D:\install\Workflow.exe
            O4 - HKLM\..\Run: [BDAgent] "C:\Program Files\BitDefender\BitDefender 2009\bdagent.exe"
            O4 - HKLM\..\Run: [BitDefender Antiphishing Helper] "C:\Program Files\BitDefender\BitDefender 2009\IEShow.exe"
            O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
            O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot
            O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
            O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
            O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
            O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
            O4 - HKCU\..\Run: [TomTomHOME.exe] "C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe"
            O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
            O4 - Global Startup: LE COMPAGNON CLUB.lnk = C:\Program Files\Club-Internet\Le Compagnon Club\bin\matcli.exe
            O4 - Global Startup: Versato.lnk = C:\Program Files\MediaKey\Versato.exe
            O8 - Extra context menu item: &Recherche AOL Toolbar - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
            O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
            O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
            O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
            O9 - Extra 'Tools' menuitem: Créer un Favori de l'appareil mobile... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
            O9 - Extra button: Livre de reliures HP - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
            O9 - Extra button: Sélection intelligente HP - {700259D7-1666-479a-93B1-3250410481E8} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
            O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
            O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
            O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
            O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
            O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
            O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
            O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
            O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
            O14 - IERESET.INF: START_PAGE_URL=http://www.files-ftp.com/~unicorni/phpBB2/index.php
            O16 - DPF: CabBuilder - http://kiw.imgag.com/imgag/kiw/toolbar/download/InstallerControl.cab
            O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
            O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - http://download.divx.com/player/DivXBrowserPlugin.cab
            O16 - DPF: {EBF85371-A38F-485B-B28F-0B4C82D25937} (CUpdateCtl Object) - http://update.hpphoto.com/download/HPSWUpdate.ocx
            O23 - Service: BitDefender Arrakis Server (Arrakis3) - BitDefender S.R.L. https://www.bitdefender.fr/ - C:\Program Files\Fichiers communs\BitDefender\BitDefender Arrakis Server\bin\Arrakis3.exe
            O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
            O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
            O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
            O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe
            O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
            O23 - Service: BitDefender Desktop Update Service (LIVESRV) - BitDefender SRL - C:\Program Files\Fichiers communs\BitDefender\BitDefender Update Service\livesrv.exe
            O23 - Service: TomTomHOMEService - TomTom - C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe
            O23 - Service: BitDefender Virus Shield (VSSERV) - BitDefender S. R. L. - C:\Program Files\BitDefender\BitDefender 2009\vsserv.exe
        6. Contributeur sécurité
          Télécharge Malwarebytes' Anti-Malware: https://www.malekal.com/tutoriel-malwarebyte-anti-malware/­

          . sur la page cliques sur Télécharger Malwarebyte's Anti-Malware
          . enregistres le sur le bureau
          . Double cliques sur le fichier téléchargé pour lancer le processus d'installation.
          . Dans l'onglet "mise à jour", cliques sur le bouton Recherche de mise à jour
          . si le pare-feu demande l'autorisation de se connecter pour malwarebytes, acceptes
          . Une fois la mise à jour terminée,fermes Malwarebytes
          . tu double-cliques sur l'icône de malwarebytes
          . une fois ouvert rend-toi dans l'onglet, Recherche
          . Sélectionnes Exécuter un examen complet
          . Cliques sur Rechercher
          . Le scan démarre.
          . A la fin de l'analyse, un message s'affiche : L'examen s'est terminé normalement. Cliquez sur 'Afficher les résultats' pour afficher tous les objets trouvés.
          . Cliques sur Ok pour poursuivre.
          . Si des malwares ont été détectés, cliques sur Afficher les résultats
          . Sélectionnes tout (ou laisses cochés)

          . cliques sur Supprimer la sélection

          . Malwarebytes va détruire les fichiers et clés de registre et en mettre une copie dans la quarantaine.
          . Malwarebytes va ouvrir le bloc-notes et y copier le rapport d'analyse.
          . redemarre le pc
          . une fois redémarré double-cliques sur malwarebytes
          . rends toi dans l'onglet rapport/log
          . tu cliques dessus pour l'afficher une fois affiché
          . tu cliques sur edition en haut du boc notes,et puis sur sélectionner tous
          . tu recliques sur edition et puis sur copier et tu reviens sur le forum et dans ta réponse
          . tu cliques droit dans le cadre de la reponse et coller

          Si tu as besoin d'aide regarde ces tutoriels :
          https://forum.pcastuces.com/malwarebytes_antimalwares___tutoriel-f31s3.htm
          https://www.malekal.com/tutoriel-malwarebyte-anti-malware/

          1. Bonjour,

            Eh bien voilà l'étape suivante de terminée. Ci-après le rapport MalwareBytes.
            A plus tard.
            Max

            Malwarebytes' Anti-Malware 1.36
            Version de la base de données: 1951
            Windows 5.1.2600 Service Pack 2

            08/04/2009 09:33:02
            mbam-log-2009-04-08 (09-33-02).txt

            Type de recherche: Examen complet (C:\|)
            Eléments examinés: 143264
            Temps écoulé: 56 minute(s), 6 second(s)

            Processus mémoire infecté(s): 0
            Module(s) mémoire infecté(s): 0
            Clé(s) du Registre infectée(s): 0
            Valeur(s) du Registre infectée(s): 0
            Elément(s) de données du Registre infecté(s): 1
            Dossier(s) infecté(s): 0
            Fichier(s) infecté(s): 0

            Processus mémoire infecté(s):
            (Aucun élément nuisible détecté)

            Module(s) mémoire infecté(s):
            (Aucun élément nuisible détecté)

            Clé(s) du Registre infectée(s):
            (Aucun élément nuisible détecté)

            Valeur(s) du Registre infectée(s):
            (Aucun élément nuisible détecté)

            Elément(s) de données du Registre infecté(s):
            HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SecurityProviders (Broken.SecurityProviders) -> Bad: (msapsspc.dll schannel.dll digest.dll msnsspc.dll) Good: (msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll) -> Quarantined and deleted successfully.

            Dossier(s) infecté(s):
            (Aucun élément nuisible détecté)

            Fichier(s) infecté(s):
            (Aucun élément nuisible détecté)
        7. Contributeur sécurité
          ok tres bien la partie suppression maintenant

          /!\ Déconnecte-toi et ferme toutes applications en cours /!\

          ? Double-clique sur AD-Remover pour le lancer : au menu principal, choisis l'option B.

          ? Coche à l'écran de sélection :
          http://sd-1.archive-host.com/membres/up/16506160323759868/Capturer-ADR.JPG

          Suppression Boonty/BoontyGames (Si trouvé)
          Suppression Eorezo (Si trouvé)
          Suppression Everest Poker (Si trouvé)
          Suppression Funwebproduct/MyWay/MyWebsearch (Si trouvé)
          Suppression Messenger Skinner (Si trouvé)
          Suppression Sweetim (Si trouvé)

          ? Puis choisis S, le programme va travailler.

          ? Poste le rapport qui apparaît à la fin.

          (Le rapport est sauvegardé aussi sous C:\Ad-report.log)

          /!\ Si le Bureau ne réapparaît pas, presse Ctrl + Alt + Suppr, Onglet "Fichier", "Nouvelle tâche", tape explorer.exe et valide) /!\
          1. Bonsoir,

            Ci-dessous le rapport après l'opération suppression de AD-Remover.
            Max

            ------- LOGFILE OF AD-REMOVER 1.1.2.5 | ONLY XP/VISTA -------

            Updated by C_XX on 01/04/2009 at 20:00
            Contact: AdRemover.contact@gmail.com
            Website: http://pagesperso-orange.fr/FindyKill.Ad.Remover/

            **** LIMITED TO ****

            Boonty/BoontyGames
            Eorezo
            Infected Poker Softwares
            FunWebProduct/MyWay/MyWebSearch
            It's TV
            Sweetim
            Other Adwares

            ********************

            Start at: 17:55:59, Mar 07/04/2009 | Boot mode: Normal Boot
            Option: CLEAN | Executed from: C:\Program Files\Ad-remover\Ad-remover.bat
            Operating System: Microsoft® Windows XP™ Service Pack 2 (version 5.1.2600)
            Computer Name: MAXWELL
            Current User: Maxwell - Administrator
            Drive(s):
            - C:\ (File System: NTFS)
            - E:\ (File System: FAT)
            System Drive: C:\
            Windows Directory: C:\WINDOWS\
            System Directory: C:\WINDOWS\System32\

            --- Running Processes: 58

            (!) ---- IE start pages/Tabs reset

            +-----------------| Boonty/Boonty Games Elements Deleted :

            .
            HKCR\boontybox
            HKLM\Software\Boonty
            HKLM\System\ControlSet002\Enum\Root\LEGACY_BOONTY_GAMES
            .
            C:\Documents and Settings\All Users\Application Data\BOONTY

            +-----------------| Eorezo Elements Deleted :

            HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\Eoengine
            HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\Eoclock
            HKCR\Interface\{B0D071A1-36B3-4757-A126-14C89C56013A}
            HKCR\Typelib\{B4C656C9-F2E9-4E77-B3F4-443DF2BD778F}
            HKCU\Software\EoRezo
            HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{64F56FC1-1272-44CD-BA6E-39723696E350}
            HKLM\Software\EoRezo
            HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{64F56FC1-1272-44CD-BA6E-39723696E350}
            .
            C:\Program Files\EoRezo
            C:\Documents and Settings\Maxwell\Application Data\EoRezo

            +-----------------| Infected Poker Softwares Elements Deleted :

            .

            +-----------------| FunWebProducts/MyWay/MyWebSearch Elements Deleted :

            .
            .

            +-----------------| It's TV Elements Deleted :

            .

            +-----------------| Sweetim Elements Deleted :

            .

            ============ Other Adwares Deleted ============

            .
            .

            ---- Complementary Cleaning + Heuristic ----

            ... Done !

            (!) ---- Temp files deleted.
            (!) ---- Recycle bin emptied in all drives.

            +-----------------| Added Scan :

            ---- Mozilla FireFox Version 3.0.8 ----

            ProfilePath: 8wkpxk17.default (Maxwell)
            .
            .
            .
            .
            .
            .

            ---- Internet Explorer Version 6.0.2900.2180 ----

            +-[HKEY_CURRENT_USER\..\Internet Explorer\Main]

            Default_Page_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
            Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
            Search bar: hxxp://www.google.com/ie
            Search Page: hxxp://www.google.com
            Start page: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome

            +-[HKEY_USERS\S-1-5-21-1547161642-412668190-839522115-1003\..\Internet Explorer\Main]

            Default_Page_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
            Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
            Search bar: hxxp://www.google.com/ie
            Search Page: hxxp://www.google.com
            Start page: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome

            +-[HKEY_LOCAL_MACHINE\..\Internet Explorer\Main]

            Default_Page_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
            Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
            Search bar: hxxp://search.msn.com/spbasic.htm
            Search Page: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
            Start page: hxxp://fr.msn.com/

            +-[HKEY_LOCAL_MACHINE\..\Internet Explorer\ABOUTURLS]

            Tabs: hxxp://ieframe.dll/tabswelcome.htm

            +---------------------------------------------------------------------------+

            3734 Byte(s) - C:\Ad-Report-Clean-07.04.2009.log
            3370 Byte(s) - C:\Ad-Report-Scan-07.04.2009.log

            2 File(s) - C:\Program Files\Ad-remover\TOOLS\BACKUP
            0 File(s) - C:\Program Files\Ad-remover\TOOLS\QUARANTINE

            End at: 18:55:18 | 07/04/2009
            .
            +-----------------| E.O.F - 92 Lines
            .
        8. Contributeur sécurité
          Télécharge AD-Remover (de Cyrildu17 / C_XX) sur ton Bureau.

          http://sd-1.archive-host.com/membres/up/16506160323759868/AD-R.exe

          /!\ Déconnecte-toi et ferme toutes applications en cours /!\

          Double-clique sur le programme d'installation, installe-le dans son emplacement par défaut (C:\Program files).
          Double-clique sur l'icône Ad-remover située sur ton Bureau.
          Au menu principal, choisis l'option "A".
          Poste le rapport qui apparaît à la fin.

          (Le rapport est sauvegardé aussi sous C:\Ad-report(date).log)

          (CTRL+A pour tout sélectionner, CTRL+C pour copier et CTRL+V pour coller)

          Note :

          "Process.exe", une composante de l'outil, est détectée par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool.
          Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.
          Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall...) d'où l'alerte émise par ces antivirus.
          1. Bonjour,

            Voila le rapport, l'analyse a durée plus de 45 minutes.
            Max

            ------- LOGFILE OF AD-REMOVER 1.1.2.5 | ONLY XP/VISTA -------

            Updated by C_XX on 01/04/2009 at 20:00
            Contact: AdRemover.contact@gmail.com
            Website: http://pagesperso-orange.fr/FindyKill.Ad.Remover/

            Start at: 9:57:25, Mar 07/04/2009 | Boot mode: Normal Boot
            Option: SCAN | Executed from: C:\Program Files\Ad-remover\Ad-remover.bat
            Operating System: Microsoft® Windows XP™ Service Pack 2 (version 5.1.2600)
            Computer Name: MAXWELL
            Current User: Maxwell - Administrator
            Drive(s):
            - C:\ (File System: NTFS)
            - E:\ (File System: FAT)
            System Drive: C:\
            Windows Directory: C:\WINDOWS\
            System Directory: C:\WINDOWS\System32\

            --- Running Processes: 58

            +-----------------| Boonty/Boonty Games Elements Found:

            .
            HKCR\boontybox
            HKLM\Software\Boonty
            HKLM\Software\Classes\boontybox
            HKLM\System\ControlSet002\Enum\Root\LEGACY_BOONTY_GAMES
            .
            C:\Documents and Settings\All Users\Application Data\BOONTY

            +-----------------| Eorezo Elements Found:

            HKCR\Interface\{B0D071A1-36B3-4757-A126-14C89C56013A}
            HKCR\Typelib\{B4C656C9-F2E9-4E77-B3F4-443DF2BD778F}
            HKCU\Software\EoRezo
            HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{64F56FC1-1272-44CD-BA6E-39723696E350}
            HKLM\Software\EoRezo
            HKLM\Software\Classes\TypeLib\{B4C656C9-F2E9-4E77-B3F4-443DF2BD778F}
            HKLM\Software\Classes\Interface\{B0D071A1-36B3-4757-A126-14C89C56013A}
            HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{64F56FC1-1272-44CD-BA6E-39723696E350}
            HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\Eoengine
            HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\Eoclock
            .
            C:\Program Files\EoRezo
            C:\Documents and Settings\Maxwell\Application Data\EoRezo

            +-----------------| Infected Poker Softwares Elements Found:

            .

            +-----------------| FunWebProducts/MyWay/MyWebSearch Elements Found:

            .
            .

            +-----------------| It's TV Elements Found:

            .

            +-----------------| Sweetim Elements Found:

            .

            ============ Other Adwares Found ============

            .
            .
            C:\Documents and Settings\Maxwell\Cookies\maxwell@atdmt[1].txt

            +-----------------| Added Scan:

            ---- Mozilla FireFox Version 3.0.8 ----

            ProfilePath: 8wkpxk17.default (Maxwell)
            .
            .
            .
            .
            .
            .

            ---- Internet Explorer Version 6.0.2900.2180 ----

            +-[HKEY_CURRENT_USER\..\Internet Explorer\Main]

            Search bar: hxxp://www.google.com/ie
            Search Page: hxxp://www.google.com
            Start page: hxxp://www.club-internet.fr

            +-[HKEY_USERS\S-1-5-21-1547161642-412668190-839522115-1003\..\Internet Explorer\Main]

            Search bar: hxxp://www.google.com/ie
            Search Page: hxxp://www.google.com
            Start page: hxxp://www.club-internet.fr

            +-[HKEY_LOCAL_MACHINE\..\Internet Explorer\Main]

            Default_Page_URL: hxxp://www.files-ftp.com/~unicorni/phpBB2/index.php
            Default_Search_URL: hxxp://www.google.com/ie
            Search Page: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
            Start page: hxxp://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home

            +-[HKEY_LOCAL_MACHINE\..\Internet Explorer\ABOUTURLS]

            +---------------------------------------------------------------------------+

            3130 Byte(s) - C:\Ad-Report-Scan-07.04.2009.log

            0 File(s) - C:\Program Files\Ad-remover\TOOLS\BACKUP
            0 File(s) - C:\Program Files\Ad-remover\TOOLS\QUARANTINE

            End at: 10:53:49 | 07/04/2009
            .
            +-----------------| E.O.F - 76 Lines
            .