Rapport comboFix

Bonjour,
j'ai éffectué un scan de mon ordinateur avec comboFix que je viens de télécharger, pouvez vous m'aider à savoir si tout va bien. Merci
Le rapport est le suivant:
ComboFix 09-05-02.4 - ale 03/05/2009 7:58.1 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.3.1252.33.1036.18.2038.1535 [GMT 2:00]
Lancé depuis: c:\documents and settings\ale\Bureau\ComboFix.exe
AV: Avira AntiVir PersonalEdition *On-access scanning disabled* (Updated)
FW: Norton Internet Worm Protection *disabled*
.

(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.

D:\Autorun.inf

.
((((((((((((((((((((((((((((( Fichiers créés du 2009-04-03 au 2009-05-03 ))))))))))))))))))))))))))))))))))))
.

2009-04-30 13:50 . 2009-04-30 13:50 -------- d-----w c:\program files\Bouygues
2009-04-28 19:02 . 2009-04-29 20:28 -------- d-----w c:\program files\adslTV
2009-04-18 21:26 . 2006-10-12 03:09 94208 --sh--w c:\windows\system32\SalaatTime.dll
2009-04-18 21:25 . 2009-04-18 21:26 -------- d-----w c:\program files\Salaat Time
2009-04-18 20:25 . 2009-04-18 20:25 -------- d-----w c:\windows\system32\athan
2009-04-18 20:25 . 2009-04-18 21:21 -------- d-----w c:\program files\Athan
2009-04-16 16:08 . 2009-02-06 10:10 227840 ------w c:\windows\system32\dllcache\wmiprvse.exe
2009-04-16 16:08 . 2009-03-06 14:20 286720 ------w c:\windows\system32\dllcache\pdh.dll
2009-04-16 16:08 . 2009-02-09 11:23 111104 ------w c:\windows\system32\dllcache\services.exe
2009-04-16 16:08 . 2009-02-09 10:53 401408 ------w c:\windows\system32\dllcache\rpcss.dll
2009-04-16 16:08 . 2009-02-09 10:53 473600 ------w c:\windows\system32\dllcache\fastprox.dll
2009-04-16 16:08 . 2009-02-06 10:39 35328 ------w c:\windows\system32\dllcache\sc.exe
2009-04-16 16:08 . 2009-02-09 10:53 685568 ------w c:\windows\system32\dllcache\advapi32.dll
2009-04-16 16:08 . 2009-02-09 10:53 735744 ------w c:\windows\system32\dllcache\lsasrv.dll
2009-04-16 16:08 . 2009-02-09 10:53 453120 ------w c:\windows\system32\dllcache\wmiprvsd.dll
2009-04-16 16:08 . 2009-02-09 10:53 739840 ------w c:\windows\system32\dllcache\ntdll.dll
2009-04-16 16:00 . 2008-12-16 12:31 354304 ------w c:\windows\system32\dllcache\winhttp.dll
2009-04-16 15:56 . 2008-04-21 21:15 219136 ------w c:\windows\system32\dllcache\wordpad.exe
2009-04-15 18:28 . 2009-04-15 18:28 -------- d-----w c:\documents and settings\ale\Local Settings\Application Data\Help
2009-04-13 10:32 . 2009-04-13 10:32 179 ----a-w C:\handle.dat
2009-04-10 16:19 . 2009-04-10 16:19 -------- d-----w c:\program files\uTorrent
2009-04-10 16:19 . 2009-04-16 13:55 -------- d-----w c:\documents and settings\ale\Application Data\uTorrent
2009-04-07 11:30 . 2009-04-07 11:30 -------- d-----w c:\documents and settings\ale\Application Data\DivX
2009-04-07 11:29 . 2009-02-24 19:35 120056 ------w c:\windows\system32\pxcpyi64.exe
2009-04-07 11:29 . 2009-02-24 19:35 118520 ------w c:\windows\system32\pxinsi64.exe
2009-04-07 11:28 . 2009-04-07 11:28 -------- d-----w c:\program files\Fichiers communs\DivX Shared
2009-04-07 11:28 . 2009-04-07 11:29 -------- d-----w c:\program files\DivX
2009-04-05 18:48 . 2009-04-05 18:48 -------- d-----w c:\program files\NCH Software
2009-04-05 18:42 . 2009-04-05 18:42 -------- d-----w c:\documents and settings\All Users\Application Data\NCH Swift Sound
2009-04-05 17:13 . 2009-04-05 17:13 -------- d-----w c:\documents and settings\ale\Application Data\AVS4YOU
2009-04-05 17:13 . 2009-04-05 17:13 -------- d-----w c:\documents and settings\All Users\Application Data\AVS4YOU
2009-04-05 17:13 . 2009-04-05 17:36 -------- d-----w c:\program files\Fichiers communs\AVSMedia
2009-04-05 17:13 . 2003-05-21 10:50 24576 ----a-w c:\windows\system32\msxml3a.dll
2009-04-05 17:13 . 2009-04-05 17:36 -------- d-----w c:\program files\AVS4YOU
2009-04-05 16:55 . 2009-04-05 16:55 -------- d-----w c:\documents and settings\ale\Local Settings\Application Data\WinAVI
2009-04-05 12:10 . 2009-04-05 12:10 -------- d-----w c:\program files\Fichiers communs\xing shared
2009-04-05 08:52 . 2009-04-05 08:53 -------- d-----w c:\documents and settings\ale\Application Data\Nero
2009-04-04 20:11 . 2009-04-05 16:52 -------- d-----w c:\program files\Nero
2009-04-04 20:10 . 2009-04-05 17:05 -------- d-----w c:\documents and settings\All Users\Application Data\Nero
2009-04-04 20:10 . 2009-04-05 17:06 -------- d-----w c:\program files\Fichiers communs\Nero
2009-04-04 18:46 . 2008-04-13 18:40 149376 ----a-w c:\windows\system32\dllcache\tffsport.sys
2009-04-04 18:46 . 2008-04-13 18:40 149376 ----a-w c:\windows\system32\drivers\tffsport.sys

.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-05-03 06:03 . 2008-12-11 06:47 -------- d-----w c:\program files\Arovax AntiSpyware
2009-05-03 06:03 . 2008-09-20 22:07 -------- d-----w c:\program files\WinTV
2009-05-03 06:03 . 2006-06-29 17:10 6 ---ha-w c:\windows\Tasks\SA.DAT
2009-05-02 21:31 . 2009-02-14 17:18 876 ----a-w c:\windows\Tasks\GoogleUpdateTaskMachine.job
2009-04-28 20:55 . 2009-02-12 07:59 284 ----a-w c:\windows\Tasks\AppleSoftwareUpdate.job
2009-04-18 12:31 . 2006-06-29 16:24 68402 ----a-w c:\windows\system32\perfc00C.dat
2009-04-18 12:31 . 2006-06-29 16:24 460148 ----a-w c:\windows\system32\perfh00C.dat
2009-04-15 18:47 . 2009-04-15 18:47 454 ----a-w c:\windows\Tasks\Connexion facile à Internet.job
2009-04-09 15:36 . 2009-02-14 17:16 1000 ----a-w c:\windows\Tasks\Google Software Updater.job
2009-04-07 07:37 . 2009-01-29 12:04 -------- d-----w c:\program files\Microsoft Games
2009-04-06 10:52 . 2009-01-01 13:45 -------- d-----w c:\program files\Vuze
2009-04-06 10:51 . 2008-07-26 03:52 -------- d-----w c:\program files\Google
2009-04-05 12:10 . 2008-07-27 22:34 -------- d-----w c:\program files\Fichiers communs\Real
2009-04-05 08:52 . 2008-07-26 04:05 -------- d-----w c:\program files\Fichiers communs\LightScribe
2009-03-06 14:20 . 2006-03-25 11:00 286720 ----a-w c:\windows\system32\pdh.dll
2009-02-24 19:35 . 2008-07-30 18:35 129784 ------w c:\windows\system32\pxafs.dll
2009-02-24 19:34 . 2009-02-24 19:34 90112 ----a-w c:\windows\system32\dpl100.dll
2009-02-24 19:34 . 2009-02-24 19:34 823296 ----a-w c:\windows\system32\divx_xx0c.dll
2009-02-24 19:34 . 2009-02-24 19:34 823296 ----a-w c:\windows\system32\divx_xx07.dll
2009-02-24 19:34 . 2009-02-24 19:34 815104 ----a-w c:\windows\system32\divx_xx0a.dll
2009-02-24 19:34 . 2009-02-24 19:34 802816 ----a-w c:\windows\system32\divx_xx11.dll
2009-02-24 19:34 . 2009-02-24 19:34 684032 ----a-w c:\windows\system32\DivX.dll
2009-02-20 08:10 . 2006-03-25 11:00 670208 ----a-w c:\windows\system32\wininet.dll
2009-02-20 08:10 . 2006-03-25 11:00 81920 ----a-w c:\windows\system32\ieencode.dll
2009-02-09 14:05 . 2006-03-25 11:00 1846912 ----a-w c:\windows\system32\win32k.sys
2009-02-09 11:23 . 2006-03-25 11:00 2025984 ----a-w c:\windows\system32\ntkrnlpa.exe
2009-02-09 11:23 . 2006-03-25 11:00 2147328 ----a-w c:\windows\system32\ntoskrnl.exe
2009-02-09 11:23 . 2006-03-25 11:00 111104 ----a-w c:\windows\system32\services.exe
2009-02-09 10:53 . 2006-03-25 11:00 735744 ----a-w c:\windows\system32\lsasrv.dll
2009-02-09 10:53 . 2006-03-25 11:00 739840 ----a-w c:\windows\system32\ntdll.dll
2009-02-09 10:53 . 2006-03-25 11:00 685568 ----a-w c:\windows\system32\advapi32.dll
2009-02-09 10:53 . 2006-03-25 11:00 401408 ----a-w c:\windows\system32\rpcss.dll
2009-02-06 17:52 . 2009-02-06 17:52 49504 ----a-w c:\windows\system32\sirenacm.dll
2009-02-06 10:39 . 2006-03-25 11:00 35328 ----a-w c:\windows\system32\sc.exe
2009-02-03 19:58 . 2006-03-25 11:00 56832 ----a-w c:\windows\system32\secur32.dll
2006-10-12 03:09 . 2009-04-18 21:26 94208 --sh--w c:\windows\system32\SalaatTime.dll
.

((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-07-26 68856]
"MsnMsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-02-06 3885408]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\daemon.exe" [2008-07-24 490952]
"Messenger (Yahoo!)"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [2008-10-16 4347120]
"Arovax AntiSpyware"="c:\program files\Arovax AntiSpyware\arovaxantispyware.exe" [2007-09-21 1966080]
"LDM"="c:\program files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe" [2008-07-27 16384]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2006-11-03 204288]
"SalaatTime"="c:\program files\Salaat Time\SalaatTime.exe" [2008-05-16 13496320]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-08-06 64512]
"hpWirelessAssistant"="c:\program files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe" [2006-05-04 458752]
"SunJavaUpdateSched"="c:\program files\Java\jre1.5.0_06\bin\jusched.exe" [2005-11-11 36975]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2006-03-23 94208]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2006-03-23 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2006-03-23 118784]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-06-17 794713]
"Cpqset"="c:\program files\Hewlett-Packard\Default Settings\cpqset.exe" [2006-06-19 40960]
"RecGuard"="c:\windows\SMINST\RecGuard.exe" [2005-10-11 1187840]
"LVCOMS"="c:\program files\Fichiers communs\Logitech\QCDriver3\LVCOMS.EXE" [2002-12-10 127022]
"LogitechGalleryRepair"="c:\program files\Logitech\ImageStudio\ISStart.exe" [2002-12-10 155648]
"LogitechImageStudioTray"="c:\program files\Logitech\ImageStudio\LogiTray.exe" [2002-12-10 61440]
"HP Software Update"="c:\program files\Hp\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"avgnt"="c:\program files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-06-12 266497]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-01-05 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-01-06 290088]
"TkBellExe"="c:\program files\Fichiers communs\Real\Update_OB\realsched.exe" [2009-04-05 198160]
"High Definition Audio Property Page Shortcut"="CHDAudPropShortcut.exe" - c:\windows\system32\CHDAudPropShortcut.exe [2006-06-02 61952]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
AutoStart IR.lnk - c:\program files\WinTV\Ir.exe [2008-9-21 106551]
D‚marrage rapide de HP Photosmart Premier.lnk - c:\program files\HP\Digital Imaging\bin\hpqthb08.exe [2005-9-24 73728]
GlobeTrotter Connect.lnk - c:\program files\Bouygues\GlobeTrotter Connect\GlobeTrotter Connect.exe [2008-3-11 880640]
Lancement rapide d'Adobe Reader.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-9-23 29696]
Logitech Desktop Messenger.lnk - c:\program files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe [2008-7-28 169472]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\progra~1\bandoo\bndhook.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 nwprovau

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"AntiVirusOverride"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\backWeb-8876480.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\2K Games\\Firaxis Games\\Sid Meier's Civilization IV Colonization\\Colonization.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

R2 gupdate1c98ec843a4d890;Service Google Update (gupdate1c98ec843a4d890);c:\program files\Google\Update\GoogleUpdate.exe [2009-02-14 133104]
R3 GT72NDISIPXP;GT 72 IP NDIS;c:\windows\system32\DRIVERS\Gt51Ip.sys [2008-02-18 106624]
R3 GT72UBUS;GT 72 U BUS;c:\windows\system32\DRIVERS\gt72ubus.sys [2008-02-08 59648]
R3 GTPTSER;GT PT SER;c:\windows\system32\DRIVERS\gtptser.sys [2007-03-30 8064]
R3 MODRC;Hauppauge Nova-T IR Driver;c:\windows\system32\DRIVERS\hcw95rc.sys [2006-09-27 15104]
S0 tffsport;M-Systems DiskOnChip 2000;c:\windows\system32\DRIVERS\tffsport.sys [2008-04-13 149376]
S2 Bandoo Coordinator;Bandoo Coordinator;c:\progra~1\Bandoo\Bandoo.exe [2009-02-18 1484736]
S2 EPGService;EPGService;c:\progra~1\WinTV\EPG Services\System\EPGService.exe [2006-10-16 357888]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{11263403-a770-11dd-b9e1-0018de0fb330}]
\Shell\AutoRun\command - gi2ky.exe
\Shell\open\Command - gi2ky.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{19250608-22cf-11de-bb7f-0018de0fb330}]
\Shell\AutoRun\command - F:\1ogf.exe
\Shell\open\Command - F:\1ogf.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{4709a60a-a381-11dd-b9d7-0018de0fb330}]
\Shell\AutoRun\command - 22wcb21o.exe
\Shell\explore\Command - 22wcb21o.exe
\Shell\open\Command - 22wcb21o.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{8a1b7b8f-24f1-11de-bb8b-0018de0fb330}]
\Shell\AutoRun\command - 0xuc.com
\Shell\open\Command - 0xuc.com

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a7c84ab0-a2b3-11dd-b9d4-0018de0fb330}]
\Shell\AutoRun\command - F:\ino6.com
\Shell\explore\Command - F:\ino6.com
\Shell\open\Command - F:\ino6.com

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{c1a912bc-358d-11de-bbe5-0018de0fb330}]
\Shell\AutoRun\command - F:\setup.exe AUTORUN=1
.
Contenu du dossier 'Tâches planifiées'

2009-04-28 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]

2009-04-15 c:\windows\Tasks\Connexion facile à Internet.job
- c:\program files\Hewlett-Packard\SDP\HPSdpApp.exe [2005-11-16 08:55]

2009-05-02 c:\windows\Tasks\GoogleUpdateTaskMachine.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-02-14 17:18]
.
- - - - ORPHELINS SUPPRIMES - - - -

WebBrowser-{EEE6C35B-6118-11DC-9C72-001320C79847} - (no file)
WebBrowser-{90B8B761-DF2B-48AC-BBE0-BCC03A819B3B} - (no file)
HKLM-Run-WinampAgent - c:\program files\Winamp\winampa.exe

.
------- Examen supplémentaire -------
.
uStart Page = hxxp://www.google.fr/
uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = localhost;*.local
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - c:\program files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-05-03 08:03
Windows 5.1.2600 Service Pack 3 NTFS

Recherche de processus cachés ...

Recherche d'éléments en démarrage automatique cachés ...

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
Cpqset = c:\program files\Hewlett-Packard\Default Settings\cpqset.exe????????????L?@? ????f??????`?@?????L?@

Recherche de fichiers cachés ...

Scan terminé avec succès
Fichiers cachés: 0

**************************************************************************
.
--------------------- CLES DE REGISTRE BLOQUEES ---------------------

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\•€|ÿÿÿÿ"•€|þ»Ñw*]
"C040110900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"
.
--------------------- DLLs chargées dans les processus actifs ---------------------

- - - - - - - > 'explorer.exe'(3664)
c:\progra~1\FICHIE~1\MICROS~1\WEBCOM~1\10\OWC10.DLL
c:\program files\Fichiers communs\Microsoft Shared\Web Components\10\1036\OWCI10.DLL
c:\progra~1\FICHIE~1\MICROS~1\WEBCOM~1\11\OWC11.DLL
c:\program files\Fichiers communs\Microsoft Shared\Web Components\11\1036\OWCI11.DLL
c:\windows\system32\eappprxy.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Autres processus actifs ------------------------
.
c:\program files\Avira\AntiVir PersonalEdition Classic\sched.exe
c:\program files\Avira\AntiVir PersonalEdition Classic\avguard.exe
c:\program files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\ehome\ehrecvr.exe
c:\windows\ehome\ehSched.exe
c:\program files\Fichiers communs\LightScribe\LSSrvc.exe
c:\windows\ehome\mcrdsvc.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\program files\Hewlett-Packard\Shared\hpqwmiex.exe
c:\windows\ehome\ehmsas.exe
c:\windows\system32\dllhost.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\HP\Digital Imaging\bin\hpqimzone.exe
c:\program files\Bandoo\BndCore.exe
c:\program files\Yahoo!\Messenger\Ymsgr_tray.exe
.
**************************************************************************
.
Heure de fin: 2009-05-03 8:07 - La machine a redémarré
ComboFix-quarantined-files.txt 2009-05-03 06:07

Avant-CF: 21 204 041 728 octets libres
Après-CF: 25 610 944 512 octets libres

WindowsXP-KB310994-SP2-Pro-BootDisk-FRA.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Windows XP Media Center Edition" /noexecute=optin /fastdetect

270 --- E O F --- 2009-04-29 14:56
Configuration: Windows XP Internet Explorer 6.0

51 réponses

Résumé de la discussion

Un scan ComboFix sur Windows XP Professionnel a généré un rapport détaillé et la question porte sur l'état général du système et la nécessité d'actions supplémentaires. Le rapport liste des éléments en démarrage et des suppressions, notamment Bandoo Coordinator et des entrées récurrentes, ainsi que des fichiers cachés liés à des logiciels tiers. Pour les démarches suivantes, il est recommandé de mettre à jour l'antivirus, relancer un contrôle avec un autre outil et examiner les éléments suspects en démarrage, tout en restant attentif aux adwares et composants indésirables.

Bobot (l’IA à votre service)
  1. Contributeur sécurité
    Salut,

    très dangereux d'utiliser Combofix comme ceci sans l'appuie d'une personne qui s'y connait ...

    bref , infection par support amovible et plus si affinité ...

    Voilà ce que tu vas faire dans un premier temps :

    1- Supprime Combofix ainsi ( on le retéléchargera au besoin ) :

    -> Clique sur " Démarrer " -> " Executer "( ou combine la touche Windows + R ) -> copie/colle cette ligne :

    ComboFix /u

    ( laisse l'espace entre Combofix et /u )

    -> Valide .

    ========================

    2- Télécharge et installe le logiciel HijackThis :

    ici http://www.commentcamarche.net/telecharger/telecharger 159 hijackthis
    ou ici http://www.trendsecure.com/portal/en-US/_download/HJTInstall.exe
    ou ici https://www.clubic.com/telecharger-fiche17891-hijackthis.html

    -->Clique sur le setup pour lancer l'installe : laisse toi guider et ne modifie pas les paramètres d'installation .
    A la fin de l'installe , le prg se lance automatiquement : ferme le en cliquant sur la croix rouge .
    Au final, tu dois avoir un raccourci sur ton bureau et aussi un cheminement comme :
    "C:\ program files\Trend Micro\HijackThis\HijackThis.exe " .

    ( ne lance pas ce prg pour l'instant et fais la suite ... )

    3- Télécharge Random's System Information Tool (RSIT) de random/random et enregistre l'exécutable sur ton Bureau.

    -> http://images.malwareremoval.com/random/RSIT.exe

    ! Déconnecte toi et ferme toutes tes applications en cours !

    Double-clique sur " RSIT.exe " pour le lancer .

    -> Une première fenêtre s'ouvre avec en titre : " Disclaimer of warranty " .

    * Devant l'option "List files/folders created ..." , tu choisis : 2 months

    * clique ensuite sur " Continue " pour lancer l'analyse ...

    -> laisse faire le scan et ne touche pas au PC ...

    Lorsque l'analyse sera terminée, deux fichiers texte s'ouvriront (probablement avec le bloc-note).

    Poste le contenu de " log.txt " (c'est celui qui apparait à l'écran), ainsi que de " info.txt " (que tu verras dans la barre des tâches), pour analyse et attends la suite ...

    Important : poste un rapport, puis l'autre dans la réponse suivante ...
    Si tu essaies de poster les deux en même temps, cela risque d'être trop long pour le forum ...
    ( Et si "log.txt" seul, ne passe pas non plus , fais le en 2 fois ... merci ... )

    ( Note : les rapports seront en outre sauvegardés dans ce dossier -> C:\rsit )

    1. Contributeur sécurité
      Bien ...

      dans l'ordre :

      1- refais un coup de CCleaner ( registre compris ).

      ===================

      2- MBAM :

      mets le à jour .

      (NB : S'il te manque "COMCTL32.OCX" lors de l'installe, alors télécharge le ici : https://www.malekal.com/tutorial-aboutbuster/ )

      * Potasse le tuto pour te familiariser avec le prg :
      https://forum.pcastuces.com/sujet.asp?f=31&s=3
      ( cela dis, il est très simple d'utilisation ).

      ! Déconnecte toi et ferme toutes applications en cours !

      * Lance Malwarebyte's .

      Fais un examen dit "Rapide" .

      --> Laisse le programme travailler ( et ne rien faire d'autre avec le PC durant le scan ).
      --> à la fin tu cliques sur "résultat" .
      --> Vérifie que tous les objets infectés soient validés, puis clique sur " suppression " .

      Note : si il faut redémarrer ton PC pour finir le nettoyage, fais le !

      Poste le rapport sauvegardé après la suppression des objets infectés (dans l'onglet "rapport/log"de Malwarebytes, le dernier en date) pour analyse ...

      ===========================

      3- Télécharge GenProc (de Jean-Chretien1 et Narco4) sur ton bureau (et pas ailleur !) :
      http://www.genproc.com/GenProc.exe

      !!Déconnecte toi et ferme tes applications en cours !!

      * double-clique sur GenProc.exe pour lancer le scan et laisse faire ...

      * A la question "faites vous aidez sur un forum..." > clique sur " oui " .

      -> poste le contenu du rapport qui s'ouvre ...

      Aide en images ici : http://www.alt-shift-return.org/Info/GenProc-HowTo.html

      IMPORTANT : poste le rapport et ne fais rien d'autre pour l'instant ( souvant il faut ajouter des consignes à la manipe indiquée pour que cela fonctionne parfaitement ) .

      1. info.txt logfile of random's system information tool 1.06 2009-05-07 07:02:01

        ======Uninstall list======

        -->C:\PROGRA~1\Yahoo!\Common\UNYT_W~1.EXE
        -->C:\Program Files\DivX\DivXConverterUninstall.exe /CONVERTER
        -->C:\Program Files\Fichiers communs\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
        -->C:\WINDOWS\IsUn040c.exe -fC:\WINDOWS\orun32.isu
        -->C:\WINDOWS\system32\\MSIEXEC.EXE /x {075473F5-846A-448B-BCB3-104AA1760205}
        -->C:\WINDOWS\system32\\MSIEXEC.EXE /x {AB708C9B-97C8-4AC9-899B-DBF226AC9382}
        -->C:\WINDOWS\system32\\MSIEXEC.EXE /x {B12665F4-4E93-4AB4-B7FC-37053B524629}
        -->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{939F8208-C8CE-4AFF-B7BA-ACEB2E74A6CB}\Setup.exe"
        -->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
        Adobe Flash Player ActiveX-->C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
        Adobe Reader 7.0.5 - Français-->MsiExec.exe /I{AC76BA86-7AD7-1036-7B44-A70500000002}
        Ad-remover-->C:\Program Files\Ad-remover\Uninstall ADR.exe
        adsl TV-->C:\Program Files\adslTV\Uninstal.exe
        Age of Mythology-->"C:\Program Files\Microsoft Games\Age of Mythology\UNINSTAL.EXE" /runtemp /addremove
        Amélioration de nos services-->C:\PROGRA~1\FICHIE~1\INSTAL~1\Driver\1050\INTEL3~1\IDriver.exe /M{23012310-3E05-46A5-88A9-C6CBCABCAC79} /l1036
        Apple Mobile Device Support-->MsiExec.exe /I{EC4455AB-F155-4CC1-A4C5-88F3777F9886}
        Apple Software Update-->MsiExec.exe /I{6956856F-B6B3-4BE0-BA0B-8F495BE32033}
        Archiveur WinRAR-->C:\Program Files\WinRAR\uninstall.exe
        Arovax AntiSpyware 2.1.153-->C:\Program Files\Arovax AntiSpyware\uninst.exe
        Assistant de connexion Windows Live-->MsiExec.exe /I{DCE8CD14-FBF5-4464-B9A4-E18E473546C7}
        Avira AntiVir Personal - Free Antivirus-->C:\Program Files\Avira\AntiVir PersonalEdition Classic\SETUP.EXE /REMOVE
        Bandoo-->C:\Program Files\Bandoo\PreUninstall.exe
        Bonjour-->MsiExec.exe /I{8A25392D-C5D2-4E79-A2BD-C15DDC5B0959}
        CCleaner (remove only)-->"C:\Program Files\CCleaner\uninst.exe"
        Choice Guard-->MsiExec.exe /I{8FFC5648-FAF8-43A3-BC8F-42BA1E275C4E}
        Compatibility Pack for the 2007 Office system-->MsiExec.exe /X{90120000-0020-040C-0000-0000000FF1CE}
        Conexant HD Audio-->C:\Program Files\CONEXANT\CNXT_HDAUDIO\HXFSETUP.EXE -U -IAt8VEN5a.inf
        Connexion Facile à Internet-->C:\PROGRA~1\FICHIE~1\INSTAL~1\Driver\1050\INTEL3~1\IDriver.exe /M{8105684D-8CA6-440D-8F58-7E5FD67A499D} /l1036
        Correctif pour Lecteur Windows Media 11 (KB939683)-->"C:\WINDOWS\$NtUninstallKB939683$\spuninst\spuninst.exe"
        Correctif pour Windows XP (KB952287)-->"C:\WINDOWS\$NtUninstallKB952287$\spuninst\spuninst.exe"
        DivX Codec-->C:\Program Files\DivX\DivXCodecUninstall.exe /CODEC
        DivX Converter-->C:\Program Files\DivX\DivXConverterUninstall.exe /CONVERTER
        DivX Player-->C:\Program Files\DivX\DivXPlayerUninstall.exe /PLAYER
        DivX Plus DirectShow Filters-->C:\Program Files\DivX\DivXDSFiltersUninstall.exe /DSFILTERS
        DivX Web Player-->C:\Program Files\DivX\DivXWebPlayerUninstall.exe /PLUGIN
        GlobeTrotter Connect-->MsiExec.exe /X{DDEB70E9-34C5-4DF3-8B39-85358859B049}
        Google Chrome-->"C:\Program Files\Google\Chrome\Application\1.0.154.59\Installer\setup.exe" --uninstall --system-level
        Google Toolbar for Internet Explorer-->"C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarManager_BDA1448D3D255554.exe" /uninstall
        Google Toolbar for Internet Explorer-->MsiExec.exe /I{18455581-E099-4BA8-BC6B-F34B2F06600C}
        Google Update Helper-->MsiExec.exe /I{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}
        Hauppauge English Help Files and Resources-->C:\PROGRA~1\WinTV\UNHLPeng.EXE C:\PROGRA~1\WinTV\WTV2Keng.LOG
        Hauppauge French Help Files and Resources-->C:\PROGRA~1\WinTV\UNHLPfra.EXE C:\PROGRA~1\WinTV\WTV2Kfra.LOG
        Hauppauge WinTV DVB-T EPG Service-->C:\WINDOWS\system32\UNWISE.EXE C:\WINDOWS\system32\UnEPGService.LOG
        Hauppauge WinTV Infrared Remote-->C:\PROGRA~1\WinTV\UNir32.EXE C:\PROGRA~1\WinTV\ir32.LOG
        Hauppauge WinTV Scheduler-->C:\PROGRA~1\WinTV\SCHEDU~1\uniSCHED.exe C:\PROGRA~1\WinTV\SCHEDU~1\uniSCHED.log
        Hauppauge WinTV TV Services-->C:\PROGRA~1\WinTV\uniTvSrv.exe C:\PROGRA~1\WinTV\UniTVSrv.LOG
        Hauppauge WinTV2000-->C:\PROGRA~1\WinTV\UNTV32.EXE C:\PROGRA~1\WinTV\WINTV2K.LOG
        HijackThis 2.0.2-->"C:\Program Files\Trend Micro\HijackThis\HijackThis.exe" /uninstall
        Hotfix for Windows Media Format 11 SDK (KB929399)-->"C:\WINDOWS\$NtUninstallKB929399$\spuninst\spuninst.exe"
        HP Help and Support-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\10\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{A93C4E94-1005-489D-BEAA-B873C1AA6CFC}\setup.exe" -l0x40c -removeonly
        HP Imaging Device Functions 6.0-->C:\Program Files\HP\Digital Imaging\DigitalImagingMonitor\hpzscr01.exe -datfile hpqbud01.dat
        HP Photosmart Premier Software 6.0-->C:\Program Files\HP\Digital Imaging\uninstall\hpzscr01.exe -datfile hpqscr01.dat
        HP Quick Launch Buttons 6.10 A2-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{34D2AB40-150D-475D-AE32-BD23FB5EE355}\setup.exe" -l0x40c -removeonly uninst
        HP QuickPlay 2.3-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{45D707E9-F3C4-11D9-A373-0050BAE317E1}\setup.exe" -uninstall
        HP Update-->MsiExec.exe /X{7059BDA7-E1DB-442C-B7A1-6144596720A4}
        HP User Guides 0035-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\10\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{BE247E71-C143-40BB-ADF2-A465DF062BAB}\Setup.exe" -l0x40c -removeonly
        HP Wireless Assistant 2.00 G2-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{4302B2DD-D958-40E3-BAF3-B07FFE1978CE}\setup.exe" -l0x40c hpquninst
        Installation Windows Live-->C:\Program Files\Windows Live\Installer\wlarp.exe
        Installation Windows Live-->MsiExec.exe /I{7370DF47-B4F9-4279-BFC3-3F09919F720D}
        Intel(R) Graphics Media Accelerator Driver-->RUNDLL32.EXE C:\WINDOWS\system32\ialmrem.dll,UninstallW2KIGfx2ID PCI\VEN_8086&DEV_27A6 PCI\VEN_8086&DEV_27A2
        Intel(R) PRO Network Connections Drivers-->Prounstl.exe
        InterVideo FilterSDK for Hauppauge-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{2227E1FA-01F5-483C-AB0E-2A308E900B3D}\setup.exe" REMOVEALL
        iTunes-->MsiExec.exe /I{F5C63795-2708-4D15-BF18-5ABBFF7DFFC8}
        J2SE Runtime Environment 5.0 Update 6-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0150060}
        Lecteur Windows Media 11-->"C:\Program Files\Windows Media Player\Setup_wm.exe" /Uninstall
        Logitech Desktop Messenger-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{900B1197-53F5-4F46-A882-2CFFFE2EEDCB}\Setup.exe" -l0x40c UNINSTALL
        Logitech IM Video Companion-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{984F10FD-11FD-4BED-8163-92DB81E6A825}\Setup.exe" -l0x40c UNINSTALL
        Logitech ImageStudio-->MsiExec.exe /I{5A24DD7E-7B01-41AC-ADA8-F1776177A3BA}
        Logitech Print Service-->C:\PROGRA~1\Logitech\PRINTS~1\UNWISE.EXE C:\PROGRA~1\Logitech\PRINTS~1\INSTALL.LOG
        Macromedia Flash Player 8-->MsiExec.exe /X{6815FCDD-401D-481E-BA88-31B4754C2B46}
        Macromedia Shockwave Player-->MsiExec.exe /X{838A1BC9-95CA-4880-9BE3-2A7D23600A2B}
        Malwarebytes' Anti-Malware-->"C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
        Microsoft .NET Framework 1.1 French Language Pack-->MsiExec.exe /X{9A394342-4A68-4EBA-85A6-55B559F4E700}
        Microsoft .NET Framework 1.1 Hotfix (KB928366)-->"C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\hotfix.exe" "C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\M928366\M928366Uninstall.msp"
        Microsoft .NET Framework 1.1-->msiexec.exe /X {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
        Microsoft .NET Framework 1.1-->MsiExec.exe /X{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
        Microsoft Compression Client Pack 1.0 for Windows XP-->"C:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe"
        Microsoft Office Professional Edition 2003-->MsiExec.exe /I{9011040C-6000-11D3-8CFE-0150048383C9}
        Microsoft Silverlight-->MsiExec.exe /X{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
        Microsoft User-Mode Driver Framework Feature Pack 1.5-->"C:\WINDOWS\$NtUninstallWudf01005$\spuninst\spuninst.exe"
        Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
        Microsoft Works-->MsiExec.exe /I{A059DE09-1B49-4450-B340-7AE097EC3F04}
        Mise à jour critique pour Lecteur Windows Media 11 (KB959772)-->"C:\WINDOWS\$NtUninstallKB959772_WM11$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Lecteur Windows Media (KB952069)-->"C:\WINDOWS\$NtUninstallKB952069_WM9$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Lecteur Windows Media 10 (KB911565)-->"C:\WINDOWS\$NtUninstallKB911565$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Lecteur Windows Media 10 (KB936782)-->"C:\WINDOWS\$NtUninstallKB936782_WMP10$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Lecteur Windows Media 11 (KB936782)-->"C:\WINDOWS\$NtUninstallKB936782_WMP11$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Lecteur Windows Media 11 (KB954154)-->"C:\WINDOWS\$NtUninstallKB954154_WM11$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Step by Step Interactive Training (KB923723)-->"C:\WINDOWS\$NtUninstallKB923723$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB923561)-->"C:\WINDOWS\$NtUninstallKB923561$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB938464)-->"C:\WINDOWS\$NtUninstallKB938464$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB938464-v2)-->"C:\WINDOWS\$NtUninstallKB938464-v2$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB941569)-->"C:\WINDOWS\$NtUninstallKB941569$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB946648)-->"C:\WINDOWS\$NtUninstallKB946648$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB950759)-->"C:\WINDOWS\$NtUninstallKB950759$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB950760)-->"C:\WINDOWS\$NtUninstallKB950760$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB950762)-->"C:\WINDOWS\$NtUninstallKB950762$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB950974)-->"C:\WINDOWS\$NtUninstallKB950974$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB951066)-->"C:\WINDOWS\$NtUninstallKB951066$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB951376-v2)-->"C:\WINDOWS\$NtUninstallKB951376-v2$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB951698)-->"C:\WINDOWS\$NtUninstallKB951698$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB951748)-->"C:\WINDOWS\$NtUninstallKB951748$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB952004)-->"C:\WINDOWS\$NtUninstallKB952004$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB952954)-->"C:\WINDOWS\$NtUninstallKB952954$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB953838)-->"C:\WINDOWS\$NtUninstallKB953838$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB953839)-->"C:\WINDOWS\$NtUninstallKB953839$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB954211)-->"C:\WINDOWS\$NtUninstallKB954211$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB954459)-->"C:\WINDOWS\$NtUninstallKB954459$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB954600)-->"C:\WINDOWS\$NtUninstallKB954600$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB955069)-->"C:\WINDOWS\$NtUninstallKB955069$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB956390)-->"C:\WINDOWS\$NtUninstallKB956390$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB956391)-->"C:\WINDOWS\$NtUninstallKB956391$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB956572)-->"C:\WINDOWS\$NtUninstallKB956572$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB956802)-->"C:\WINDOWS\$NtUninstallKB956802$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB956803)-->"C:\WINDOWS\$NtUninstallKB956803$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB956841)-->"C:\WINDOWS\$NtUninstallKB956841$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB957095)-->"C:\WINDOWS\$NtUninstallKB957095$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB957097)-->"C:\WINDOWS\$NtUninstallKB957097$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB958215)-->"C:\WINDOWS\$NtUninstallKB958215$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB958644)-->"C:\WINDOWS\$NtUninstallKB958644$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB958687)-->"C:\WINDOWS\$NtUninstallKB958687$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB958690)-->"C:\WINDOWS\$NtUninstallKB958690$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB959426)-->"C:\WINDOWS\$NtUninstallKB959426$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB960225)-->"C:\WINDOWS\$NtUninstallKB960225$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB960714)-->"C:\WINDOWS\$NtUninstallKB960714$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB960715)-->"C:\WINDOWS\$NtUninstallKB960715$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB960803)-->"C:\WINDOWS\$NtUninstallKB960803$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB961373)-->"C:\WINDOWS\$NtUninstallKB961373$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB963027)-->"C:\WINDOWS\$NtUninstallKB963027$\spuninst\spuninst.exe"
        Mise à jour pour Lecteur Windows Media 10 (KB910393)-->"C:\WINDOWS\$NtUninstallKB910393$\spuninst\spuninst.exe"
        Mise à jour pour Lecteur Windows Media 10 (KB913800)-->"C:\WINDOWS\$NtUninstallKB913800$\spuninst\spuninst.exe"
        Mise à jour pour Lecteur Windows Media 10 (KB926251)-->"C:\WINDOWS\$NtUninstallKB926251$\spuninst\spuninst.exe"
        Mise à jour pour Windows XP (KB942763)-->"C:\WINDOWS\$NtUninstallKB942763$\spuninst\spuninst.exe"
        Mise à jour pour Windows XP (KB951072-v2)-->"C:\WINDOWS\$NtUninstallKB951072-v2$\spuninst\spuninst.exe"
        Mise à jour pour Windows XP (KB951978)-->"C:\WINDOWS\$NtUninstallKB951978$\spuninst\spuninst.exe"
        Mise à jour pour Windows XP (KB955839)-->"C:\WINDOWS\$NtUninstallKB955839$\spuninst\spuninst.exe"
        Mise à jour pour Windows XP (KB961503)-->"C:\WINDOWS\$NtUninstallKB961503$\spuninst\spuninst.exe"
        Mise à jour pour Windows XP (KB967715)-->"C:\WINDOWS\$NtUninstallKB967715$\spuninst\spuninst.exe"
        MSN-->C:\Program Files\MSN\MsnInstaller\msninst.exe /Action:ARP
        MSVCRT-->MsiExec.exe /I{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}
        MSXML 4.0 SP2 (KB936181)-->MsiExec.exe /I{C04E32E0-0416-434D-AFB9-6969D703A9EF}
        MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
        MSXML4 Parser-->MsiExec.exe /I{01501EBA-EC35-4F9F-8889-3BE346E5DA13}
        Navilog1 3.7.6-->"C:\Program Files\Navilog1\unins000.exe"
        neroxml-->MsiExec.exe /I{56C049BE-79E9-4502-BEA7-9754A3E60F9B}
        NetWaiting-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{3F92ABBB-6BBF-11D5-B229-002078017FBF}\setup.exe" -l0x40c ControlPanel
        Otto-->"C:\Program Files\FrenchOtto\uninstallotto.exe"
        Outil de mise à jour Google-->"C:\Program Files\Google\Google Updater\GoogleUpdater.exe" -uninstall
        Outil de téléchargement Windows Live-->MsiExec.exe /I{205C6BDD-7B73-42DE-8505-9A093F35A238}
        Package de pilotes Windows - Nokia (WUDFRd) WPD (06/01/2007 6.84.33.0)-->C:\PROGRA~1\DIFX\270581355A767BF1\dpinst.exe /u C:\WINDOWS\system32\DRVSTORE\pccswpddri_044C8712DB44F83D9DE6C376991EE9254E0A69E4\pccswpddriver.inf
        Package de pilotes Windows - Nokia Modem (02/15/2007 3.1)-->C:\PROGRA~1\DIFX\270581355A767BF1\dpinst.exe /u C:\WINDOWS\system32\DRVSTORE\pccs_bluet_8B37DC72918CCD58A6EC20373AF6242B037A293B\pccs_bluetooth.inf
        Package de pilotes Windows - Nokia Modem (02/15/2007 3.1)-->C:\PROGRA~1\DIFX\270581355A767BF1\dpinst.exe /u C:\WINDOWS\system32\DRVSTORE\pccs_bluet_F12A08B6F776984A95553486F64C541356F86E38\pccs_bluetooth.inf
        PC Connectivity Solution-->MsiExec.exe /I{99A40651-0BC2-4095-8F9A-A40FAB224FEF}
        QuickTime-->MsiExec.exe /I{216AB108-2AE1-4130-B3D5-20B2C4C80F8F}
        RealPlayer-->C:\Program Files\Fichiers communs\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
        Salaat Time 2.0-->C:\PROGRA~1\SALAAT~1\Setup.exe /remove /q0
        Security Update for CAPICOM (KB931906)-->MsiExec.exe /I{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
        Security Update for CAPICOM (KB931906)-->MsiExec.exe /X{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
        Segoe UI-->MsiExec.exe /I{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}
        Sid Meier's Civilization IV Colonization-->C:\Program Files\InstallShield Installation Information\{EF36A836-BF89-4A4F-B079-057B0C68C1E0}\setup.exe -runfromtemp -l0x040c -removeonly
        Skuld iPod Converter 1.2.1-->"C:\Program Files\Skuld iPod Converter\unins000.exe"
        Skype™ 3.8-->MsiExec.exe /X{5C82DAE5-6EB0-4374-9254-BE3319BA4E82}
        Soft Data Fax Modem with SmartCP-->C:\Program Files\CONEXANT\CNXT_MODEM_PCI_VEN_14F1&DEV_5045_at8ven5m\HXFSETUP.EXE -U -IAt8VEN5m.inf
        Sonic Audio Module-->MsiExec.exe /I{AB708C9B-97C8-4AC9-899B-DBF226AC9382}
        Sonic Copy Module-->MsiExec.exe /I{B12665F4-4E93-4AB4-B7FC-37053B524629}
        Sonic Data Module-->MsiExec.exe /I{075473F5-846A-448B-BCB3-104AA1760205}
        Sonic Express Labeler-->MsiExec.exe /I{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}
        Sonic MyDVD Plus-->MsiExec.exe /I{21657574-BD54-48A2-9450-EB03B2C7FC29}
        Sonic Update Manager-->MsiExec.exe /I{30465B6C-B53F-49A1-9EBA-A3F187AD502E}
        SonicAC3Encoder-->MsiExec.exe /I{52FBAE98-D389-4281-8C14-21B4046CCB4E}
        SonicMPEGEncoder-->MsiExec.exe /I{B16AF568-A644-483C-A6DA-5028CD019C8C}
        Synaptics Pointing Device Driver-->rundll32.exe "C:\Program Files\Synaptics\SynTP\SynISDLL.dll",standAloneUninstall
        VC80CRTRedist - 8.0.50727.762-->MsiExec.exe /I{767CC44C-9BBC-438D-BAD3-FD4595DD148B}
        VideoLAN VLC media player 0.8.6i-->C:\Program Files\VideoLAN\VLC\uninstall.exe
        Windows Live Call-->MsiExec.exe /I{82C7B308-0BDD-49D8-8EA5-9CD3A3F9DF41}
        Windows Live Communications Platform-->MsiExec.exe /I{3B4E636E-9D65-4D67-BA61-189800823F52}
        Windows Live Messenger-->MsiExec.exe /X{059C042E-796A-4ACC-A81A-ECC2010BB78C}
        Windows Media Connect-->"C:\WINDOWS\$NtUninstallWMCSetup$\spuninst\spuninst.exe"
        Windows Media Format 11 runtime-->"C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll
        Windows Media Format 11 runtime-->"C:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe"
        Windows Media Player 11-->"C:\WINDOWS\$NtUninstallwmp11$\spuninst\spuninst.exe"
        Windows XP Media Center Edition 2005 KB925766-->"C:\WINDOWS\$NtUninstallKB925766$\spuninst\spuninst.exe"
        Windows XP Service Pack 3-->"C:\WINDOWS\$NtServicePackUninstall$\spuninst\spuninst.exe"
        Yahoo! Extras-->C:\PROGRA~1\Yahoo!\Common\unyext.exe
        Yahoo! Internet Mail-->C:\WINDOWS\system32\regsvr32 /u /s C:\PROGRA~1\Yahoo!\Common\ymmapi.dll
        Yahoo! Messenger-->C:\PROGRA~1\Yahoo!\MESSEN~1\UNWISE.EXE /U C:\PROGRA~1\Yahoo!\MESSEN~1\INSTALL.LOG
        Yahoo! Toolbar-->C:\PROGRA~1\Yahoo!\Common\UNYT_W~1.EXE

        ======Security center information======

        AV: Avira AntiVir PersonalEdition
        FW: Norton Internet Worm Protection (disabled)

        ======System event log======

        Computer Name: LAO
        Event Code: 4201
        Message: Le système a détecté que la carte réseau \DEVICE\TCPIP_{844894F5-6189-4879-A0E9-F72EDFA9200E} était connectée au réseau,
        et a lancé une opération normale sur la carte réseau.

        Record Number: 63289
        Source Name: Tcpip
        Time Written: 20090427220114.000000+120
        Event Type: Informations
        User:

        Computer Name: LAO
        Event Code: 7036
        Message: Le service Carte de performance WMI est entré dans l'état : arrêté.

        Record Number: 63288
        Source Name: Service Control Manager
        Time Written: 20090427204601.000000+120
        Event Type: Informations
        User:

        Computer Name: LAO
        Event Code: 4201
        Message: Le système a détecté que la carte réseau \DEVICE\TCPIP_{844894F5-6189-4879-A0E9-F72EDFA9200E} était connectée au réseau,
        et a lancé une opération normale sur la carte réseau.

        Record Number: 63287
        Source Name: Tcpip
        Time Written: 20090427203654.000000+120
        Event Type: Informations
        User:

        Computer Name: LAO
        Event Code: 4201
        Message: Le système a détecté que la carte réseau \DEVICE\TCPIP_{844894F5-6189-4879-A0E9-F72EDFA9200E} était connectée au réseau,
        et a lancé une opération normale sur la carte réseau.

        Record Number: 63286
        Source Name: Tcpip
        Time Written: 20090427203514.000000+120
        Event Type: Informations
        User:

        Computer Name: LAO
        Event Code: 7036
        Message: Le service Windows Installer est entré dans l'état : arrêté.

        Record Number: 63285
        Source Name: Service Control Manager
        Time Written: 20090427201830.000000+120
        Event Type: Informations
        User:

        =====Application event log=====

        Computer Name: LAO
        Event Code: 4096
        Message: The AntiVir service has been started successfully!

        Record Number: 5
        Source Name: Avira AntiVir
        Time Written: 20090408173108.000000+120
        Event Type: Informations
        User: AUTORITE NT\SYSTEM

        Computer Name: LAO
        Event Code: 0
        Message:
        Record Number: 4
        Source Name: gusvc
        Time Written: 20090408173100.000000+120
        Event Type: Informations
        User:

        Computer Name: LAO
        Event Code: 0
        Message:
        Record Number: 3
        Source Name: gupdate1c98ec843a4d890
        Time Written: 20090408173059.000000+120
        Event Type: Informations
        User:

        Computer Name: LAO
        Event Code: 0
        Message:
        Record Number: 2
        Source Name: EPGService
        Time Written: 20090408173059.000000+120
        Event Type: Informations
        User:

        Computer Name: LAO
        Event Code: 1
        Message:
        Record Number: 1
        Source Name: Bonjour Service
        Time Written: 20090408173057.000000+120
        Event Type: Informations
        User:

        ======Environment variables======

        "ComSpec"=%SystemRoot%\system32\cmd.exe
        "Path"=%systemroot%\system32;%systemroot%;%systemroot%\system32\wbem;C:\Program Files\PC Connectivity Solution;C:\Program Files\QuickTime\QTSystem;C:\Program Files\Fichiers communs\DivX Shared
        "windir"=%SystemRoot%
        "FP_NO_HOST_CHECK"=NO
        "OS"=Windows_NT
        "PROCESSOR_ARCHITECTURE"=x86
        "PROCESSOR_LEVEL"=6
        "PROCESSOR_IDENTIFIER"=x86 Family 6 Model 14 Stepping 8, GenuineIntel
        "PROCESSOR_REVISION"=0e08
        "NUMBER_OF_PROCESSORS"=2
        "PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
        "TEMP"=%SystemRoot%\TEMP
        "TMP"=%SystemRoot%\TEMP
        "SonicCentral"=C:\Program Files\Fichiers communs\Sonic Shared\Sonic Central\
        "PCTYPE"=PRESARIO
        "PLATFORM"=MCD
        "CLASSPATH"=.;C:\Program Files\Java\jre1.5.0_06\lib\ext\QTJava.zip
        "QTJAVA"=C:\Program Files\Java\jre1.5.0_06\lib\ext\QTJava.zip

        -----------------EOF-----------------
        1. Logfile of random's system information tool 1.06 (written by random/random)
          Run by ale at 2009-05-07 07:01:57
          Microsoft Windows XP Professionnel Service Pack 3
          System drive C: has 25 GB (24%) free of 105 GB
          Total RAM: 2038 MB (73% free)

          Logfile of Trend Micro HijackThis v2.0.2
          Scan saved at 07:01:59, on 07/05/2009
          Platform: Windows XP SP3 (WinNT 5.01.2600)
          MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
          Boot mode: Normal

          Running processes:
          C:\WINDOWS\System32\smss.exe
          C:\WINDOWS\system32\winlogon.exe
          C:\WINDOWS\system32\services.exe
          C:\WINDOWS\system32\lsass.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\system32\spoolsv.exe
          C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
          C:\WINDOWS\Explorer.EXE
          C:\WINDOWS\ehome\ehtray.exe
          C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
          C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
          C:\WINDOWS\system32\igfxtray.exe
          C:\WINDOWS\system32\hkcmd.exe
          C:\WINDOWS\system32\igfxpers.exe
          C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
          C:\Program Files\Fichiers communs\Logitech\QCDriver3\LVCOMS.EXE
          C:\Program Files\Logitech\ImageStudio\LogiTray.exe
          C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
          C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
          C:\Program Files\iTunes\iTunesHelper.exe
          C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
          C:\WINDOWS\system32\ctfmon.exe
          C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
          C:\Program Files\Windows Live\Messenger\msnmsgr.exe
          C:\Program Files\DAEMON Tools Lite\daemon.exe
          C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
          C:\Program Files\Messenger\msmsgs.exe
          C:\Program Files\Windows Media Player\WMPNSCFG.exe
          C:\Program Files\Salaat Time\SalaatTime.exe
          C:\Program Files\Bouygues\GlobeTrotter Connect\GlobeTrotter Connect.exe
          C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
          C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
          C:\Program Files\Bonjour\mDNSResponder.exe
          C:\WINDOWS\eHome\ehRecvr.exe
          C:\WINDOWS\eHome\ehSched.exe
          C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
          C:\PROGRA~1\WinTV\EPG Services\System\EPGService.exe
          C:\Program Files\Google\Update\GoogleUpdate.exe
          C:\WINDOWS\System32\svchost.exe
          C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
          C:\WINDOWS\system32\svchost.exe
          C:\PROGRA~1\Bandoo\Bandoo.exe
          C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
          C:\Program Files\iPod\bin\iPodService.exe
          C:\WINDOWS\system32\dllhost.exe
          C:\WINDOWS\eHome\ehmsas.exe
          C:\PROGRA~1\Bandoo\BndCore.exe
          C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
          C:\Program Files\Internet Explorer\iexplore.exe
          C:\Documents and Settings\ale\Bureau\RSIT.exe
          C:\Program Files\Trend Micro\HijackThis\ale.exe

          R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
          R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost;*.local
          R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
          R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
          O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
          O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
          O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
          O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
          O2 - BHO: Click-to-Call BHO - {5C255C8A-E604-49b4-9D64-90988571CECB} - C:\Program Files\Windows Live\Messenger\wlchtc.dll
          O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
          O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
          O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
          O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
          O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
          O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
          O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
          O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
          O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
          O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
          O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
          O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
          O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
          O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] CHDAudPropShortcut.exe
          O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
          O4 - HKLM\..\Run: [Cpqset] C:\Program Files\Hewlett-Packard\Default Settings\cpqset.exe
          O4 - HKLM\..\Run: [RecGuard] C:\Windows\SMINST\RecGuard.exe
          O4 - HKLM\..\Run: [LVCOMS] C:\Program Files\Fichiers communs\Logitech\QCDriver3\LVCOMS.EXE
          O4 - HKLM\..\Run: [LogitechGalleryRepair] C:\Program Files\Logitech\ImageStudio\ISStart.exe
          O4 - HKLM\..\Run: [LogitechImageStudioTray] C:\Program Files\Logitech\ImageStudio\LogiTray.exe
          O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
          O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
          O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
          O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
          O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
          O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
          O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
          O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
          O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
          O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
          O4 - HKCU\..\Run: [Messenger (Yahoo!)] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
          O4 - HKCU\..\Run: [Arovax AntiSpyware] C:\Program Files\Arovax AntiSpyware\arovaxantispyware.exe /s
          O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
          O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
          O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
          O4 - HKCU\..\Run: [SalaatTime] C:\Program Files\Salaat Time\SalaatTime.exe
          O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
          O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
          O4 - Startup: Adobe Media Player.lnk = C:\Program Files\Adobe Media Player\Adobe Media Player.exe
          O4 - Global Startup: AutoStart IR.lnk = C:\Program Files\WinTV\Ir.exe
          O4 - Global Startup: Démarrage rapide de HP Photosmart Premier.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
          O4 - Global Startup: GlobeTrotter Connect.lnk = C:\Program Files\Bouygues\GlobeTrotter Connect\GlobeTrotter Connect.exe
          O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
          O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
          O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
          O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
          O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
          O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
          O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
          O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
          O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
          O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
          O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
          O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
          O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
          O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
          O14 - IERESET.INF: START_PAGE_URL=https://www.msn.com/fr-fr?cobrand=compaq-notebook.msn.com&ocid=HPDHP&pc=CPNTDF
          O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w3/pr01/resources/MSNPUpld.cab
          O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/...
          O16 - DPF: {FE0BD779-44EE-4A4B-AA2E-743C63F2E5E6} (IWinAmpActiveX Class) - http://pdl.stream.aol.com/downloads/aol/unagi/ampx_en_dl.cab
          O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
          O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
          O20 - AppInit_DLLs: c:\progra~1\bandoo\bndhook.dll c:\progra~1\bandoo\bndhook.dll
          O23 - Service: AddFiltr - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\AddFiltr.exe
          O23 - Service: Avira AntiVir Personal - Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
          O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
          O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
          O23 - Service: Bandoo Coordinator - Discordia Limited - C:\PROGRA~1\Bandoo\Bandoo.exe
          O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
          O23 - Service: EPGService - Hauppauge Computer Works - C:\PROGRA~1\WinTV\EPG Services\System\EPGService.exe
          O23 - Service: Service Google Update (gupdate1c98ec843a4d890) (gupdate1c98ec843a4d890) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
          O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
          O23 - Service: HauppaugeTVServer - Hauppauge Computer Works - C:\PROGRA~1\WinTV\HCWTVS~1.EXE
          O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
          O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - c:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe
          O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
          O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
          O23 - Service: Nero BackItUp Scheduler 4.0 - Unknown owner - C:\Program Files\Fichiers communs\Nero\Nero BackItUp 4\NBService.exe (file missing)
          O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
          O24 - Desktop Component 0: (no name) - file:///C:/DOCUME~1/ale/LOCALS~1/Temp/msohtml1/01/clip_image002.jpg
          1. bonjour

            ------- LOGFILE OF AD-REMOVER 1.1.3.6 | ONLY XP/VISTA -------

            Updated by C_XX on 05/05/2009 at 21:20
            Contact: AdRemover.contact@gmail.com
            Website: http://pagesperso-orange.fr/NosTools/ad_remover.html

            **** LIMITED TO ****

            Known Adwares
            Sweetim

            ********************

            Start at: 20:38:52, 06/05/2009 | Boot mode: Normal Boot
            Option: CLEAN | Executed from: C:\Program Files\Ad-remover\Ad-remover.bat
            Operating System: Microsoft® Windows XP™ Service Pack 3 (version 5.1.2600)
            Computer Name: LAO
            Current User: ale - Administrator
            Drive(s):
            - C:\ (File System: NTFS)
            - D:\ (File System: FAT32)

            (!) ---- IE start pages/Tabs reset

            ============ Known Adwares Deleted ============

            .
            .
            C:\Documents and Settings\ale\Cookies\ale@atdmt[2].txt
            C:\Documents and Settings\ale\Cookies\ale@bs.serving-sys[2].txt

            +-----------------| Sweetim Elements Deleted :

            HKCU\Software\SweetIM
            HKLM\Software\SweetIM
            .

            (!) ---- Temp files deleted.
            (!) ---- Recycle bin emptied in all drives.

            +-----------------| Added Scan :

            ---- Mozilla FireFox Version [Unable to get version] ----

            ProfilePath: 381u48nj.default (ale)
            .
            Prefs.js: Browser.Search.DefaultEngineName: "Yahoo"
            Prefs.js: Browser.Search.SelectedEngine: "Yahoo"
            Prefs.js: Browser.Search.DefaultUrl: "hxxp://fr.search.yahoo.com/search?ei=UTF-8&fr=ytff-msgr&p="
            .
            .
            .
            .
            .

            +---------------------------------------------------------------------------+
            1. Contributeur sécurité
              salut,

              dans l'ordre :

              1- Nettoyage AD-Remover :

              ! Déconnecte toi et ferme toutes application en cours ( navigarteur compris ) !

              * Relance "Ad-remover" : au menu principal choisis l'option "B" .

              * A l'écran de sélection :

              > choisis le(s) chiffre(s) suivant pour nettoyer les traces de :

              1 - "Adwares connus" puis [entrée]
              4 - "Sweetim" puis [entrée]

              Une fois la sélection faite, tape S puis [entrée] pour lancer la suppression .

              --> le programme va travailler , ne touche à rien ...

              * Poste le rapport qui apparait à la fin pour analyse ...

              ( le rapport est sauvegardé aussi sous C:\Ad-report.log )

              /!\ Si le Bureau ne réapparait pas, presse Ctrl + Alt + Suppr , Onglet "Fichier" , "Nouvelle tâche" , tape explorer.exe et valide ) /!\

              =====================

              2- MalwareByte's :

              mets le à jour .

              ! Déconnecte toi et ferme toutes applications en cours !

              * Lance Malwarebyte's .

              Fais un examen dit "Rapide" .

              --> Laisse le programme travailler ( et ne rien faire d'autre avec le PC durant le scan ).
              --> à la fin tu cliques sur "résultat" .
              --> Vérifie que tous les objets infectés soient validés, puis clique sur " suppression " .

              Note : si il faut redémarrer ton PC pour finir le nettoyage, fais le !

              Poste le rapport sauvegardé après la suppression des objets infectés (dans l'onglet "rapport/log"de Malwarebytes, le dernier en date),
              accompagné d'un nouveau rapport RSIT pour analyse ...

              1. ------- LOGFILE OF AD-REMOVER 1.1.3.6 | ONLY XP/VISTA -------

                Updated by C_XX on 05/05/2009 at 21:20
                Contact: AdRemover.contact@gmail.com
                Website: http://pagesperso-orange.fr/NosTools/ad_remover.html

                Start at: 16:47:07, 06/05/2009 | Boot mode: Normal Boot
                Option: SCAN | Executed from: C:\Program Files\Ad-remover\Ad-remover.bat
                Operating System: Microsoft® Windows XP™ Service Pack 3 (version 5.1.2600)
                Computer Name: LAO
                Current User: ale - Administrator
                Drive(s):
                - C:\ (File System: NTFS)
                - D:\ (File System: FAT32)

                ============ Known Adwares Found ============

                .
                .
                C:\Documents and Settings\ale\Cookies\ale@atdmt[2].txt
                C:\Documents and Settings\ale\Cookies\ale@bs.serving-sys[2].txt

                +-----------------| Eorezo Elements Found:

                .

                +-----------------| It's TV Elements Found:

                .

                +-----------------| Sweetim Elements Found:

                HKCU\Software\SweetIM
                HKLM\Software\SweetIM
                .

                +-----------------| Added Scan:

                ---- Mozilla FireFox Version [Unable to get version] ----

                ProfilePath: 381u48nj.default (ale)
                .
                Prefs.js: Browser.Search.DefaultEngineName: "Yahoo"
                Prefs.js: Browser.Search.SelectedEngine: "Yahoo"
                Prefs.js: Browser.Search.DefaultUrl: "hxxp://fr.search.yahoo.com/search?ei=UTF-8&fr=ytff-msgr&p="
                .
                .
                .
                .
                .

                +---------------------------------------------------------------------------+

                2738 Byte(s) - C:\Ad-Report-Clean-03.05.2009.log
                2360 Byte(s) - C:\Ad-Report-Scan-03.05.2009.log
                1461 Byte(s) - C:\Ad-Report-Scan-06.05.2009.log

                End at: 17:03:46 | 06/05/2009
                .
                +-----------------| E.O.F
                .
                1. Contributeur sécurité
                  Bien ...

                  on va aussi revérifier ceci :

                  Télécharge Ad-remover ( de C_XX ) sur ton bureau ( et pas ailleurs!) :

                  http://sd-1.archive-host.com/membres/up/16506160323759868/AD-R.exe

                  ! Déconnecte toi et ferme toutes application en cours ( navigarteur compris ) !

                  * Clique sur "Ad-R.exe" pour lancer l'installation et laisse les paramètres d'installe par défaut .
                  * Double-clique sur le raccourci Ad-remover qui est sur ton bureau pour lancer l'outil .
                  * Au menu principal choisis l'option "A" et tape sur [entrée] .

                  Laisse travailler l'outil et ne touche à rien ...

                  --> Poste le rapport qui apparait à la fin .

                  ( le rapport est sauvegardé aussi sous C:\Ad-report.log )

                  ( CTRL+A Pour tout selectionner , CTRL+C pour copier et CTRL+V pour coller )

                  Note :
                  "Process.exe", une composante de l'outil, est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool.
                  Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.
                  Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall...) d'où l'alerte émise par ces antivirus.

                  Site de l'auteur > http://pagesperso-orange.fr/NosTools/ad_remover.html

                  1. Search Navipromo version 3.7.6 commencé le 05/05/2009 à 23:05:22,82

                    !!! Attention,ce rapport peut indiquer des fichiers/programmes légitimes!!!
                    !!! Postez ce rapport sur le forum pour le faire analyser !!!
                    !!! Ne lancez pas la partie désinfection sans l'avis d'un spécialiste !!!

                    Outil exécuté depuis C:\Program Files\navilog1

                    Mise à jour le 14.03.2009 à 18h00 par IL-MAFIOSO

                    Microsoft Windows XP Professionnel ( v5.1.2600 ) Service Pack 3
                    X86-based PC ( Multiprocessor Free : Genuine Intel(R) CPU T2250 @ 1.73GHz )
                    BIOS : Ver 1.00PARTTBLw
                    USER : ale ( Administrator )
                    BOOT : Normal boot

                    Antivirus : Avira AntiVir PersonalEdition 8.0.1.30 (Activated)
                    Firewall : Norton Internet Worm Protection 2006 (Not Activated)

                    C:\ (Local Disk) - NTFS - Total:102 Go (Free:24 Go)
                    D:\ (Local Disk) - FAT32 - Total:8 Go (Free:1 Go)
                    E:\ (CD or DVD)
                    G:\ (CD or DVD)

                    Recherche executé en mode normal

                    *** Recherche dossiers dans "C:\WINDOWS" ***

                    *** Recherche dossiers dans "C:\Program Files" ***

                    *** Recherche dossiers dans "C:\Documents and Settings\All Users\menudm~1\progra~1" ***

                    *** Recherche dossiers dans "C:\Documents and Settings\All Users\menudm~1" ***

                    *** Recherche dossiers dans "c:\docume~1\alluse~1\applic~1" ***

                    *** Recherche dossiers dans "C:\Documents and Settings\ale\applic~1" ***

                    *** Recherche dossiers dans "C:\DOCUME~1\ADMINI~1\applic~1" ***

                    *** Recherche dossiers dans "C:\DOCUME~1\general\applic~1" ***

                    *** Recherche dossiers dans "C:\DOCUME~1\INVIT~1\applic~1" ***

                    *** Recherche dossiers dans "C:\Documents and Settings\ale\locals~1\applic~1" ***

                    *** Recherche dossiers dans "C:\DOCUME~1\ADMINI~1\locals~1\applic~1" ***

                    *** Recherche dossiers dans "C:\DOCUME~1\general\locals~1\applic~1" ***

                    *** Recherche dossiers dans "C:\DOCUME~1\INVIT~1\locals~1\applic~1" ***

                    *** Recherche dossiers dans "C:\Documents and Settings\ale\menudm~1\progra~1" ***

                    *** Recherche dossiers dans "C:\DOCUME~1\ADMINI~1\menudm~1\progra~1" ***

                    *** Recherche dossiers dans "C:\DOCUME~1\general\menudm~1\progra~1" ***

                    *** Recherche dossiers dans "C:\DOCUME~1\INVIT~1\menudm~1\progra~1" ***

                    *** Recherche avec Catchme-rootkit/stealth malware detector par gmer ***
                    pour + d'infos : http://www.gmer.net

                    *** Recherche avec GenericNaviSearch ***
                    !!! Tous ces résultats peuvent révéler des fichiers légitimes !!!
                    !!! A vérifier impérativement avant toute suppression manuelle !!!

                    * Recherche dans "C:\WINDOWS\system32" *

                    * Recherche dans "C:\Documents and Settings\ale\locals~1\applic~1" *

                    * Recherche dans "C:\DOCUME~1\ADMINI~1\locals~1\applic~1" *

                    * Recherche dans "C:\DOCUME~1\general\locals~1\applic~1" *

                    * Recherche dans "C:\DOCUME~1\INVIT~1\locals~1\applic~1" *

                    *** Recherche fichiers ***

                    *** Recherche clés spécifiques dans le Registre ***
                    !! Les clés trouvées ne sont pas forcément infectées !!

                    *** Module de Recherche complémentaire ***
                    (Recherche fichiers spécifiques)

                    1)Recherche nouveaux fichiers Instant Access :

                    2)Recherche Heuristique :

                    * Dans "C:\WINDOWS\system32" :

                    * Dans "C:\Documents and Settings\ale\locals~1\applic~1" :

                    * Dans "C:\DOCUME~1\ADMINI~1\locals~1\applic~1" :

                    * Dans "C:\DOCUME~1\general\locals~1\applic~1" :

                    * Dans "C:\DOCUME~1\INVIT~1\locals~1\applic~1" :

                    3)Recherche Certificats :

                    Certificat Egroup absent !
                    Certificat Electronic-Group absent !
                    Certificat Montorgueil absent !
                    Certificat OOO-Favorit absent !
                    Certificat Sunny-Day-Design-Ltd absent !

                    4)Recherche autres dossiers et fichiers connus :

                    *** Analyse terminée le 05/05/2009 à 23:11:05,70 ***
                    1. [ Rapport ToolsCleaner version 2.3.5 (par A.Rothstein & dj QUIOU) ]

                      --> Recherche:

                      C:\Combofix.txt: trouvé !
                      C:\fixnavi.txt: trouvé !
                      C:\cleannavi.txt: trouvé !
                      C:\UsbFix.txt: trouvé !
                      C:\Combofix: trouvé !
                      C:\GenProc: trouvé !
                      C:\UsbFix: trouvé !
                      C:\Rsit: trouvé !
                      C:\Documents and Settings\ale\Bureau\Navilog1.exe: trouvé !
                      C:\Documents and Settings\ale\Bureau\HJTInstall.exe: trouvé !
                      C:\Documents and Settings\ale\Bureau\Ad-remover.lnk: trouvé !
                      C:\Documents and Settings\ale\Bureau\Ad-R.exe: trouvé !
                      C:\Documents and Settings\ale\Bureau\UsbFix.exe: trouvé !
                      C:\Documents and Settings\ale\Bureau\Rsit.exe: trouvé !
                      C:\Documents and Settings\ale\Menu Démarrer\Programmes\UsbFix: trouvé !
                      C:\Documents and Settings\ale\Menu Démarrer\Programmes\Ad-remover: trouvé !
                      C:\Documents and Settings\All Users\Bureau\Navilog1.lnk: trouvé !
                      C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Navilog1: trouvé !
                      C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Navilog1\Navilog1.lnk: trouvé !
                      C:\GenProc\Page\GenProc[*].html: trouvé !
                      C:\Program Files\Navilog1: trouvé !
                      C:\Program Files\Ad-remover: trouvé !
                      C:\Program Files\Microsoft Games\Age of Mythology\history\units\avenger.txt: trouvé !
                      C:\Program Files\Navilog1\Navilog1.bat: trouvé !
                      C:\Program Files\trend micro\HijackThis.exe: trouvé !
                      C:\Program Files\trend micro\hijackthis.log: trouvé !
                      C:\Program Files\trend micro\HijackThis: trouvé !
                      C:\Program Files\trend micro\HijackThis\hijackthis.log: trouvé !

                      ---------------------------------
                      --> Suppression:

                      C:\Documents and Settings\ale\Bureau\Navilog1.exe: supprimé !
                      C:\Documents and Settings\ale\Bureau\HJTInstall.exe: supprimé !
                      C:\Documents and Settings\ale\Bureau\Ad-remover.lnk: supprimé !
                      C:\Documents and Settings\ale\Bureau\Ad-R.exe: supprimé !
                      C:\Documents and Settings\All Users\Bureau\Navilog1.lnk: supprimé !
                      C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Navilog1\Navilog1.lnk: supprimé !
                      C:\Program Files\Navilog1\Navilog1.bat: supprimé !
                      C:\Program Files\trend micro\HijackThis.exe: supprimé !
                      C:\Combofix.txt: supprimé !
                      C:\fixnavi.txt: supprimé !
                      C:\cleannavi.txt: supprimé !
                      C:\UsbFix.txt: supprimé !
                      C:\Documents and Settings\ale\Bureau\UsbFix.exe: supprimé !
                      C:\Documents and Settings\ale\Bureau\Rsit.exe: supprimé !
                      C:\GenProc\Page\GenProc[*].html: ERREUR DE SUPPRESSION !!
                      C:\Program Files\Microsoft Games\Age of Mythology\history\units\avenger.txt: supprimé !
                      C:\Program Files\trend micro\hijackthis.log: supprimé !
                      C:\Program Files\trend micro\HijackThis\hijackthis.log: supprimé !
                      C:\Combofix: supprimé !
                      C:\GenProc: supprimé !
                      C:\UsbFix: ERREUR DE SUPPRESSION !!
                      C:\Rsit: supprimé !
                      C:\Documents and Settings\ale\Menu Démarrer\Programmes\UsbFix: supprimé !
                      C:\Documents and Settings\ale\Menu Démarrer\Programmes\Ad-remover: supprimé !
                      C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Navilog1: supprimé !
                      C:\Program Files\Navilog1: supprimé !
                      C:\Program Files\Ad-remover: supprimé !
                      C:\Program Files\trend micro\HijackThis: supprimé !
                      1. Contributeur sécurité
                        Bien ...

                        rien d'illégitime ...

                        on continue ... on va repartir sur des outils propre et à jour ... donc dans l'ordre :

                        1- Télécharge ToolsCleaner (de A.Rothstein) sur ton Bureau.
                        http://pc-system.fr/

                        Déconnecte toi et ferms bien toutes tes applications en cours .

                        Lance ToolsCleaner .
                        *Clique sur Recherche et laisse le scan se terminer (cela peut être long).
                        *Clique sur Suppression pour finaliser.
                        *Clique sur "quitter" pour générer un rapport ( et pas sur la croix rouge !) :
                        ---> Poste ce rapport : il se trouve à la racine de ton disque dur -> C:\TCleaner.txt .

                        Note : Ce petit soft va te nettoyer tout les trucs dont on c'est servi pour la désinfection ( tu n'en as plus besion ! ) .
                        Supprime tout les outils , dossiers ou rapports consernant la désinfection que Toolscleaner2 n'a pas supprimé .

                        ======================

                        2- refais un coup de CCleaner ( registre compris ) .

                        ======================

                        3- Retélécharge et réinstalle hijackthis ( car supprimé par Toolscleaner2 ) ,

                        Télécharge et installe le logiciel HijackThis :

                        ici http://www.commentcamarche.net/telecharger/telecharger 159 hijackthis
                        ou ici http://www.trendsecure.com/portal/en-US/_download/HJTInstall.exe
                        ou ici https://www.clubic.com/telecharger-fiche17891-hijackthis.html

                        -> Clique sur le setup pour lancer l'installe : laisse toi guider et ne modifie pas les paramètres d'installation .
                        A la fin de l'installe , le prg ce lance automatiquement : ferme le en cliquant sur la croix rouge .
                        Au final, tu dois avoir un raccourci sur ton bureau et aussi un cheminement comme :
                        "C:\ program files\Trend Micro\HijackThis\HijackThis.exe " .

                        ( ne fais pas de scan pour le moment )

                        =====================

                        2- Télécharge Navilog1 sur ton bureau :

                        http://perso.orange.fr/il.mafioso/Navifix/Navilog1.exe

                        !! Déconnecte toi,désactive tes défenses( anti-virus,anti-spyware ) et ferme bien toutes tes applications le temps de la manipe !!

                        Ensuite double clique sur navilog1.exe pour lancer l'installation.
                        Une fois l'installation terminée, le fix s'exécutera automatiquement.
                        (Si ce n'est pas le cas, double-clique sur le raccourci Navilog1 présent sur le bureau).

                        Laisse-toi guider. Au menu principal, choisis 1 et valide .
                        (ne fais pas le choix 2,3 ou 4 sans notre avis/accord)

                        Patiente jusqu'au message :
                        *** Analyse Termine le ..... ***

                        Appuie sur une touche comme demandé, le bloc-note va s'ouvrir.
                        Copie-colle l'intégralité de son contenu dans ta prochaine réponse et attends la suite .

                        (Le rapport est en outre sauvegardé à la racine du disque "C\:fixnavi.txt" )

                        TUTO (aide) : http://www.malekal.com/Adware.Magic_Control.php#mozTocId595901

                        1. rapport D:\Warning.bmp
                          Antivirus Version Dernière mise à jour Résultat
                          a-squared 4.0.0.101 2009.05.05 -
                          AhnLab-V3 5.0.0.2 2009.05.05 -
                          AntiVir 7.9.0.160 2009.05.05 -
                          Antiy-AVL 2.0.3.1 2009.05.05 -
                          Authentium 5.1.2.4 2009.05.05 -
                          Avast 4.8.1335.0 2009.05.05 -
                          AVG 8.5.0.327 2009.05.05 -
                          BitDefender 7.2 2009.05.05 -
                          CAT-QuickHeal 10.00 2009.05.05 -
                          ClamAV 0.94.1 2009.05.05 -
                          Comodo 1151 2009.05.05 -
                          DrWeb 5.0.0.12182 2009.05.05 -
                          eSafe 7.0.17.0 2009.05.05 -
                          eTrust-Vet 31.6.6490 2009.05.05 -
                          F-Prot 4.4.4.56 2009.05.05 -
                          F-Secure 8.0.14470.0 2009.05.05 -
                          Fortinet 3.117.0.0 2009.05.05 -
                          GData 19 2009.05.05 -
                          Ikarus T3.1.1.49.0 2009.05.05 -
                          K7AntiVirus 7.10.723 2009.05.05 -
                          Kaspersky 7.0.0.125 2009.05.05 -
                          McAfee 5606 2009.05.05 -
                          McAfee+Artemis 5606 2009.05.05 -
                          McAfee-GW-Edition 6.7.6 2009.05.05 -
                          Microsoft 1.4602 2009.05.05 -
                          NOD32 4054 2009.05.05 -
                          Norman 6.01.05 2009.05.05 -
                          nProtect 2009.1.8.0 2009.05.04 -
                          Panda 10.0.0.14 2009.05.05 -
                          PCTools 4.4.2.0 2009.05.05 -
                          Prevx1 3.0 2009.05.05 -
                          Rising 21.28.12.00 2009.05.05 -
                          Sophos 4.41.0 2009.05.05 -
                          Sunbelt 3.2.1858.2 2009.05.05 -
                          Symantec 1.4.4.12 2009.05.05 -
                          TheHacker 6.3.4.1.319 2009.05.05 -
                          TrendMicro 8.950.0.1092 2009.05.05 -
                          VBA32 3.12.10.4 2009.05.05 -
                          ViRobot 2009.5.4.1719 2009.05.04 -
                          VirusBuster 4.6.5.0 2009.05.05 -
                          Information additionnelle
                          File size: 88038 bytes
                          MD5...: d834df822550bd562ade3bf70c95dcdb
                          SHA1..: 81cea06782a01edbbcc8810cf61810f92a8dd65e
                          SHA256: af6c31c449f9964304cf0bdd3484d2ca84e72f8ad770c987d52ec6da2152dd2e
                          SHA512: 535bcc336ac269d614775fce9ec32cef22027a8fcffb3f4ac464956bf164bc2e
                          61ef6c0dc78c6c6fbdc932d742b4a11e97ce651baa2830665d40d2d404be5d6c
                          ssdeep: 96:XpiBA/Lf8uU9p19LVI2ga1YSOHLl1qNSWQyiCR6RO:XpiA/Lf8XFNVca1YXHL
                          rq1QyHRx

                          PEiD..: -
                          TrID..: File type identification
                          Windows Bitmap (100.0%)
                          PEInfo: -
                          PDFiD.: -
                          RDS...: NSRL Reference Data Set
                          -
                          1. rapport D:\Info.exe
                            Antivirus Version Dernière mise à jour Résultat
                            a-squared 4.0.0.101 2009.05.05 -
                            AhnLab-V3 5.0.0.2 2009.05.05 Win-Trojan/Xema.variant
                            AntiVir 7.9.0.160 2009.05.05 -
                            Antiy-AVL 2.0.3.1 2009.05.05 -
                            Authentium 5.1.2.4 2009.05.05 -
                            Avast 4.8.1335.0 2009.05.05 -
                            AVG 8.5.0.327 2009.05.05 -
                            BitDefender 7.2 2009.05.05 -
                            CAT-QuickHeal 10.00 2009.05.05 -
                            ClamAV 0.94.1 2009.05.05 -
                            Comodo 1151 2009.05.05 -
                            DrWeb 5.0.0.12182 2009.05.05 -
                            eSafe 7.0.17.0 2009.05.05 -
                            eTrust-Vet 31.6.6490 2009.05.05 -
                            F-Prot 4.4.4.56 2009.05.05 -
                            F-Secure 8.0.14470.0 2009.05.05 -
                            Fortinet 3.117.0.0 2009.05.05 -
                            GData 19 2009.05.05 -
                            Ikarus T3.1.1.49.0 2009.05.05 -
                            K7AntiVirus 7.10.723 2009.05.05 -
                            Kaspersky 7.0.0.125 2009.05.05 -
                            McAfee 5606 2009.05.05 -
                            McAfee+Artemis 5606 2009.05.05 -
                            McAfee-GW-Edition 6.7.6 2009.05.05 -
                            Microsoft 1.4602 2009.05.05 -
                            NOD32 4054 2009.05.05 -
                            Norman 6.01.05 2009.05.05 -
                            nProtect 2009.1.8.0 2009.05.04 -
                            Panda 10.0.0.14 2009.05.05 -
                            PCTools 4.4.2.0 2009.05.05 -
                            Prevx1 3.0 2009.05.05 -
                            Rising 21.28.12.00 2009.05.05 -
                            Sophos 4.41.0 2009.05.05 -
                            Sunbelt 3.2.1858.2 2009.05.05 -
                            Symantec 1.4.4.12 2009.05.05 -
                            TheHacker 6.3.4.1.319 2009.05.05 -
                            TrendMicro 8.950.0.1092 2009.05.05 -
                            VBA32 3.12.10.4 2009.05.05 -
                            ViRobot 2009.5.4.1719 2009.05.04 -
                            VirusBuster 4.6.5.0 2009.05.05 -
                            Information additionnelle
                            File size: 73728 bytes
                            MD5...: 6c487182578d1253831725a7cdc606c3
                            SHA1..: b1bc21a4c05a12ec624f0d500aa678b702de6acd
                            SHA256: ee578cb48d8d03e74f1188fbecd68badc6088f5adf61a2feffa352c152c216e1
                            SHA512: 1f20c8f9d3198cf92623e37c8459b8647156f3d0722e4b28b40f96bc72ccb4c8
                            4fb50678a5560bafa76136ec431cf142a7204a2a8a63a7227a76e936ce89346a
                            ssdeep: 768:TM4GmjjcjWFXd5/XSj7wlOE1CVG9nAc76BWU4:TzqUN5/BlOSCVBKA4

                            PEiD..: Armadillo v1.71
                            TrID..: File type identification
                            Win64 Executable Generic (59.6%)
                            Win32 Executable MS Visual C++ (generic) (26.2%)
                            Win32 Executable Generic (5.9%)
                            Win32 Dynamic Link Library (generic) (5.2%)
                            Generic Win/DOS Executable (1.3%)
                            PEInfo: PE Structure information

                            ( base data )
                            entrypointaddress.: 0x2031
                            timedatestamp.....: 0x41ac531c (Tue Nov 30 11:01:48 2004)
                            machinetype.......: 0x14c (I386)

                            ( 4 sections )
                            name viradd virsiz rawdsiz ntrpy md5
                            .text 0x1000 0x44fa 0x5000 6.07 598683178b3435efe7815bf8bb7c6e70
                            .rdata 0x6000 0xc9c 0x1000 4.52 07c5e6545f3db748f5816a82c4d47853
                            .data 0x7000 0x2afc 0x3000 0.56 1d27cd815188a048381f6b278a327a5c
                            .rsrc 0xa000 0x7dc8 0x8000 4.78 2ab8be94e1623347f338bc43a46654a6

                            ( 5 imports )
                            > KERNEL32.dll: GetVersionExA, GetProcAddress, GetModuleHandleA, FreeLibrary, LoadLibraryA, GetModuleFileNameA, LCMapStringA, GetOEMCP, GetACP, GetCPInfo, GetStringTypeW, GetStringTypeA, MultiByteToWideChar, HeapReAlloc, VirtualAlloc, ReadFile, RtlUnwind, CreateFileA, HeapCreate, HeapDestroy, GetEnvironmentVariableA, GetFileType, GetStdHandle, SetHandleCount, GetEnvironmentStringsW, GetEnvironmentStrings, WideCharToMultiByte, FreeEnvironmentStringsW, FreeEnvironmentStringsA, UnhandledExceptionFilter, HeapAlloc, HeapFree, GetVersion, lstrlenA, WriteFile, lstrcpyA, LCMapStringW, GetCommandLineA, GetStartupInfoA, GetCurrentProcess, TerminateProcess, VirtualFree, CloseHandle, ExitProcess
                            > USER32.dll: SendMessageA, GetClientRect, CopyAcceleratorTableA, BeginPaint, EndPaint, DefWindowProcA, DestroyWindow, PostQuitMessage, MoveWindow, LoadIconA, LoadCursorA, RegisterClassExA, CreateWindowExA, ShowWindow, UpdateWindow, GetMessageA, TranslateMessage, DispatchMessageA, SystemParametersInfoA, IsIconic, GetWindowPlacement, GetWindowRect, GetSystemMetrics
                            > ole32.dll: CoUninitialize, CoInitialize, StgCreateDocfileOnILockBytes, CreateILockBytesOnHGlobal
                            > COMCTL32.dll: -
                            > SHLWAPI.dll: PathAppendA, PathRemoveFileSpecA

                            ( 0 exports )

                            PDFiD.: -
                            RDS...: NSRL Reference Data Set
                            -
                            ThreatExpert info: <a href='http://www.threatexpert.com/report.aspx?md5=6c487182578d1253831725a7cdc606c3' target='_blank'>https://www.symantec.com?md5=6c487182578d1253831725a7cdc606c3</a>
                            CWSandbox info: <a href='http://research.sunbelt-software.com/partnerresource/MD5.aspx?md5=6c487182578d1253831725a7cdc606c3' target='_blank'>http://research.sunbelt-software.com/...
                            1. rapport D:\Folder.htt
                              Antivirus Version Dernière mise à jour Résultat
                              a-squared 4.0.0.101 2009.05.05 -
                              AhnLab-V3 5.0.0.2 2009.05.05 -
                              Antiy-AVL 2.0.3.1 2009.05.05 -
                              Authentium 5.1.2.4 2009.05.05 -
                              Avast 4.8.1335.0 2009.05.05 -
                              AVG 8.5.0.327 2009.05.05 -
                              BitDefender 7.2 2009.05.05 -
                              ClamAV 0.94.1 2009.05.05 -
                              Comodo 1151 2009.05.05 -
                              DrWeb 5.0.0.12182 2009.05.05 -
                              eSafe 7.0.17.0 2009.05.05 -
                              eTrust-Vet 31.6.6490 2009.05.05 -
                              F-Prot 4.4.4.56 2009.05.05 -
                              Fortinet 3.117.0.0 2009.05.05 -
                              GData 19 2009.05.05 -
                              Ikarus T3.1.1.49.0 2009.05.05 -
                              K7AntiVirus 7.10.723 2009.05.05 -
                              Kaspersky 7.0.0.125 2009.05.05 -
                              McAfee 5606 2009.05.05 -
                              McAfee+Artemis 5606 2009.05.05 -
                              McAfee-GW-Edition 6.7.6 2009.05.05 -
                              Microsoft 1.4602 2009.05.05 -
                              NOD32 4054 2009.05.05 -
                              Norman 6.01.05 2009.05.05 -
                              nProtect 2009.1.8.0 2009.05.04 -
                              Panda 10.0.0.14 2009.05.05 -
                              PCTools 4.4.2.0 2009.05.05 -
                              Rising 21.28.12.00 2009.05.05 -
                              Sophos 4.41.0 2009.05.05 -
                              Sunbelt 3.2.1858.2 2009.05.05 -
                              Symantec 1.4.4.12 2009.05.05 -
                              TrendMicro 8.950.0.1092 2009.05.05 -
                              VBA32 3.12.10.4 2009.05.05 -
                              ViRobot 2009.5.4.1719 2009.05.04 -
                              VirusBuster 4.6.5.0 2009.05.05 -
                              Information additionnelle
                              File size: 7850 bytes
                              MD5...: ca97c95f4edca75fde2e1778d6bcc6b7
                              SHA1..: 996b2b45a3cc4b0e7d524e19c76d5ea4667cbdd4
                              SHA256: fa82e0dc7553d6ac963084bc1b4bfb1e42287b3d6b66399a877a2a79ee1b6c68
                              SHA512: 309f5faa881727b1c90cc1f12ef4b7b7b0532032ecc3b8561020fe1b0ac91875
                              2ccf54b4a34c4b92d95b308ca76e72a5dc94c0d230ed6e6610084c50bd263878
                              ssdeep: 192:ziOiWwyPyh4TY5L5RHQAWIN8kofoGoPko7oKOorCCgbDUFKMtDyAMiOIAQ:z
                              iOiW6OTY5L5iAWvwZfcOOCgXUFLt+W5

                              PEiD..: -
                              TrID..: File type identification
                              HyperText Markup Language (100.0%)
                              PEInfo: -
                              PDFiD.: -
                              RDS...: NSRL Reference Data Set
                              -
                              1. rapport C:\pcanet.ini
                                Antivirus Version Dernière mise à jour Résultat
                                a-squared 4.0.0.101 2009.05.05 -
                                AhnLab-V3 5.0.0.2 2009.05.05 -
                                AntiVir 7.9.0.160 2009.05.05 -
                                Antiy-AVL 2.0.3.1 2009.05.05 -
                                Authentium 5.1.2.4 2009.05.05 -
                                Avast 4.8.1335.0 2009.05.05 -
                                AVG 8.5.0.327 2009.05.05 -
                                BitDefender 7.2 2009.05.05 -
                                CAT-QuickHeal 10.00 2009.05.05 -
                                ClamAV 0.94.1 2009.05.05 -
                                Comodo 1151 2009.05.05 -
                                DrWeb 5.0.0.12182 2009.05.05 -
                                eSafe 7.0.17.0 2009.05.05 -
                                eTrust-Vet 31.6.6490 2009.05.05 -
                                F-Prot 4.4.4.56 2009.05.05 -
                                F-Secure 8.0.14470.0 2009.05.05 -
                                Fortinet 3.117.0.0 2009.05.05 -
                                GData 19 2009.05.05 -
                                Ikarus T3.1.1.49.0 2009.05.05 -
                                K7AntiVirus 7.10.723 2009.05.05 -
                                Kaspersky 7.0.0.125 2009.05.05 -
                                McAfee 5606 2009.05.05 -
                                McAfee+Artemis 5606 2009.05.05 -
                                McAfee-GW-Edition 6.7.6 2009.05.05 -
                                Microsoft 1.4602 2009.05.05 -
                                NOD32 4054 2009.05.05 -
                                Norman 6.01.05 2009.05.05 -
                                nProtect 2009.1.8.0 2009.05.04 -
                                Panda 10.0.0.14 2009.05.05 -
                                PCTools 4.4.2.0 2009.05.05 -
                                Prevx1 3.0 2009.05.05 -
                                Rising 21.28.12.00 2009.05.05 -
                                Sophos 4.41.0 2009.05.05 -
                                Sunbelt 3.2.1858.2 2009.05.05 -
                                Symantec 1.4.4.12 2009.05.05 -
                                TheHacker 6.3.4.1.319 2009.05.05 -
                                TrendMicro 8.950.0.1092 2009.05.05 -
                                VBA32 3.12.10.4 2009.05.05 -
                                ViRobot 2009.5.4.1719 2009.05.04 -
                                VirusBuster 4.6.5.0 2009.05.05 -
                                Information additionnelle
                                File size: 688 bytes
                                MD5...: b920a13baeb3389afc4c486d0170f13e
                                SHA1..: 23b5198d33d96f0e6f0768c6141d98c1b44946d4
                                SHA256: 0d03e9c1b4f7fdc63dc003d8a16c19a777d1dcfbb6a6cbf4568160d27c59ec43
                                SHA512: 236f1fcf972143507cd8f7b1932104e21aba896f67fd1a1310d2eb60bfdab26b
                                9e07763822080899983ea43ba1947e883f52d04bb9c5b45b6d2fd5b3457bc683
                                ssdeep: 12:Q+4anE1yRjZ1jKF7cGlvqsOW9ZF9PA+BMluL3qJWckMdCUMl4tTz:Q+y1yNGr
                                lvRrZFMl03qJWck2w49

                                PEiD..: -
                                TrID..: File type identification
                                Text - UTF-16 (LE) encoded (64.4%)
                                MP3 audio (32.2%)
                                Lumena CEL bitmap (2.0%)
                                Corel Photo Paint (1.3%)
                                PEInfo: -
                                PDFiD.: -
                                RDS...: NSRL Reference Data Set
                                -
                                packers (F-Prot): Unicode
                                1. rapport C:\hpqp.ini
                                  Antivirus Version Dernière mise à jour Résultat
                                  a-squared 4.0.0.101 2009.05.05 -
                                  AhnLab-V3 5.0.0.2 2009.05.05 -
                                  AntiVir 7.9.0.160 2009.05.05 -
                                  Antiy-AVL 2.0.3.1 2009.05.05 -
                                  Authentium 5.1.2.4 2009.05.05 -
                                  Avast 4.8.1335.0 2009.05.05 -
                                  AVG 8.5.0.327 2009.05.05 -
                                  BitDefender 7.2 2009.05.05 -
                                  CAT-QuickHeal 10.00 2009.05.05 -
                                  ClamAV 0.94.1 2009.05.05 -
                                  Comodo 1151 2009.05.05 -
                                  DrWeb 5.0.0.12182 2009.05.05 -
                                  eSafe 7.0.17.0 2009.05.05 -
                                  eTrust-Vet 31.6.6490 2009.05.05 -
                                  F-Prot 4.4.4.56 2009.05.05 -
                                  F-Secure 8.0.14470.0 2009.05.05 -
                                  Fortinet 3.117.0.0 2009.05.05 -
                                  GData 19 2009.05.05 -
                                  Ikarus T3.1.1.49.0 2009.05.05 -
                                  K7AntiVirus 7.10.723 2009.05.05 -
                                  Kaspersky 7.0.0.125 2009.05.05 -
                                  McAfee 5606 2009.05.05 -
                                  McAfee+Artemis 5606 2009.05.05 -
                                  McAfee-GW-Edition 6.7.6 2009.05.05 -
                                  Microsoft 1.4602 2009.05.05 -
                                  NOD32 4054 2009.05.05 -
                                  Norman 6.01.05 2009.05.05 -
                                  nProtect 2009.1.8.0 2009.05.04 -
                                  Panda 10.0.0.14 2009.05.05 -
                                  PCTools 4.4.2.0 2009.05.05 -
                                  Prevx1 3.0 2009.05.05 -
                                  Rising 21.28.12.00 2009.05.05 -
                                  Sophos 4.41.0 2009.05.05 -
                                  Sunbelt 3.2.1858.2 2009.05.05 -
                                  Symantec 1.4.4.12 2009.05.05 -
                                  TheHacker 6.3.4.1.319 2009.05.05 -
                                  TrendMicro 8.950.0.1092 2009.05.05 -
                                  VBA32 3.12.10.4 2009.05.05 -
                                  ViRobot 2009.5.4.1719 2009.05.04 -
                                  VirusBuster 4.6.5.0 2009.05.05 -
                                  Information additionnelle
                                  File size: 1671 bytes
                                  MD5...: 3a668094bbd9b30622cad4eda330c41a
                                  SHA1..: 99f68d42cb8b7011582025437e9061ae39566b97
                                  SHA256: a47bbdcca07dd1f1603019b065edc245db7b4e3161fead324759c3c177ebc8b9
                                  SHA512: cac44fa0fd27ee0935e84594ea04d876cbcd8b6e8a85a73a6c1f95bb181125c8
                                  a8bef7e47af7587ef28b1bcbd9f170733e65a9baf87e2f86b10bf60995b4da29
                                  ssdeep: 48:1CPNtOEa6zC0x4qNI+xhNId6y6xxiKNI7SD4xhNI0:tKccAdn6XifeDiA0

                                  PEiD..: -
                                  TrID..: File type identification
                                  Generic INI configuration (100.0%)
                                  PEInfo: -
                                  PDFiD.: -
                                  RDS...: NSRL Reference Data set
                                  1. rapport handle.dat_
                                    Antivirus Version Dernière mise à jour Résultat
                                    a-squared 4.0.0.101 2009.05.05 -
                                    AhnLab-V3 5.0.0.2 2009.05.05 -
                                    AntiVir 7.9.0.160 2009.05.05 -
                                    Antiy-AVL 2.0.3.1 2009.05.05 -
                                    Authentium 5.1.2.4 2009.05.05 -
                                    Avast 4.8.1335.0 2009.05.05 -
                                    AVG 8.5.0.327 2009.05.05 -
                                    BitDefender 7.2 2009.05.05 -
                                    CAT-QuickHeal 10.00 2009.05.05 -
                                    ClamAV 0.94.1 2009.05.05 -
                                    Comodo 1151 2009.05.05 -
                                    DrWeb 5.0.0.12182 2009.05.05 -
                                    eSafe 7.0.17.0 2009.05.05 -
                                    eTrust-Vet 31.6.6490 2009.05.05 -
                                    F-Prot 4.4.4.56 2009.05.05 -
                                    F-Secure 8.0.14470.0 2009.05.05 -
                                    Fortinet 3.117.0.0 2009.05.05 -
                                    GData 19 2009.05.05 -
                                    Ikarus T3.1.1.49.0 2009.05.05 -
                                    K7AntiVirus 7.10.723 2009.05.05 -
                                    Kaspersky 7.0.0.125 2009.05.05 -
                                    McAfee 5606 2009.05.05 -
                                    McAfee+Artemis 5606 2009.05.05 -
                                    McAfee-GW-Edition 6.7.6 2009.05.05 -
                                    Microsoft 1.4602 2009.05.05 -
                                    NOD32 4054 2009.05.05 -
                                    Norman 6.01.05 2009.05.05 -
                                    nProtect 2009.1.8.0 2009.05.04 -
                                    Panda 10.0.0.14 2009.05.05 -
                                    PCTools 4.4.2.0 2009.05.05 -
                                    Prevx1 3.0 2009.05.05 -
                                    Rising 21.28.12.00 2009.05.05 -
                                    Sophos 4.41.0 2009.05.05 -
                                    Sunbelt 3.2.1858.2 2009.05.05 -
                                    Symantec 1.4.4.12 2009.05.05 -
                                    TheHacker 6.3.4.1.319 2009.05.05 -
                                    TrendMicro 8.950.0.1092 2009.05.05 -
                                    VBA32 3.12.10.4 2009.05.05 -
                                    ViRobot 2009.5.4.1719 2009.05.04 -
                                    VirusBuster 4.6.5.0 2009.05.05 -
                                    Information additionnelle
                                    File size: 179 bytes
                                    MD5...: 4f8fac581058d61398b0929ef00b8963
                                    SHA1..: ed35aa7a03cc25a7105de4cd7b3be18d7468d1a2
                                    SHA256: 770389e24ff1d6e66fec7cbdc0cb8919c911de76533cfa18cb891a23b480e1b5
                                    SHA512: a10cb360092e6ab6351ceaafaca9bceee1daa414dc2ce5c97c59bae6173b77c8
                                    941f5f73b527340a589e9c6af7c02d7d2b5f313a2ea04b561ed4d4c0b7cb301c
                                    ssdeep: 3:h8M/ZlkyLNWE9Am12MFuAvOAsHhcywgWxOSOOh6ljWLmllhmP:h8sttP12MUAv
                                    vahcy0bOOMjWLSiP

                                    PEiD..: -
                                    TrID..: File type identification
                                    Adobe PhotoShop Brush (100.0%)
                                    PEInfo: -
                                    PDFiD.: -
                                    RDS...: NSRL Reference Data Set
                                    -
                                    1. Contributeur sécurité
                                      bien ... avant de poursuivre , quelques vérifs :

                                      1- Avoir accès aux fichiers cachés :

                                      Va dans Menu Démarrer->Poste de travail->Outils->Options des dossiers...->Affichage
                                      * "Afficher les fichiers et dossiers cachés" ---> coché
                                      * "Masquer les extensions des fichiers dont le type est connu" ---> décoché
                                      * "masquer les fichiers du système" ---> décoché
                                      -> valide la modif ( "appliquer" puis "ok" ).
                                      ( tu remetteras les paramètres de départ une fois la désinfection terminée , pas avant ... )

                                      2- Rends toi sur ce site :

                                      https://www.virustotal.com/gui/

                                      Copies ce qui suit et colles le ( ou clique sur "parcourrir" pour aller jusqu'au fichier demandé ) dans l'espace pour la recherche :
                                      C:\handle.dat

                                      Clique sur Send File ( = " Envoyer le fichier " ).

                                      Un rapport va s'élaborer ligne à ligne.

                                      Attends bien la fin ... Il doit comprendre la taille du fichier envoyé.

                                      Sauvegarde le rapport avec le bloc-note.

                                      Copie le dans ta prochaine réponse ...

                                      ( Si VirusTotal indique que le fichier a déjà été analysé, clique sur le bouton Ré-analyse le fichier maintenant )

                                      Fais de même pour :
                                      C:\hpqp.ini
                                      C:\pcanet.ini
                                      D:\Folder.htt
                                      D:\Info.exe
                                      D:\Warning.bmp


                                      Poste moi donc ces 6 rapports ( surtout le début avec le listing des AV , et en précisant bien au début de chacuns à quel fichier ils correspondent ) et attends la suite ...

                                      1. rapport rsit
                                        Logfile of random's system information tool 1.06 (written by random/random)
                                        Run by ale at 2009-05-05 20:13:14
                                        Microsoft Windows XP Professionnel Service Pack 3
                                        System drive C: has 25 GB (24%) free of 105 GB
                                        Total RAM: 2038 MB (80% free)

                                        Logfile of Trend Micro HijackThis v2.0.2
                                        Scan saved at 20:13:22, on 05/05/2009
                                        Platform: Windows XP SP3 (WinNT 5.01.2600)
                                        MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
                                        Boot mode: Normal

                                        Running processes:
                                        C:\WINDOWS\System32\smss.exe
                                        C:\WINDOWS\system32\winlogon.exe
                                        C:\WINDOWS\system32\services.exe
                                        C:\WINDOWS\system32\lsass.exe
                                        C:\WINDOWS\system32\svchost.exe
                                        C:\WINDOWS\System32\svchost.exe
                                        C:\WINDOWS\system32\svchost.exe
                                        C:\WINDOWS\system32\spoolsv.exe
                                        C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
                                        C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
                                        C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                                        C:\Program Files\Bonjour\mDNSResponder.exe
                                        C:\WINDOWS\eHome\ehRecvr.exe
                                        C:\WINDOWS\eHome\ehSched.exe
                                        C:\PROGRA~1\WinTV\EPG Services\System\EPGService.exe
                                        C:\Program Files\Google\Update\GoogleUpdate.exe
                                        C:\WINDOWS\System32\svchost.exe
                                        C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
                                        C:\WINDOWS\system32\svchost.exe
                                        C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
                                        C:\PROGRA~1\Bandoo\Bandoo.exe
                                        C:\PROGRA~1\Bandoo\BandooUI.exe
                                        C:\WINDOWS\system32\dllhost.exe
                                        C:\WINDOWS\system32\wuauclt.exe
                                        C:\WINDOWS\explorer.exe
                                        C:\WINDOWS\system32\notepad.exe
                                        C:\Documents and Settings\ale\Bureau\RSIT.exe
                                        C:\Program Files\trend micro\ale.exe

                                        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
                                        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
                                        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                                        R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
                                        R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost;*.local
                                        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                                        R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
                                        O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
                                        O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
                                        O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
                                        O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
                                        O2 - BHO: Click-to-Call BHO - {5C255C8A-E604-49b4-9D64-90988571CECB} - C:\Program Files\Windows Live\Messenger\wlchtc.dll
                                        O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
                                        O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                                        O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
                                        O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
                                        O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
                                        O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
                                        O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
                                        O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
                                        O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
                                        O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
                                        O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
                                        O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
                                        O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
                                        O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] CHDAudPropShortcut.exe
                                        O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                                        O4 - HKLM\..\Run: [Cpqset] C:\Program Files\Hewlett-Packard\Default Settings\cpqset.exe
                                        O4 - HKLM\..\Run: [RecGuard] C:\Windows\SMINST\RecGuard.exe
                                        O4 - HKLM\..\Run: [LVCOMS] C:\Program Files\Fichiers communs\Logitech\QCDriver3\LVCOMS.EXE
                                        O4 - HKLM\..\Run: [LogitechGalleryRepair] C:\Program Files\Logitech\ImageStudio\ISStart.exe
                                        O4 - HKLM\..\Run: [LogitechImageStudioTray] C:\Program Files\Logitech\ImageStudio\LogiTray.exe
                                        O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
                                        O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
                                        O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                                        O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
                                        O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
                                        O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
                                        O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                                        O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
                                        O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
                                        O4 - HKCU\..\Run: [Messenger (Yahoo!)] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
                                        O4 - HKCU\..\Run: [Arovax AntiSpyware] C:\Program Files\Arovax AntiSpyware\arovaxantispyware.exe /s
                                        O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
                                        O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
                                        O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
                                        O4 - HKCU\..\Run: [SalaatTime] C:\Program Files\Salaat Time\SalaatTime.exe
                                        O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
                                        O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
                                        O4 - Startup: Adobe Media Player.lnk = C:\Program Files\Adobe Media Player\Adobe Media Player.exe
                                        O4 - Global Startup: AutoStart IR.lnk = C:\Program Files\WinTV\Ir.exe
                                        O4 - Global Startup: Démarrage rapide de HP Photosmart Premier.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
                                        O4 - Global Startup: GlobeTrotter Connect.lnk = C:\Program Files\Bouygues\GlobeTrotter Connect\GlobeTrotter Connect.exe
                                        O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
                                        O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
                                        O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
                                        O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
                                        O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
                                        O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
                                        O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
                                        O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
                                        O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
                                        O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                                        O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                                        O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                                        O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                                        O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
                                        O14 - IERESET.INF: START_PAGE_URL=http://ie.redirect.hp.com/...
                                        O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w3/pr01/resources/MSNPUpld.cab
                                        O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/...
                                        O16 - DPF: {FE0BD779-44EE-4A4B-AA2E-743C63F2E5E6} (IWinAmpActiveX Class) - http://pdl.stream.aol.com/downloads/aol/unagi/ampx_en_dl.cab
                                        O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
                                        O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
                                        O20 - AppInit_DLLs: c:\progra~1\bandoo\bndhook.dll c:\progra~1\bandoo\bndhook.dll
                                        O23 - Service: AddFiltr - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\AddFiltr.exe
                                        O23 - Service: Avira AntiVir Personal - Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
                                        O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
                                        O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                                        O23 - Service: Bandoo Coordinator - Discordia Limited - C:\PROGRA~1\Bandoo\Bandoo.exe
                                        O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
                                        O23 - Service: EPGService - Hauppauge Computer Works - C:\PROGRA~1\WinTV\EPG Services\System\EPGService.exe
                                        O23 - Service: Service Google Update (gupdate1c98ec843a4d890) (gupdate1c98ec843a4d890) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
                                        O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                                        O23 - Service: HauppaugeTVServer - Hauppauge Computer Works - C:\PROGRA~1\WinTV\HCWTVS~1.EXE
                                        O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
                                        O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - c:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe
                                        O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
                                        O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
                                        O23 - Service: Nero BackItUp Scheduler 4.0 - Unknown owner - C:\Program Files\Fichiers communs\Nero\Nero BackItUp 4\NBService.exe (file missing)
                                        O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
                                        O24 - Desktop Component 0: (no name) - file:///C:/DOCUME~1/ale/LOCALS~1/Temp/msohtml1/01/clip_image002.jpg
                                        • 1
                                        • 2
                                        • 3