TR\Vundo.Gen

Bonjour,
J'ai un virus (avira antivir) et il me trouve toutes les 5 minutes ce virus comment faire pour le supprimer car en cliquant sur "supprimer" ça ne le supprime pa :s
Merci de votre aide
De plus msn ne fonctionne plus : lorsque je me connecte, mes contacts connecté recoivent un lien (que moi meme j'ai recu et que j'ai cliqué) pui sje suis obliger de me déconnecté.
Configuration: Windows Vista
Safari 528.16

11 réponses

  1. Contributeur
    Trés bien,

    Infection Navipromo, celle-ci arrive lorsque tu télécharges des programmes tels que :

    Funky Emoticons
    Game Attack
    go-astro
    GoRecord
    HotTVPlayer / HotTVPlayer & Paris Hilton
    Live-Player
    MailSkinner
    Messenger Skinner
    Instant Access
    InternetGameBox
    Official Emule (Version d'Emule modifiée)
    Original Solitaire
    SuperSexPlayer
    Speed Downloading
    Sudoplanet
    Webmediaplayer
    Sur le site www.games-desktop.com (n'allez pas dessus!!)

    - Relances Navilog1 et choisis cette fois l'option2
    - Laisses l'outil travailler et patientes jusqu'au message : *** Nettoyage terminée le ***
    - Un rapport sera généré, postes son contenu

    Note : tu trouveras également le rapport Cleanavi.txt à la racine du disque C

    -----------------------------
    - Telecharges Malwarebytes' Anti-Malware :

    - Une fois téléchargé, lances l'installation ---> il se mettra automatiquement à jour

    - Une fois installé, fermes toutes les applications en cours et lances Malwarebytes

    - Executes un examen rapide du pc ( tu n'auras pas accés à internet pendant l'analyse)

    - A la fin du scan clic sur " Afficher les resultats ", si Malwarebytes a trouvé des infections >> clic sur " Supprimer la selection "

    - Si il a besoin de redemarrer le pc pour finir la desinfection, acceptes

    - Un rapport s'etablira, postes son contenu.
    0
    1. Re,

      Laisse tomber.

      ++
      0
      1. Search Navipromo version 3.7.7 commencé le 13/05/2009 à 20:01:50,79

        !!! Attention,ce rapport peut indiquer des fichiers/programmes légitimes!!!
        !!! Postez ce rapport sur le forum pour le faire analyser !!!
        !!! Ne lancez pas la partie désinfection sans l'avis d'un spécialiste !!!

        Outil exécuté depuis C:\Program Files\navilog1

        Mise à jour le 12.05.2009 à 18h00 par IL-MAFIOSO

        Microsoft® Windows Vista™ Édition Familiale Premium ( v6.0.6000 )
        X86-based PC ( Multiprocessor Free : Intel(R) Core(TM)2 Duo CPU E6750 @ 2.66GHz )
        BIOS : Default System BIOS
        USER : Carteron Benoît ( Administrator )
        BOOT : Normal boot

        Antivirus : Avira AntiVir PersonalEdition Classic 8.0.1.30 (Not Activated)

        C:\ (Local Disk) - NTFS - Total:298 Go (Free:80 Go)
        D:\ (CD or DVD)
        E:\ (USB) - FAT - Total:973 Mo (Free:0 Go)
        F:\ (USB)

        Recherche executé en mode normal

        *** Recherche dossiers dans "C:\Windows" ***

        *** Recherche dossiers dans "C:\Program Files" ***

        *** Recherche dossiers dans "c:\progra~2\micros~1\windows\startm~1\programs" ***

        ...\MessengerSkinner trouvé !

        *** Recherche dossiers dans "c:\progra~2\micros~1\windows\startm~1" ***

        *** Recherche dossiers dans "C:\ProgramData" ***

        *** Recherche dossiers dans "c:\users\carter~1\appdata\roaming\micros~1\windows\startm~1\programs" ***

        *** Recherche dossiers dans "C:\Users\Carteron BenoŒt\AppData\Roaming" ***

        ...\MessengerSkinner trouvé !

        *** Recherche avec Catchme-rootkit/stealth malware detector par gmer ***
        pour + d'infos : http://www.gmer.net

        *** Recherche avec GenericNaviSearch ***
        !!! Tous ces résultats peuvent révéler des fichiers légitimes !!!
        !!! A vérifier impérativement avant toute suppression manuelle !!!

        * Recherche dans "C:\Windows\system32" *

        * Recherche dans "C:\Users\Carteron BenoŒt\AppData\Local\Microsoft" *

        * Recherche dans "C:\Users\Carteron BenoŒt\AppData\Local" *

        *** Recherche fichiers ***

        C:\Windows\system32\nvs2.inf trouvé !

        *** Recherche clés spécifiques dans le Registre ***
        !! Les clés trouvées ne sont pas forcément infectées !!

        HKEY_CURRENT_USER\Software\Lanconfig

        [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
        "kmiyg"="\"c:\\users\\carteron benoŒt\\appdata\\local\\kmiyg.exe\" kmiyg"

        *** Module de Recherche complémentaire ***
        (Recherche fichiers spécifiques)

        1)Recherche nouveaux fichiers Instant Access :

        2)Recherche Heuristique :

        * Dans "C:\Windows\system32" :

        * Dans "C:\Users\Carteron BenoŒt\AppData\Local\Microsoft" :

        * Dans "C:\Users\Carteron BenoŒt\AppData\Local" :

        kmiyg.dat trouvé !
        kmiyg_nav.dat trouvé !
        kmiyg_navps.dat trouvé !

        3)Recherche Certificats :

        Certificat Egroup trouvé !
        Certificat Electronic-Group trouvé !
        Certificat Montorgueil absent !
        Certificat OOO-Favorit trouvé !
        Certificat Sunny-Day-Design-Ltd absent !

        4)Recherche autres dossiers et fichiers connus :

        *** Analyse terminée le 13/05/2009 à 20:10:52,28 ***
        0
    2. Re,

      je ne vois pas l'utilité de lui demander le rapport


      Pour moi si..;)

      0
      1. Excusez moi mais c'est quoi le rapport que vous me demandez?
        0
    3. Contributeur
      Salut V-X

      - Oui j'ai bien vu, mais l'outil étant obsolète, je ne vois pas l'utilité de lui demander le rapport, mais bon pourquoi pas ?

      - Karldu, passes Navilog1 puis postes si tu veux le rapport Vundofix
      0
      1. B'soir,


        2009-05-13 18:14:25 ----D---- C:\VundoFix Backups
        2009-05-13 18:14:25 ----A---- C:\VundoFix.txt


        As tu un rapport avec ?

        Si oui poste le STP.

        merci

        Bonne suite.
        0
        1. Contributeur
          ;-) Salut Ske,

          Karldu, pour le moment :

          Telecharges Navilog1 sur ton bureau :
          http://perso.orange.fr/il.mafioso/Navifix/Navilog1.exe

          - Desactives la garde de ton Antivirus celle de ton (es) antispyware (s) ( si tu en as)
          - Lances l'installation en executant le fichier téléchargé
          - Une fois installé, fermes tous les programmes en cours et cliques-droit ( executer en tant qu'admin) sur Navilog1.exe
          - Choisis la langue et presses la touche " entrée " de ton clavier
          - Une fenetre s'ouvre, presses 1 touche pour passer aux etapes suivantes
          - Le menu du fix s'ouvre, choisis l'option 1 et presses la touche " entrée "
          - Laisses le fix travailler et patientes jusqu'au message *** Analyse terminée le***
          - Un rapport c:\fixnavi.txt s'etablira, postes son contenu...
          0
          1. info.txt logfile of random's system information tool 1.06 2009-05-13 18:55:34

            ======Uninstall list======

            -->C:\Program Files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
            -->C:\Program Files\Nero\Nero 7\nero\uninstall\UNNERO.exe /UNINSTALL
            -->C:\Windows\UNNeroBackItUp.exe /UNINSTALL
            -->MsiExec.exe /I{403EF592-953B-4794-BCEF-ECAB835C2095}
            2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-0016-040C-0000-0000000FF1CE} /uninstall {A0353900-21A2-42CF-B973-883500A027F7}
            2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-0018-040C-0000-0000000FF1CE} /uninstall {A0353900-21A2-42CF-B973-883500A027F7}
            2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001B-040C-0000-0000000FF1CE} /uninstall {A0353900-21A2-42CF-B973-883500A027F7}
            2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001F-0401-0000-0000000FF1CE} /uninstall {5A2F65A4-808F-4A1E-973E-92E17824982D}
            2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001F-0407-0000-0000000FF1CE} /uninstall {2AB528A5-BB1B-4EBE-8E51-AD0C4CD33CA9}
            2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001F-0409-0000-0000000FF1CE} /uninstall {3EC77D26-799B-4CD8-914F-C1565E796173}
            2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001F-040C-0000-0000000FF1CE} /uninstall {430971B1-C31E-45DA-81E0-72C095BAB72C}
            2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001F-0413-0000-0000000FF1CE} /uninstall {B3F4DC34-7F60-4B7C-A79F-1C13012D99D4}
            2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001F-0C0A-0000-0000000FF1CE} /uninstall {F7A31780-33C4-4E39-951A-5EC9B91D7BF1}
            2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-00A1-040C-0000-0000000FF1CE} /uninstall {A0353900-21A2-42CF-B973-883500A027F7}
            2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {BEE75E01-DD3F-4D5F-B96C-609E6538D419}
            32 Bit HP CIO Components Installer-->MsiExec.exe /I{F1E63043-54FC-429B-AB2C-31AF9FBA4BC7}
            Adobe Acrobat and Reader 8.1.2 Security Update 1 (KB403742)-->MsiExec.exe /X{6846389C-BAC0-4374-808E-B120F86AF5D7}
            Adobe Flash Player 10 ActiveX-->C:\Windows\system32\Macromed\Flash\uninstall_activeX.exe
            Adobe Flash Player 10 Plugin-->C:\Windows\system32\Macromed\Flash\uninstall_plugin.exe
            Adobe Reader 8.1.2 - Français-->MsiExec.exe /I{AC76BA86-7AD7-1036-7B44-A81200000003}
            Apple Software Update-->MsiExec.exe /I{6956856F-B6B3-4BE0-BA0B-8F495BE32033}
            ArcSoft Panorama Maker 4-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{D45E8C45-B601-4A80-AFD8-E16338744DE1}\Setup.exe" -l0x40c
            Assistant de connexion Windows Live-->MsiExec.exe /I{DCE8CD14-FBF5-4464-B9A4-E18E473546C7}
            Avira AntiVir Personal - Free Antivirus-->C:\Program Files\Avira\AntiVir PersonalEdition Classic\SETUP.EXE /REMOVE
            Bandoo-->C:\Program Files\Bandoo\PreUninstall.exe
            Bonjour-->MsiExec.exe /I{07287123-B8AC-41CE-8346-3D777245C35B}
            Cabri 3D 2.1.2-->"C:\Program Files\Cabri\Cabri 3D 2.1\uninstall\unins000.exe"
            Cabri 3D Plug-in 2.1.2-->"C:\Program Files\Cabri\Cabri 3D Plug-in 2.1\uninstall\unins000.exe"
            CCleaner (remove only)-->"C:\Program Files\CCleaner\uninst.exe"
            Choice Guard-->MsiExec.exe /I{8FFC5648-FAF8-43A3-BC8F-42BA1E275C4E}
            Coffret de pilotes Logitech QuickCam-->"C:\Program Files\Common Files\LogiShrd\LogiDriverStore\lvdrivers\11.70.1196\LgDrvInst.exe" -remove -instdir"C:\Program Files\Common Files\LogiShrd\LogiDriverStore\lvdrivers\" -enumdelay=2000 -enabledifx -forcedelete -usbhubsfirst -forceremove -cumulativeremove -arpregkey"lvdrivers_11.70" /clone_wait /hide_progress
            Favorit-->c:\users\carteron benoît\appdata\local\kokmm.bat
            Galerie de photos Windows Live-->MsiExec.exe /X{44E54A81-9D91-4AA1-9417-80AFF134F5FF}
            GeoGebra-->"C:\Program Files\GeoGebra\UninstallerData\Uninstaller.exe"
            Gimp 2.6.2-->"C:\Program Files\Gimp-2.0\setup\unins000.exe"
            HijackThis 2.0.2-->"C:\Program Files\Trend Micro\HijackThis\HijackThis.exe" /uninstall
            HP Customer Participation Program 8.0-->C:\Program Files\HP\Digital Imaging\ExtCapUninstall\hpzscr01.exe -datfile hpqhsc01.dat
            HP Imaging Device Functions 8.0-->C:\Program Files\HP\Digital Imaging\DeviceManagement\hpzscr01.exe -datfile hpqbud01.dat
            HP OCR Software 8.0-->C:\Program Files\HP\Digital Imaging\OCR\hpzscr01.exe -datfile hpqbud11.dat
            HP Photosmart Essential-->MsiExec.exe /X{EB21A812-671B-4D08-B974-2A347F0D8F70}
            HP Photosmart.All-In-One Driver Software 8.0 .A-->C:\Program Files\HP\Digital Imaging\{282E5AB2-8E47-4571-B6FA-6B512555B557}\setup\hpzscr01.exe -datfile hposcr18.dat -onestop -showdisconnect -forcereboot
            HP Solution Center 8.0-->C:\Program Files\HP\Digital Imaging\eSupport\hpzscr01.exe -datfile hpqbud05.dat
            HP Update-->MsiExec.exe /X{8C6027FD-53DC-446D-BB75-CACD7028A134}
            Installation Windows Live-->C:\Program Files\Windows Live\Installer\wlarp.exe
            Installation Windows Live-->MsiExec.exe /I{7370DF47-B4F9-4279-BFC3-3F09919F720D}
            Intel(R) Management Engine Interface-->C:\Windows\system32\heciudlg.exe -uninstall
            Intel(R) PRO Network Connections 12.1.12.0-->MsiExec.exe /i{777CA40C-0206-4EF6-A0FC-618BF06BF8D0} ARPREMOVE=1
            Intel(R) PRO Network Connections 12.1.12.0-->MsiExec.exe /i{777CA40C-0206-4EF6-A0FC-618BF06BF8D0} ARPREMOVE=1
            iTunes-->MsiExec.exe /I{585776BC-4BD6-4BD2-A19A-1D6CB44A403B}
            Java(TM) 6 Update 4-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160040}
            Junk Mail filter update-->MsiExec.exe /I{4DE3E3D9-AE81-45DE-9195-3015F7B1DBF3}
            K-Lite Codec Pack 3.9.5 (Full)-->"C:\Program Files\K-Lite Codec Pack\unins000.exe"
            La Version 0101-->C:\geom3D\unins000.exe
            LimeWire 5.1.2-->"C:\Program Files\LimeWire\uninstall.exe"
            Logitech Desktop Messenger-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{900B1197-53F5-4F46-A882-2CFFFE2EEDCB}\Setup.exe" -l0x40c UNINSTALL
            Logitech QuickCam-->MsiExec.exe /X{6444D9D9-CD6C-4464-B970-55C606C944DC}
            Logitech Updater-->MsiExec.exe /I{53735ECE-E461-4FD0-B742-23A352436D3A}
            Maxima 5.13.0-->"C:\Program Files\Maxima-5.13.0\uninst\unins000.exe"
            Messenger Plus! Live-->"C:\Program Files\Messenger Plus! Live\Uninstall.exe"
            Microsoft Office Excel MUI (French) 2007-->MsiExec.exe /X{90120000-0016-040C-0000-0000000FF1CE}
            Microsoft Office Home and Student 2007-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE12\Office Setup Controller\setup.exe" /uninstall HOMESTUDENTR /dll OSETUP.DLL
            Microsoft Office Home and Student 2007-->MsiExec.exe /X{91120000-002F-0000-0000-0000000FF1CE}
            Microsoft Office Language Pack 2007 Service Pack 1 (SP1)-->msiexec /package {90120000-006E-040C-0000-0000000FF1CE} /uninstall {EC50B538-CBE1-42E6-B7FE-87AA540AADFB}
            Microsoft Office Live Add-in 1.3-->MsiExec.exe /I{57F0ED40-8F11-41AA-B926-4A66D0D1A9CC}
            Microsoft Office OneNote MUI (French) 2007-->MsiExec.exe /X{90120000-00A1-040C-0000-0000000FF1CE}
            Microsoft Office PowerPoint MUI (French) 2007-->MsiExec.exe /X{90120000-0018-040C-0000-0000000FF1CE}
            Microsoft Office Proof (Arabic) 2007-->MsiExec.exe /X{90120000-001F-0401-0000-0000000FF1CE}
            Microsoft Office Proof (Dutch) 2007-->MsiExec.exe /X{90120000-001F-0413-0000-0000000FF1CE}
            Microsoft Office Proof (English) 2007-->MsiExec.exe /X{90120000-001F-0409-0000-0000000FF1CE}
            Microsoft Office Proof (French) 2007-->MsiExec.exe /X{90120000-001F-040C-0000-0000000FF1CE}
            Microsoft Office Proof (German) 2007-->MsiExec.exe /X{90120000-001F-0407-0000-0000000FF1CE}
            Microsoft Office Proof (Spanish) 2007-->MsiExec.exe /X{90120000-001F-0C0A-0000-0000000FF1CE}
            Microsoft Office Proofing (French) 2007-->MsiExec.exe /X{90120000-002C-040C-0000-0000000FF1CE}
            Microsoft Office Shared MUI (French) 2007-->MsiExec.exe /X{90120000-006E-040C-0000-0000000FF1CE}
            Microsoft Office Word MUI (French) 2007-->MsiExec.exe /X{90120000-001B-040C-0000-0000000FF1CE}
            Microsoft Search Enhancement Pack-->MsiExec.exe /I{9C9CEB9D-53FD-49A7-85D2-FE674F72F24E}
            Microsoft Silverlight-->MsiExec.exe /X{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
            Microsoft SQL Server 2005 Compact Edition [ENU]-->MsiExec.exe /I{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}
            Microsoft Sync Framework Runtime Native v1.0 (x86)-->MsiExec.exe /I{8A74E887-8F0F-4017-AF53-CBA42211AAA5}
            Microsoft Sync Framework Services Native v1.0 (x86)-->MsiExec.exe /I{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}
            Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
            Mise à jour Microsoft Office Excel 2007 Help (KB963678)-->msiexec /package {90120000-0016-040C-0000-0000000FF1CE} /uninstall {B761869A-B85C-40E2-994C-A1CE78AC8F2C}
            Mise à jour Microsoft Office Powerpoint 2007 Help (KB963669)-->msiexec /package {90120000-0018-040C-0000-0000000FF1CE} /uninstall {C3DCA38E-005E-41BA-A52A-7C3429F351C3}
            Mise à jour Microsoft Office Word 2007 Help (KB963665)-->msiexec /package {90120000-001B-040C-0000-0000000FF1CE} /uninstall {81536A04-DBFB-4DB3-978F-0F284590C223}
            Monopoly-->C:\Windows\system32\msinfhlp.exe ;uninstall; ;C:\Program Files\Monopoly\Monopoly.dat;
            MSVCRT-->MsiExec.exe /I{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}
            MSXML 4.0 SP2 (KB936181)-->MsiExec.exe /I{C04E32E0-0416-434D-AFB9-6969D703A9EF}
            MSXML 4.0 SP2 (KB941833)-->MsiExec.exe /I{C523D256-313D-4866-B36A-F3DE528246EF}
            MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
            MSXML 4.0 SP2 Parser and SDK-->MsiExec.exe /I{716E0306-8318-4364-8B8F-0CC4E9376BAC}
            Navilog1 3.6.0-->"C:\Program Files\Navilog1\unins000.exe"
            Nero 7 Essentials-->MsiExec.exe /X{2B04D44F-1D1B-4E0E-8431-D04F87C21036}
            Nikon Message Center-->MsiExec.exe /X{D2FCC1AE-6311-47C5-8130-C6C66D77DD71}
            Nikon Transfer-->MsiExec.exe /X{E9757890-7EC5-46C8-99AB-B00F07B6525C}
            NVIDIA Drivers-->C:\Windows\system32\NVUNINST.EXE UninstallGUI
            OpenOffice.org 3.0-->MsiExec.exe /I{1572F66F-F9AD-4D45-B0D2-0F45A0D5A0F6}
            Outil de téléchargement Windows Live-->MsiExec.exe /I{205C6BDD-7B73-42DE-8505-9A093F35A238}
            PowerDVD-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}\setup.exe" -uninstall
            PowerProducer-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{B7A0CE06-068E-11D6-97FD-0050BACBF861}\setup.exe" -uninstall
            QuickTime-->MsiExec.exe /I{1838C5A2-AB32-4145-85C1-BB9B8DFA24CD}
            RealPlayer-->C:\Program Files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
            Safari-->MsiExec.exe /I{AF10D7E4-D29A-45DA-8050-B116097B69B5}
            Security Update for 2007 Microsoft Office System (KB951550)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {B243E9A5-ED77-4F1B-B338-2486FD82DC85}
            Security Update for 2007 Microsoft Office System (KB951944)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {797AE457-BA17-4BBC-B501-25FB3A0103C7}
            Security Update for 2007 Microsoft Office System (KB960003)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {F04F8702-18D0-458D-921E-146FB7CD38CF}
            Security Update for CAPICOM (KB931906)-->MsiExec.exe /I{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
            Security Update for CAPICOM (KB931906)-->MsiExec.exe /X{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
            Security Update for Microsoft Office Excel 2007 (KB959997)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {9EAC3AEC-5C81-4856-A05B-DE9DC236D740}
            Security Update for Microsoft Office OneNote 2007 (KB950130)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {F1B2401C-B610-4BF2-AA1C-52C55827A8F4}
            Security Update for Microsoft Office PowerPoint 2007 (KB957789)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {7559E742-FF9F-4FAE-B279-008ED296CB4D}
            Security Update for Microsoft Office system 2007 (KB954326)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {5F7F6FFF-395D-480E-8450-64F385D82C5F}
            Security Update for Microsoft Office system 2007 (KB956828)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {885E081B-72BD-4E76-8E98-30B4BE468FAC}
            Security Update for Microsoft Office Word 2007 (KB956358)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {4551666D-0FD6-4C69-8A81-1C6F2E64517C}
            Security Update for Visio 2007 (KB947590)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {6BAD036C-261F-4BEF-96CF-C20678D07A41}
            Shop for HP Supplies-->C:\Program Files\HP\Digital Imaging\HPSSupply\hpzscr01.exe -datfile hpqbud16.dat
            SigmaTel Audio-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{A462213D-EED4-42C2-9A60-7BDD4D4B0B17}\setup.exe" -l0x40c -remove -removeonly
            SmartShopper-->C:\Program Files\Smart-Shopper\Uninst.exe
            TI Connect 1.6-->MsiExec.exe /I{A8B94669-8654-4126-BD28-D0D2412CDED6}
            Update for 2007 Microsoft Office System (KB967642)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {C444285D-5E4F-48A4-91DD-47AAAA68E92D}
            VirginMega.Fr Premium-->MsiExec.exe /I{EE467474-04A8-48D5-8DDF-0F8D3A3CCBE5}
            Windows Live Call-->MsiExec.exe /I{82C7B308-0BDD-49D8-8EA5-9CD3A3F9DF41}
            Windows Live Communications Platform-->MsiExec.exe /I{3B4E636E-9D65-4D67-BA61-189800823F52}
            Windows Live Mail-->MsiExec.exe /I{63DC2DA0-2A6C-4C38-9249-B75395458657}
            Windows Live Messenger-->MsiExec.exe /X{059C042E-796A-4ACC-A81A-ECC2010BB78C}
            Windows Live Movie Maker Bêta-->MsiExec.exe /X{F874DF52-A31F-44C1-A606-EF40F1549261}
            Windows Live OneCare safety scanner-->"C:\Program Files\Windows Live Safety Center\UnInstall.exe"
            Windows Live OneCare safety scanner-->MsiExec.exe /X{FE0646A7-19D0-41B4-A2BB-2C35D644270D}
            Windows Live Sync-->MsiExec.exe /X{9C5EB781-0D37-44B8-9A58-77B3E4BF5F5E}
            Windows Live Toolbar-->MsiExec.exe /X{F7D27C70-90F5-49B9-B188-0A133C0CE353}
            Windows Live Writer-->MsiExec.exe /X{2231CE39-B963-4B9D-823A-F412ECA637B1}
            World of Warcraft-->C:\Program Files\Common Files\Blizzard Entertainment\World of Warcraft (2)\Uninstall.exe
            wxMaxima 0.8.1-->"C:\Program Files\wxMaxima\uninst\unins000.exe"
            Yahoo! Install Manager-->C:\Windows\system32\regsvr32 /u C:\PROGRA~1\Yahoo!\Common\YINSTH~1.DLL
            Yahoo! Toolbar avec bloqueur de fenêtres pop-up-->C:\PROGRA~1\Yahoo!\Common\unyt.exe

            ======Security center information======

            AV: Avira AntiVir PersonalEdition Classic
            AS: Windows Defender

            ======System event log======

            Computer Name: PC-de-CarteronB
            Event Code: 7031
            Message: Le service Service KtmRm pour Distributed Transaction Coordinator s'est terminé de manière inattendue. Ceci s'est produit 2 fois. L'action corrective suivante va être effectuée dans 11000 millisecondes : Redémarrer le service.
            Record Number: 167601
            Source Name: Service Control Manager
            Time Written: 20090513153251.000000-000
            Event Type: Erreur
            User:

            Computer Name: PC-de-CarteronB
            Event Code: 7031
            Message: Le service Connaissance des emplacements réseau s'est terminé de manière inattendue. Ceci s'est produit 2 fois. L'action corrective suivante va être effectuée dans 100 millisecondes : Redémarrer le service.
            Record Number: 167602
            Source Name: Service Control Manager
            Time Written: 20090513153251.000000-000
            Event Type: Erreur
            User:

            Computer Name: PC-de-CarteronB
            Event Code: 7031
            Message: Le service Téléphonie s'est terminé de manière inattendue. Ceci s'est produit 2 fois. L'action corrective suivante va être effectuée dans 300000 millisecondes : Redémarrer le service.
            Record Number: 167603
            Source Name: Service Control Manager
            Time Written: 20090513153251.000000-000
            Event Type: Erreur
            User:

            Computer Name: PC-de-CarteronB
            Event Code: 7031
            Message: Le service Services Terminal Server s'est terminé de manière inattendue. Ceci s'est produit 2 fois. L'action corrective suivante va être effectuée dans 60000 millisecondes : Redémarrer le service.
            Record Number: 167604
            Source Name: Service Control Manager
            Time Written: 20090513153251.000000-000
            Event Type: Erreur
            User:

            Computer Name: PC-de-CarteronB
            Event Code: 4226
            Message: TCP/IP a atteint la limite de sécurité imposée sur le nombre de tentatives de connexion TCP simultanées.
            Record Number: 167614
            Source Name: Tcpip
            Time Written: 20090513155140.447548-000
            Event Type: Avertissement
            User:

            =====Application event log=====

            Computer Name: PC-de-CarteronB
            Event Code: 4113
            Message: AntiVir a détecté dans le fichier C:\Users\Carteron Benoît\AppData\Local\Temp\IXP000.TMP\is.exe un code suspect avec la désignation 'TR/Vundo.Gen'!
            Record Number: 37722
            Source Name: Avira AntiVir
            Time Written: 20090513163413.000000-000
            Event Type: Avertissement
            User: AUTORITE NT\SYSTEM

            Computer Name: PC-de-CarteronB
            Event Code: 4113
            Message: AntiVir a détecté dans le fichier C:\Users\Carteron Benoît\AppData\Local\Temp\IXP000.TMP\is.exe un code suspect avec la désignation 'TR/Vundo.Gen'!
            Record Number: 37723
            Source Name: Avira AntiVir
            Time Written: 20090513164414.000000-000
            Event Type: Avertissement
            User: AUTORITE NT\SYSTEM

            Computer Name: PC-de-CarteronB
            Event Code: 4113
            Message: AntiVir a détecté dans le fichier C:\Users\Carteron Benoît\AppData\Local\Temp\IXP000.TMP\is.exe un code suspect avec la désignation 'TR/Vundo.Gen'!
            Record Number: 37724
            Source Name: Avira AntiVir
            Time Written: 20090513164414.000000-000
            Event Type: Avertissement
            User: AUTORITE NT\SYSTEM

            Computer Name: PC-de-CarteronB
            Event Code: 4113
            Message: AntiVir a détecté dans le fichier C:\Users\Carteron Benoît\AppData\Local\Temp\IXP000.TMP\is.exe un code suspect avec la désignation 'TR/Vundo.Gen'!
            Record Number: 37725
            Source Name: Avira AntiVir
            Time Written: 20090513165415.000000-000
            Event Type: Avertissement
            User: AUTORITE NT\SYSTEM

            Computer Name: PC-de-CarteronB
            Event Code: 4113
            Message: AntiVir a détecté dans le fichier C:\Users\Carteron Benoît\AppData\Local\Temp\IXP000.TMP\is.exe un code suspect avec la désignation 'TR/Vundo.Gen'!
            Record Number: 37726
            Source Name: Avira AntiVir
            Time Written: 20090513165415.000000-000
            Event Type: Avertissement
            User: AUTORITE NT\SYSTEM

            =====Security event log=====

            Computer Name: PC-de-CarteronB
            Event Code: 5032
            Message: Le Pare-feu Windows n’a pas pu notifier l’utilisateur qu’il a empêché une application d’accepter des connexions entrantes sur le réseau.

            Code d’erreur : 2
            Record Number: 41389
            Source Name: Microsoft-Windows-Security-Auditing
            Time Written: 20090102184807.506579-000
            Event Type: Échec de l'audit
            User:

            Computer Name: PC-de-CarteronB
            Event Code: 5032
            Message: Le Pare-feu Windows n’a pas pu notifier l’utilisateur qu’il a empêché une application d’accepter des connexions entrantes sur le réseau.

            Code d’erreur : 2
            Record Number: 41390
            Source Name: Microsoft-Windows-Security-Auditing
            Time Written: 20090102184807.506579-000
            Event Type: Échec de l'audit
            User:

            Computer Name: PC-de-CarteronB
            Event Code: 5032
            Message: Le Pare-feu Windows n’a pas pu notifier l’utilisateur qu’il a empêché une application d’accepter des connexions entrantes sur le réseau.

            Code d’erreur : 2
            Record Number: 41391
            Source Name: Microsoft-Windows-Security-Auditing
            Time Written: 20090102184807.506579-000
            Event Type: Échec de l'audit
            User:

            Computer Name: PC-de-CarteronB
            Event Code: 5032
            Message: Le Pare-feu Windows n’a pas pu notifier l’utilisateur qu’il a empêché une application d’accepter des connexions entrantes sur le réseau.

            Code d’erreur : 2
            Record Number: 41392
            Source Name: Microsoft-Windows-Security-Auditing
            Time Written: 20090102185027.513415-000
            Event Type: Échec de l'audit
            User:

            Computer Name: PC-de-CarteronB
            Event Code: 5032
            Message: Le Pare-feu Windows n’a pas pu notifier l’utilisateur qu’il a empêché une application d’accepter des connexions entrantes sur le réseau.

            Code d’erreur : 2
            Record Number: 41393
            Source Name: Microsoft-Windows-Security-Auditing
            Time Written: 20090102185027.513415-000
            Event Type: Échec de l'audit
            User:

            ======Environment variables======

            "ComSpec"=%SystemRoot%\system32\cmd.exe
            "FP_NO_HOST_CHECK"=NO
            "OS"=Windows_NT
            "Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;C:\Program Files\Intel\DMIX;C:\Program Files\QuickTime\QTSystem\
            "PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC
            "PROCESSOR_ARCHITECTURE"=x86
            "TEMP"=%SystemRoot%\TEMP
            "TMP"=%SystemRoot%\TEMP
            "USERNAME"=SYSTEM
            "windir"=%SystemRoot%
            "PROCESSOR_LEVEL"=6
            "PROCESSOR_IDENTIFIER"=x86 Family 6 Model 15 Stepping 11, GenuineIntel
            "PROCESSOR_REVISION"=0f0b
            "NUMBER_OF_PROCESSORS"=2
            "CLASSPATH"=.;C:\Program Files\Java\jre1.6.0_04\lib\ext\QTJava.zip
            "QTJAVA"=C:\Program Files\Java\jre1.6.0_04\lib\ext\QTJava.zip

            -----------------EOF-----------------
            0
            1. info.txt logfile of random's system information tool 1.06 2009-05-13 18:55:34

              ======Uninstall list======

              -->C:\Program Files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
              -->C:\Program Files\Nero\Nero 7\nero\uninstall\UNNERO.exe /UNINSTALL
              -->C:\Windows\UNNeroBackItUp.exe /UNINSTALL
              -->MsiExec.exe /I{403EF592-953B-4794-BCEF-ECAB835C2095}
              2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-0016-040C-0000-0000000FF1CE} /uninstall {A0353900-21A2-42CF-B973-883500A027F7}
              2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-0018-040C-0000-0000000FF1CE} /uninstall {A0353900-21A2-42CF-B973-883500A027F7}
              2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001B-040C-0000-0000000FF1CE} /uninstall {A0353900-21A2-42CF-B973-883500A027F7}
              2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001F-0401-0000-0000000FF1CE} /uninstall {5A2F65A4-808F-4A1E-973E-92E17824982D}
              2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001F-0407-0000-0000000FF1CE} /uninstall {2AB528A5-BB1B-4EBE-8E51-AD0C4CD33CA9}
              2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001F-0409-0000-0000000FF1CE} /uninstall {3EC77D26-799B-4CD8-914F-C1565E796173}
              2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001F-040C-0000-0000000FF1CE} /uninstall {430971B1-C31E-45DA-81E0-72C095BAB72C}
              2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001F-0413-0000-0000000FF1CE} /uninstall {B3F4DC34-7F60-4B7C-A79F-1C13012D99D4}
              2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001F-0C0A-0000-0000000FF1CE} /uninstall {F7A31780-33C4-4E39-951A-5EC9B91D7BF1}
              2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-00A1-040C-0000-0000000FF1CE} /uninstall {A0353900-21A2-42CF-B973-883500A027F7}
              2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {BEE75E01-DD3F-4D5F-B96C-609E6538D419}
              32 Bit HP CIO Components Installer-->MsiExec.exe /I{F1E63043-54FC-429B-AB2C-31AF9FBA4BC7}
              Adobe Acrobat and Reader 8.1.2 Security Update 1 (KB403742)-->MsiExec.exe /X{6846389C-BAC0-4374-808E-B120F86AF5D7}
              Adobe Flash Player 10 ActiveX-->C:\Windows\system32\Macromed\Flash\uninstall_activeX.exe
              Adobe Flash Player 10 Plugin-->C:\Windows\system32\Macromed\Flash\uninstall_plugin.exe
              Adobe Reader 8.1.2 - Français-->MsiExec.exe /I{AC76BA86-7AD7-1036-7B44-A81200000003}
              Apple Software Update-->MsiExec.exe /I{6956856F-B6B3-4BE0-BA0B-8F495BE32033}
              ArcSoft Panorama Maker 4-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{D45E8C45-B601-4A80-AFD8-E16338744DE1}\Setup.exe" -l0x40c
              Assistant de connexion Windows Live-->MsiExec.exe /I{DCE8CD14-FBF5-4464-B9A4-E18E473546C7}
              Avira AntiVir Personal - Free Antivirus-->C:\Program Files\Avira\AntiVir PersonalEdition Classic\SETUP.EXE /REMOVE
              Bandoo-->C:\Program Files\Bandoo\PreUninstall.exe
              Bonjour-->MsiExec.exe /I{07287123-B8AC-41CE-8346-3D777245C35B}
              Cabri 3D 2.1.2-->"C:\Program Files\Cabri\Cabri 3D 2.1\uninstall\unins000.exe"
              Cabri 3D Plug-in 2.1.2-->"C:\Program Files\Cabri\Cabri 3D Plug-in 2.1\uninstall\unins000.exe"
              CCleaner (remove only)-->"C:\Program Files\CCleaner\uninst.exe"
              Choice Guard-->MsiExec.exe /I{8FFC5648-FAF8-43A3-BC8F-42BA1E275C4E}
              Coffret de pilotes Logitech QuickCam-->"C:\Program Files\Common Files\LogiShrd\LogiDriverStore\lvdrivers\11.70.1196\LgDrvInst.exe" -remove -instdir"C:\Program Files\Common Files\LogiShrd\LogiDriverStore\lvdrivers\" -enumdelay=2000 -enabledifx -forcedelete -usbhubsfirst -forceremove -cumulativeremove -arpregkey"lvdrivers_11.70" /clone_wait /hide_progress
              Favorit-->c:\users\carteron benoît\appdata\local\kokmm.bat
              Galerie de photos Windows Live-->MsiExec.exe /X{44E54A81-9D91-4AA1-9417-80AFF134F5FF}
              GeoGebra-->"C:\Program Files\GeoGebra\UninstallerData\Uninstaller.exe"
              Gimp 2.6.2-->"C:\Program Files\Gimp-2.0\setup\unins000.exe"
              HijackThis 2.0.2-->"C:\Program Files\Trend Micro\HijackThis\HijackThis.exe" /uninstall
              HP Customer Participation Program 8.0-->C:\Program Files\HP\Digital Imaging\ExtCapUninstall\hpzscr01.exe -datfile hpqhsc01.dat
              HP Imaging Device Functions 8.0-->C:\Program Files\HP\Digital Imaging\DeviceManagement\hpzscr01.exe -datfile hpqbud01.dat
              HP OCR Software 8.0-->C:\Program Files\HP\Digital Imaging\OCR\hpzscr01.exe -datfile hpqbud11.dat
              HP Photosmart Essential-->MsiExec.exe /X{EB21A812-671B-4D08-B974-2A347F0D8F70}
              HP Photosmart.All-In-One Driver Software 8.0 .A-->C:\Program Files\HP\Digital Imaging\{282E5AB2-8E47-4571-B6FA-6B512555B557}\setup\hpzscr01.exe -datfile hposcr18.dat -onestop -showdisconnect -forcereboot
              HP Solution Center 8.0-->C:\Program Files\HP\Digital Imaging\eSupport\hpzscr01.exe -datfile hpqbud05.dat
              HP Update-->MsiExec.exe /X{8C6027FD-53DC-446D-BB75-CACD7028A134}
              Installation Windows Live-->C:\Program Files\Windows Live\Installer\wlarp.exe
              Installation Windows Live-->MsiExec.exe /I{7370DF47-B4F9-4279-BFC3-3F09919F720D}
              Intel(R) Management Engine Interface-->C:\Windows\system32\heciudlg.exe -uninstall
              Intel(R) PRO Network Connections 12.1.12.0-->MsiExec.exe /i{777CA40C-0206-4EF6-A0FC-618BF06BF8D0} ARPREMOVE=1
              Intel(R) PRO Network Connections 12.1.12.0-->MsiExec.exe /i{777CA40C-0206-4EF6-A0FC-618BF06BF8D0} ARPREMOVE=1
              iTunes-->MsiExec.exe /I{585776BC-4BD6-4BD2-A19A-1D6CB44A403B}
              Java(TM) 6 Update 4-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160040}
              Junk Mail filter update-->MsiExec.exe /I{4DE3E3D9-AE81-45DE-9195-3015F7B1DBF3}
              K-Lite Codec Pack 3.9.5 (Full)-->"C:\Program Files\K-Lite Codec Pack\unins000.exe"
              La Version 0101-->C:\geom3D\unins000.exe
              LimeWire 5.1.2-->"C:\Program Files\LimeWire\uninstall.exe"
              Logitech Desktop Messenger-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{900B1197-53F5-4F46-A882-2CFFFE2EEDCB}\Setup.exe" -l0x40c UNINSTALL
              Logitech QuickCam-->MsiExec.exe /X{6444D9D9-CD6C-4464-B970-55C606C944DC}
              Logitech Updater-->MsiExec.exe /I{53735ECE-E461-4FD0-B742-23A352436D3A}
              Maxima 5.13.0-->"C:\Program Files\Maxima-5.13.0\uninst\unins000.exe"
              Messenger Plus! Live-->"C:\Program Files\Messenger Plus! Live\Uninstall.exe"
              Microsoft Office Excel MUI (French) 2007-->MsiExec.exe /X{90120000-0016-040C-0000-0000000FF1CE}
              Microsoft Office Home and Student 2007-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE12\Office Setup Controller\setup.exe" /uninstall HOMESTUDENTR /dll OSETUP.DLL
              Microsoft Office Home and Student 2007-->MsiExec.exe /X{91120000-002F-0000-0000-0000000FF1CE}
              Microsoft Office Language Pack 2007 Service Pack 1 (SP1)-->msiexec /package {90120000-006E-040C-0000-0000000FF1CE} /uninstall {EC50B538-CBE1-42E6-B7FE-87AA540AADFB}
              Microsoft Office Live Add-in 1.3-->MsiExec.exe /I{57F0ED40-8F11-41AA-B926-4A66D0D1A9CC}
              Microsoft Office OneNote MUI (French) 2007-->MsiExec.exe /X{90120000-00A1-040C-0000-0000000FF1CE}
              Microsoft Office PowerPoint MUI (French) 2007-->MsiExec.exe /X{90120000-0018-040C-0000-0000000FF1CE}
              Microsoft Office Proof (Arabic) 2007-->MsiExec.exe /X{90120000-001F-0401-0000-0000000FF1CE}
              Microsoft Office Proof (Dutch) 2007-->MsiExec.exe /X{90120000-001F-0413-0000-0000000FF1CE}
              Microsoft Office Proof (English) 2007-->MsiExec.exe /X{90120000-001F-0409-0000-0000000FF1CE}
              Microsoft Office Proof (French) 2007-->MsiExec.exe /X{90120000-001F-040C-0000-0000000FF1CE}
              Microsoft Office Proof (German) 2007-->MsiExec.exe /X{90120000-001F-0407-0000-0000000FF1CE}
              Microsoft Office Proof (Spanish) 2007-->MsiExec.exe /X{90120000-001F-0C0A-0000-0000000FF1CE}
              Microsoft Office Proofing (French) 2007-->MsiExec.exe /X{90120000-002C-040C-0000-0000000FF1CE}
              Microsoft Office Shared MUI (French) 2007-->MsiExec.exe /X{90120000-006E-040C-0000-0000000FF1CE}
              Microsoft Office Word MUI (French) 2007-->MsiExec.exe /X{90120000-001B-040C-0000-0000000FF1CE}
              Microsoft Search Enhancement Pack-->MsiExec.exe /I{9C9CEB9D-53FD-49A7-85D2-FE674F72F24E}
              Microsoft Silverlight-->MsiExec.exe /X{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
              Microsoft SQL Server 2005 Compact Edition [ENU]-->MsiExec.exe /I{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}
              Microsoft Sync Framework Runtime Native v1.0 (x86)-->MsiExec.exe /I{8A74E887-8F0F-4017-AF53-CBA42211AAA5}
              Microsoft Sync Framework Services Native v1.0 (x86)-->MsiExec.exe /I{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}
              Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
              Mise à jour Microsoft Office Excel 2007 Help (KB963678)-->msiexec /package {90120000-0016-040C-0000-0000000FF1CE} /uninstall {B761869A-B85C-40E2-994C-A1CE78AC8F2C}
              Mise à jour Microsoft Office Powerpoint 2007 Help (KB963669)-->msiexec /package {90120000-0018-040C-0000-0000000FF1CE} /uninstall {C3DCA38E-005E-41BA-A52A-7C3429F351C3}
              Mise à jour Microsoft Office Word 2007 Help (KB963665)-->msiexec /package {90120000-001B-040C-0000-0000000FF1CE} /uninstall {81536A04-DBFB-4DB3-978F-0F284590C223}
              Monopoly-->C:\Windows\system32\msinfhlp.exe ;uninstall; ;C:\Program Files\Monopoly\Monopoly.dat;
              MSVCRT-->MsiExec.exe /I{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}
              MSXML 4.0 SP2 (KB936181)-->MsiExec.exe /I{C04E32E0-0416-434D-AFB9-6969D703A9EF}
              MSXML 4.0 SP2 (KB941833)-->MsiExec.exe /I{C523D256-313D-4866-B36A-F3DE528246EF}
              MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
              MSXML 4.0 SP2 Parser and SDK-->MsiExec.exe /I{716E0306-8318-4364-8B8F-0CC4E9376BAC}
              Navilog1 3.6.0-->"C:\Program Files\Navilog1\unins000.exe"
              Nero 7 Essentials-->MsiExec.exe /X{2B04D44F-1D1B-4E0E-8431-D04F87C21036}
              Nikon Message Center-->MsiExec.exe /X{D2FCC1AE-6311-47C5-8130-C6C66D77DD71}
              Nikon Transfer-->MsiExec.exe /X{E9757890-7EC5-46C8-99AB-B00F07B6525C}
              NVIDIA Drivers-->C:\Windows\system32\NVUNINST.EXE UninstallGUI
              OpenOffice.org 3.0-->MsiExec.exe /I{1572F66F-F9AD-4D45-B0D2-0F45A0D5A0F6}
              Outil de téléchargement Windows Live-->MsiExec.exe /I{205C6BDD-7B73-42DE-8505-9A093F35A238}
              PowerDVD-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}\setup.exe" -uninstall
              PowerProducer-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{B7A0CE06-068E-11D6-97FD-0050BACBF861}\setup.exe" -uninstall
              QuickTime-->MsiExec.exe /I{1838C5A2-AB32-4145-85C1-BB9B8DFA24CD}
              RealPlayer-->C:\Program Files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
              Safari-->MsiExec.exe /I{AF10D7E4-D29A-45DA-8050-B116097B69B5}
              Security Update for 2007 Microsoft Office System (KB951550)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {B243E9A5-ED77-4F1B-B338-2486FD82DC85}
              Security Update for 2007 Microsoft Office System (KB951944)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {797AE457-BA17-4BBC-B501-25FB3A0103C7}
              Security Update for 2007 Microsoft Office System (KB960003)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {F04F8702-18D0-458D-921E-146FB7CD38CF}
              Security Update for CAPICOM (KB931906)-->MsiExec.exe /I{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
              Security Update for CAPICOM (KB931906)-->MsiExec.exe /X{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
              Security Update for Microsoft Office Excel 2007 (KB959997)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {9EAC3AEC-5C81-4856-A05B-DE9DC236D740}
              Security Update for Microsoft Office OneNote 2007 (KB950130)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {F1B2401C-B610-4BF2-AA1C-52C55827A8F4}
              Security Update for Microsoft Office PowerPoint 2007 (KB957789)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {7559E742-FF9F-4FAE-B279-008ED296CB4D}
              Security Update for Microsoft Office system 2007 (KB954326)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {5F7F6FFF-395D-480E-8450-64F385D82C5F}
              Security Update for Microsoft Office system 2007 (KB956828)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {885E081B-72BD-4E76-8E98-30B4BE468FAC}
              Security Update for Microsoft Office Word 2007 (KB956358)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {4551666D-0FD6-4C69-8A81-1C6F2E64517C}
              Security Update for Visio 2007 (KB947590)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {6BAD036C-261F-4BEF-96CF-C20678D07A41}
              Shop for HP Supplies-->C:\Program Files\HP\Digital Imaging\HPSSupply\hpzscr01.exe -datfile hpqbud16.dat
              SigmaTel Audio-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{A462213D-EED4-42C2-9A60-7BDD4D4B0B17}\setup.exe" -l0x40c -remove -removeonly
              SmartShopper-->C:\Program Files\Smart-Shopper\Uninst.exe
              TI Connect 1.6-->MsiExec.exe /I{A8B94669-8654-4126-BD28-D0D2412CDED6}
              Update for 2007 Microsoft Office System (KB967642)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {C444285D-5E4F-48A4-91DD-47AAAA68E92D}
              VirginMega.Fr Premium-->MsiExec.exe /I{EE467474-04A8-48D5-8DDF-0F8D3A3CCBE5}
              Windows Live Call-->MsiExec.exe /I{82C7B308-0BDD-49D8-8EA5-9CD3A3F9DF41}
              Windows Live Communications Platform-->MsiExec.exe /I{3B4E636E-9D65-4D67-BA61-189800823F52}
              Windows Live Mail-->MsiExec.exe /I{63DC2DA0-2A6C-4C38-9249-B75395458657}
              Windows Live Messenger-->MsiExec.exe /X{059C042E-796A-4ACC-A81A-ECC2010BB78C}
              Windows Live Movie Maker Bêta-->MsiExec.exe /X{F874DF52-A31F-44C1-A606-EF40F1549261}
              Windows Live OneCare safety scanner-->"C:\Program Files\Windows Live Safety Center\UnInstall.exe"
              Windows Live OneCare safety scanner-->MsiExec.exe /X{FE0646A7-19D0-41B4-A2BB-2C35D644270D}
              Windows Live Sync-->MsiExec.exe /X{9C5EB781-0D37-44B8-9A58-77B3E4BF5F5E}
              Windows Live Toolbar-->MsiExec.exe /X{F7D27C70-90F5-49B9-B188-0A133C0CE353}
              Windows Live Writer-->MsiExec.exe /X{2231CE39-B963-4B9D-823A-F412ECA637B1}
              World of Warcraft-->C:\Program Files\Common Files\Blizzard Entertainment\World of Warcraft (2)\Uninstall.exe
              wxMaxima 0.8.1-->"C:\Program Files\wxMaxima\uninst\unins000.exe"
              Yahoo! Install Manager-->C:\Windows\system32\regsvr32 /u C:\PROGRA~1\Yahoo!\Common\YINSTH~1.DLL
              Yahoo! Toolbar avec bloqueur de fenêtres pop-up-->C:\PROGRA~1\Yahoo!\Common\unyt.exe

              ======Security center information======

              AV: Avira AntiVir PersonalEdition Classic
              AS: Windows Defender

              ======System event log======

              Computer Name: PC-de-CarteronB
              Event Code: 7031
              Message: Le service Service KtmRm pour Distributed Transaction Coordinator s'est terminé de manière inattendue. Ceci s'est produit 2 fois. L'action corrective suivante va être effectuée dans 11000 millisecondes : Redémarrer le service.
              Record Number: 167601
              Source Name: Service Control Manager
              Time Written: 20090513153251.000000-000
              Event Type: Erreur
              User:

              Computer Name: PC-de-CarteronB
              Event Code: 7031
              Message: Le service Connaissance des emplacements réseau s'est terminé de manière inattendue. Ceci s'est produit 2 fois. L'action corrective suivante va être effectuée dans 100 millisecondes : Redémarrer le service.
              Record Number: 167602
              Source Name: Service Control Manager
              Time Written: 20090513153251.000000-000
              Event Type: Erreur
              User:

              Computer Name: PC-de-CarteronB
              Event Code: 7031
              Message: Le service Téléphonie s'est terminé de manière inattendue. Ceci s'est produit 2 fois. L'action corrective suivante va être effectuée dans 300000 millisecondes : Redémarrer le service.
              Record Number: 167603
              Source Name: Service Control Manager
              Time Written: 20090513153251.000000-000
              Event Type: Erreur
              User:

              Computer Name: PC-de-CarteronB
              Event Code: 7031
              Message: Le service Services Terminal Server s'est terminé de manière inattendue. Ceci s'est produit 2 fois. L'action corrective suivante va être effectuée dans 60000 millisecondes : Redémarrer le service.
              Record Number: 167604
              Source Name: Service Control Manager
              Time Written: 20090513153251.000000-000
              Event Type: Erreur
              User:

              Computer Name: PC-de-CarteronB
              Event Code: 4226
              Message: TCP/IP a atteint la limite de sécurité imposée sur le nombre de tentatives de connexion TCP simultanées.
              Record Number: 167614
              Source Name: Tcpip
              Time Written: 20090513155140.447548-000
              Event Type: Avertissement
              User:

              =====Application event log=====

              Computer Name: PC-de-CarteronB
              Event Code: 4113
              Message: AntiVir a détecté dans le fichier C:\Users\Carteron Benoît\AppData\Local\Temp\IXP000.TMP\is.exe un code suspect avec la désignation 'TR/Vundo.Gen'!
              Record Number: 37722
              Source Name: Avira AntiVir
              Time Written: 20090513163413.000000-000
              Event Type: Avertissement
              User: AUTORITE NT\SYSTEM

              Computer Name: PC-de-CarteronB
              Event Code: 4113
              Message: AntiVir a détecté dans le fichier C:\Users\Carteron Benoît\AppData\Local\Temp\IXP000.TMP\is.exe un code suspect avec la désignation 'TR/Vundo.Gen'!
              Record Number: 37723
              Source Name: Avira AntiVir
              Time Written: 20090513164414.000000-000
              Event Type: Avertissement
              User: AUTORITE NT\SYSTEM

              Computer Name: PC-de-CarteronB
              Event Code: 4113
              Message: AntiVir a détecté dans le fichier C:\Users\Carteron Benoît\AppData\Local\Temp\IXP000.TMP\is.exe un code suspect avec la désignation 'TR/Vundo.Gen'!
              Record Number: 37724
              Source Name: Avira AntiVir
              Time Written: 20090513164414.000000-000
              Event Type: Avertissement
              User: AUTORITE NT\SYSTEM

              Computer Name: PC-de-CarteronB
              Event Code: 4113
              Message: AntiVir a détecté dans le fichier C:\Users\Carteron Benoît\AppData\Local\Temp\IXP000.TMP\is.exe un code suspect avec la désignation 'TR/Vundo.Gen'!
              Record Number: 37725
              Source Name: Avira AntiVir
              Time Written: 20090513165415.000000-000
              Event Type: Avertissement
              User: AUTORITE NT\SYSTEM

              Computer Name: PC-de-CarteronB
              Event Code: 4113
              Message: AntiVir a détecté dans le fichier C:\Users\Carteron Benoît\AppData\Local\Temp\IXP000.TMP\is.exe un code suspect avec la désignation 'TR/Vundo.Gen'!
              Record Number: 37726
              Source Name: Avira AntiVir
              Time Written: 20090513165415.000000-000
              Event Type: Avertissement
              User: AUTORITE NT\SYSTEM

              =====Security event log=====

              Computer Name: PC-de-CarteronB
              Event Code: 5032
              Message: Le Pare-feu Windows n’a pas pu notifier l’utilisateur qu’il a empêché une application d’accepter des connexions entrantes sur le réseau.

              Code d’erreur : 2
              Record Number: 41389
              Source Name: Microsoft-Windows-Security-Auditing
              Time Written: 20090102184807.506579-000
              Event Type: Échec de l'audit
              User:

              Computer Name: PC-de-CarteronB
              Event Code: 5032
              Message: Le Pare-feu Windows n’a pas pu notifier l’utilisateur qu’il a empêché une application d’accepter des connexions entrantes sur le réseau.

              Code d’erreur : 2
              Record Number: 41390
              Source Name: Microsoft-Windows-Security-Auditing
              Time Written: 20090102184807.506579-000
              Event Type: Échec de l'audit
              User:

              Computer Name: PC-de-CarteronB
              Event Code: 5032
              Message: Le Pare-feu Windows n’a pas pu notifier l’utilisateur qu’il a empêché une application d’accepter des connexions entrantes sur le réseau.

              Code d’erreur : 2
              Record Number: 41391
              Source Name: Microsoft-Windows-Security-Auditing
              Time Written: 20090102184807.506579-000
              Event Type: Échec de l'audit
              User:

              Computer Name: PC-de-CarteronB
              Event Code: 5032
              Message: Le Pare-feu Windows n’a pas pu notifier l’utilisateur qu’il a empêché une application d’accepter des connexions entrantes sur le réseau.

              Code d’erreur : 2
              Record Number: 41392
              Source Name: Microsoft-Windows-Security-Auditing
              Time Written: 20090102185027.513415-000
              Event Type: Échec de l'audit
              User:

              Computer Name: PC-de-CarteronB
              Event Code: 5032
              Message: Le Pare-feu Windows n’a pas pu notifier l’utilisateur qu’il a empêché une application d’accepter des connexions entrantes sur le réseau.

              Code d’erreur : 2
              Record Number: 41393
              Source Name: Microsoft-Windows-Security-Auditing
              Time Written: 20090102185027.513415-000
              Event Type: Échec de l'audit
              User:

              ======Environment variables======

              "ComSpec"=%SystemRoot%\system32\cmd.exe
              "FP_NO_HOST_CHECK"=NO
              "OS"=Windows_NT
              "Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;C:\Program Files\Intel\DMIX;C:\Program Files\QuickTime\QTSystem\
              "PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC
              "PROCESSOR_ARCHITECTURE"=x86
              "TEMP"=%SystemRoot%\TEMP
              "TMP"=%SystemRoot%\TEMP
              "USERNAME"=SYSTEM
              "windir"=%SystemRoot%
              "PROCESSOR_LEVEL"=6
              "PROCESSOR_IDENTIFIER"=x86 Family 6 Model 15 Stepping 11, GenuineIntel
              "PROCESSOR_REVISION"=0f0b
              "NUMBER_OF_PROCESSORS"=2
              "CLASSPATH"=.;C:\Program Files\Java\jre1.6.0_04\lib\ext\QTJava.zip
              "QTJAVA"=C:\Program Files\Java\jre1.6.0_04\lib\ext\QTJava.zip

              -----------------EOF-----------------
              0
              1. Logfile of random's system information tool 1.06 (written by random/random)
                Run by Carteron Benoît at 2009-05-13 18:55:14
                Microsoft® Windows Vista™ Édition Familiale Premium
                System drive C: has 82 GB (27%) free of 305 GB
                Total RAM: 2029 MB (38% free)

                Logfile of Trend Micro HijackThis v2.0.2
                Scan saved at 18:55:30, on 13/05/2009
                Platform: Windows Vista (WinNT 6.00.1904)
                MSIE: Internet Explorer v8.00 (8.00.6001.18702)
                Boot mode: Normal

                Running processes:
                C:\Windows\system32\csrss.exe
                C:\Windows\system32\wininit.exe
                C:\Windows\system32\csrss.exe
                C:\Windows\system32\services.exe
                C:\Windows\system32\lsass.exe
                C:\Windows\system32\lsm.exe
                C:\Windows\system32\winlogon.exe
                C:\Windows\system32\svchost.exe
                C:\Windows\system32\svchost.exe
                C:\Windows\System32\svchost.exe
                C:\Windows\System32\svchost.exe
                C:\Windows\System32\svchost.exe
                C:\Windows\system32\svchost.exe
                C:\Windows\system32\svchost.exe
                C:\Windows\system32\SLsvc.exe
                C:\Windows\system32\svchost.exe
                C:\Windows\system32\Dwm.exe
                C:\Windows\Explorer.EXE
                C:\Windows\System32\spoolsv.exe
                C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
                C:\Windows\system32\svchost.exe
                C:\Windows\system32\taskeng.exe
                C:\Program Files\Common Files\Real\Update_OB\realsched.exe
                C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe
                C:\Program Files\Logitech\QuickCam\Quickcam.exe
                C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
                C:\Windows\msnmsgrss.exe
                C:\Program Files\Windows Sidebar\sidebar.exe
                C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
                C:\Windows\ehome\ehtray.exe
                C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
                C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
                C:\Program Files\Common Files\Nikon\Monitor\NkMonitor.exe
                C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
                C:\Windows\ehome\ehmsas.exe
                C:\Program Files\OpenOffice.org 3\program\soffice.exe
                C:\Program Files\OpenOffice.org 3\program\soffice.bin
                C:\Program Files\Windows Sidebar\sidebar.exe
                C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
                C:\Program Files\Bonjour\mDNSResponder.exe
                C:\Windows\system32\svchost.exe
                C:\Program Files\Common Files\LightScribe\LSSrvc.exe
                C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
                C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
                C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
                C:\Windows\System32\svchost.exe
                C:\Windows\System32\svchost.exe
                C:\Windows\system32\svchost.exe
                C:\Program Files\CyberLink\Shared Files\RichVideo.exe
                C:\Program Files\SigmaTel\C-Major Audio\WDM\STacSV.exe
                C:\Windows\system32\svchost.exe
                C:\Windows\System32\svchost.exe
                C:\PROGRA~1\Bandoo\Bandoo.exe
                C:\Windows\system32\WUDFHost.exe
                C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
                C:\Windows\System32\mobsync.exe
                C:\Windows\system32\taskeng.exe
                C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
                C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe
                C:\Windows\system32\wuauclt.exe
                C:\Program Files\Safari\Safari.exe
                C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                C:\Program Files\Windows Live\Contacts\wlcomm.exe
                C:\Windows\system32\SearchIndexer.exe
                C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
                C:\Program Files\Internet Explorer\iexplore.exe
                C:\Program Files\Internet Explorer\iexplore.exe
                C:\Windows\ehome\ehsched.exe
                C:\Windows\System32\svchost.exe
                C:\Users\CARTER~1\AppData\Local\Temp\tv0wfl5j.tmp\VundoFix.exe
                C:\Program Files\Microsoft Office\Office12\WINWORD.EXE
                C:\Program Files\Microsoft\Office Live\OfficeLiveSignIn.exe
                C:\Program Files\Internet Explorer\iexplore.exe
                C:\Windows\system32\SearchFilterHost.exe
                C:\Program Files\Internet Explorer\iexplore.exe
                C:\Windows\system32\SearchProtocolHost.exe
                C:\Users\Carteron Benoît\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\M4UXGEVF\RSIT[1].exe
                C:\Windows\system32\wbem\wmiprvse.exe
                C:\Program Files\Trend Micro\HijackThis\Carteron Benoît.exe

                R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
                R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
                R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://fr.msn.com/
                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
                R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ads.eorezo.com/cgi-bin/advert/getads.cgi?x_dp_id=18&x_format=redirect
                R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
                R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
                R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
                R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                F2 - REG:system.ini: UserInit=C:\Windows\system32\userinit.exe,C:\Windows\system32\twex.exe,
                O1 - Hosts: ::1 localhost
                O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
                O2 - BHO: Smart-Shopper - {4A7C84E2-E95C-43C6-8DD3-03ABCD0EB60E} - C:\Program Files\Smart-Shopper\Bin\2.5.1\Smrt-Shpr.dll
                O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
                O2 - BHO: EoRezoBHO - {64F56FC1-1272-44CD-BA6E-39723696E350} - C:\Program Files\EoRezo\EoAdv\EoRezoBHO.dll (file missing)
                O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll
                O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
                O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
                O3 - Toolbar: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
                O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
                O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe"
                O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam\Quickcam.exe" /hide
                O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
                O4 - HKLM\..\Run: [Windows UDP Control Center] msnmsgrss.exe
                O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
                O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
                O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
                O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
                O4 - HKCU\..\Run: [Cld2000.exe] C:\Program Files\Calendrier\Cld2000.exe
                O4 - HKCU\..\Run: [kmiyg] "c:\users\carteron benoît\appdata\local\kmiyg.exe" kmiyg
                O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
                O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
                O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
                O4 - HKUS\S-1-5-18\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background (User 'SYSTEM')
                O4 - HKUS\.DEFAULT\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background (User 'Default user')
                O4 - Startup: OneNote 2007 - Capture d'écran et lancement.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
                O4 - Startup: OpenOffice.org 3.0.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe
                O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
                O4 - Global Startup: Nikon Monitor.lnk = C:\Program Files\Common Files\Nikon\Monitor\NkMonitor.exe
                O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
                O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
                O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
                O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
                O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
                O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
                O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
                O9 - Extra button: SmartShopper - Compare product prices - {3CC3D8FE-F0E0-4dd1-A69A-8C56BCC7BEBF} - C:\Program Files\Smart-Shopper\Bin\2.5.1\Smrt-Shpr.dll
                O9 - Extra button: SmartShopper - Compare travel rates - {3CC3D8FE-F0E0-4dd1-A69A-8C56BCC7BEC0} - C:\Program Files\Smart-Shopper\Bin\2.5.1\Smrt-Shpr.dll
                O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
                O13 - Gopher Prefix:
                O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
                O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
                O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
                O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
                O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
                O20 - AppInit_DLLs: c:\progra~1\bandoo\bndhook.dll
                O23 - Service: Planificateur Avira AntiVir Personal - Free Antivirus (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
                O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
                O23 - Service: Bandoo Coordinator - Discordia Limited - C:\PROGRA~1\Bandoo\Bandoo.exe
                O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
                O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
                O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
                O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
                O23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
                O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
                O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe
                O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
                O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
                O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
                O23 - Service: SigmaTel Audio Service (STacSV) - SigmaTel, Inc. - C:\Program Files\SigmaTel\C-Major Audio\WDM\STacSV.exe
                0
                1. Contributeur sécurité
                  Salut,

                  Edit > pas assez rapide lol ...

                  Bonne suite à vous deux .... =)

                  a+

                  0
                  1. Contributeur
                    Salut,

                    - Sous vista, desactives le controle des comptes utilisateurs --> panneau de config --> comptes utilisateur --> desactiver le controle des comptes utilisateurs

                    Telecharges RSIT " Random's System Information Tool " sur ton bureau : http://images.malwareremoval.com/random/RSIT.exe

                    - Fermes toutes les applications en cours et clic-droit ( executer en tant qu'admin.) sur RSIT.exe
                    - Selectionnes " Continue " à l'ecran >> RSIT va analyser le pc et verifier si l'outil hijackthis ( version à jour) est present sur le pc, si ce n'est pas le cas, RSIT le telechargera >> acceptes la license
                    - Une fois l'analyse terminée, 2 rapports.txt s'ouvrent, log.txt à l'écran et info.txt dans la barre des taches
                    - Postes le contenu des 2 rapports
                    1
                    1. bonsoir, je suis sous Windows XP SP2. J'ai aussi cette mer.. TR/Vundo.Gen. Avira a détecté, j'ai fait un Malware, ai supprimé, rebooté l'ordi, Malware ne le trouve plus, mais Avira continue, en plus l'ordi est lent. Merci de bien vouloir m'aider. Cordialement.
                      0
                    2. Contributeur
                      @cactus83Salut Cactus83,

                      Il serait préférable que tu fasses ton message personnel, cela rendra les postes plus compréhensibles et la réponse à ton problème sera plus efficace...
                      - Fais ceci :

                      http://www.commentcamarche.net/forum/forum 7#ecrire

                      --> Tu mets d'abord un titre en rapport à ton problème ( sois clair et explicite), puis dans le cadre, exposes clairement ton problème ( quelques lignes suffiront) et cliques sur " Ajouter "

                      --> puis patientes un peu, un " helpeur " te prendra en charge "

                      - Bonne chance !
                      0
                    3. @Ced_Kingmes excuses et merci
                      0