Rapport Navilog

Bonjour, je pense que mon ordinateur est infecté : pendant mes nombreuses navigations sur le net des fenêtres de pubs s'ouvrent sans arrêt !
J'ai fait une analyse Navilog et voila le rapport , merci d'avance pour votre aide .

Search Navipromo version 3.7.7 commencé le 30/05/2009 à 15:46:06,15

!!! Attention,ce rapport peut indiquer des fichiers/programmes légitimes!!!
!!! Postez ce rapport sur le forum pour le faire analyser !!!
!!! Ne lancez pas la partie désinfection sans l'avis d'un spécialiste !!!

Outil exécuté depuis C:\Program Files\navilog1

Mise à jour le 12.05.2009 à 18h00 par IL-MAFIOSO

Microsoft Windows XP Édition familiale ( v5.1.2600 ) Service Pack 3
X86-based PC ( Multiprocessor Free : Intel(R) Pentium(R) 4 CPU 3.00GHz )
BIOS : Award Medallion BIOS v6.00PG
USER : þ}{Ø£Ñ!× ( Administrator )
BOOT : Normal boot

Antivirus : AntiVir Desktop 9.0.1.26 (Activated)

A:\ (USB)
C:\ (Local Disk) - NTFS - Total:226 Go (Free:193 Go)
D:\ (CD or DVD)
E:\ (USB)
F:\ (USB)
G:\ (USB)
H:\ (USB)

Recherche executé en mode normal

*** Recherche dossiers dans "C:\WINDOWS" ***

*** Recherche dossiers dans "C:\Program Files" ***

*** Recherche dossiers dans "C:\Documents and Settings\All Users\menudm~1\progra~1" ***

*** Recherche dossiers dans "C:\Documents and Settings\All Users\menudm~1" ***

*** Recherche dossiers dans "c:\docume~1\alluse~1\applic~1" ***

*** Recherche dossiers dans "C:\Documents and Settings\þ}{Ø£Ñ!×\applic~1" ***

*** Recherche dossiers dans "C:\DOCUME~1\PROPRI~1\applic~1" ***

*** Recherche dossiers dans "C:\Documents and Settings\þ}{Ø£Ñ!×\locals~1\applic~1" ***

*** Recherche dossiers dans "C:\Documents and Settings\þ}{Ø£Ñ!×\menudm~1\progra~1" ***

*** Recherche avec Catchme-rootkit/stealth malware detector par gmer ***
pour + d'infos : http://www.gmer.net

*** Recherche avec GenericNaviSearch ***
!!! Tous ces résultats peuvent révéler des fichiers légitimes !!!
!!! A vérifier impérativement avant toute suppression manuelle !!!

* Recherche dans "C:\WINDOWS\system32" *

* Recherche dans "C:\Documents and Settings\þ}{Ø£Ñ!×\locals~1\applic~1" *

*** Recherche fichiers ***

*** Recherche clés spécifiques dans le Registre ***
!! Les clés trouvées ne sont pas forcément infectées !!

*** Module de Recherche complémentaire ***
(Recherche fichiers spécifiques)

1)Recherche nouveaux fichiers Instant Access :

2)Recherche Heuristique :

* Dans "C:\WINDOWS\system32" :

* Dans "C:\Documents and Settings\þ}{Ø£Ñ!×\locals~1\applic~1" :

3)Recherche Certificats :

Certificat Egroup absent !
Certificat Electronic-Group absent !
Certificat Montorgueil absent !
Certificat OOO-Favorit absent !
Certificat Sunny-Day-Design-Ltd absent !

4)Recherche autres dossiers et fichiers connus :

*** Analyse terminée le 30/05/2009 à 15:58:43,85 ***
Configuration: Windows XP
Firefox 3.0.10

9 réponses

  1. Personne pour m'aider svp ?
    0
    1. Verdict ? Suis-je infecté ? :(
      0
      1. Le rapport UsFix aprés clean :

        ############################## [ UsbFix V3.026 | Cleaning ]

        # User : þ}{Ø£Ñ!× (Administrateurs) # 404323740009
        # Update on 26/05/09 by Chiquitine29, C_XX & Chimay8
        # WebSite : http://pagesperso-orange.fr/NosTools/usbfix.html
        # Start at: 16:30:04 | 30/05/2009

        # Intel(R) Pentium(R) 4 CPU 3.00GHz
        # Microsoft Windows XP Édition familiale (5.1.2600 32-bit) # Service Pack 3
        # Internet Explorer 8.0.6001.18702
        # Windows Firewall Status : Enabled
        # AV : AntiVir Desktop 9.0.1.26 [ Enabled | Updated ]

        # A:\ # Lecteur de disquettes 3 ½ pouces
        # C:\ # Disque fixe local # 226,87 Go (193,39 Go free) [HDD] # NTFS
        # D:\ # Disque CD-ROM
        # E:\ # Disque amovible
        # F:\ # Disque amovible
        # G:\ # Disque amovible
        # H:\ # Disque amovible

        ############################## [ Processus actifs ]

        C:\WINDOWS\System32\smss.exe
        C:\WINDOWS\system32\csrss.exe
        C:\WINDOWS\system32\winlogon.exe
        C:\WINDOWS\system32\services.exe
        C:\WINDOWS\system32\lsass.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\system32\logonui.exe
        C:\WINDOWS\system32\spoolsv.exe
        c:\program files\fichiers communs\logitech\lvmvfm\LVPrcSrv.exe
        C:\Program Files\Avira\AntiVir Desktop\sched.exe
        C:\WINDOWS\Explorer.EXE
        C:\Program Files\Avira\AntiVir Desktop\avguard.exe
        C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe
        C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
        C:\Program Files\Bonjour\mDNSResponder.exe
        C:\WINDOWS\system32\drivers\CDAC11BA.EXE
        c:\APPS\Powercinema\Kernel\TV\CLCapSvc.exe
        c:\APPS\Powercinema\Kernel\TV\CLSched.exe
        C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe
        C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLService.exe
        C:\Documents and Settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S40RP7.EXE
        c:\APPS\HIDSERVICE\HIDSERVICE.exe
        C:\Program Files\Java\jre6\bin\jqs.exe
        C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
        C:\WINDOWS\system32\slserv.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\System32\TUProgSt.exe
        C:\WINDOWS\system32\wbem\wmiprvse.exe
        C:\WINDOWS\System32\alg.exe
        C:\WINDOWS\system32\wbem\wmiapsrv.exe
        C:\WINDOWS\system32\wbem\wmiprvse.exe

        ################## [ Fichiers # Dossiers infectieux ]

        Deleted ! "C:\Documents and Settings\ç}{œ¥!ž\RavMonLog"
        Deleted ! C:\DOCUME~1\}{!~1\LOCALS~1\Temp\VP6Install.exe
        Deleted ! C:\install.exe

        ################## [ Registre # Clés Run infectieuses ]

        Deleted ! HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\taskmgr.exe

        ################## [ Registre # Mountpoints2 ]

        Deleted ! HKCU\...\Explorer\MountPoints2\{06c768d2-e2a6-11da-a28d-00038a000015}\Shell\Auto\Command
        Deleted ! HKCU\...\Explorer\MountPoints2\{5f9f1a5c-0ed9-11dd-a739-00038a000015}\Shell\Auto\Command

        ################## [ Listing des fichiers présent ]

        [15/03/2005 15:28|-rahs----|215] - C:\BOOT.BAK
        [10/02/2008 14:21|-rah-----|296] - C:\boot.ini
        [05/08/2004 15:00|-rahs----|4952] - C:\Bootfont.bin
        [05/08/2004 15:00|-rahs----|263488] - C:\cmldr
        [17/05/2005 13:17|--a------|5228544] - C:\diagcd20.iso
        [07/11/2007 08:00|--a------|17734] - C:\eula.1028.txt
        [07/11/2007 08:00|--a------|17734] - C:\eula.1031.txt
        [07/11/2007 08:00|--a------|10134] - C:\eula.1033.txt
        [07/11/2007 08:00|--a------|17734] - C:\eula.1036.txt
        [07/11/2007 08:00|--a------|17734] - C:\eula.1040.txt
        [07/11/2007 08:00|--a------|118] - C:\eula.1041.txt
        [07/11/2007 08:00|--a------|17734] - C:\eula.1042.txt
        [07/11/2007 08:00|--a------|17734] - C:\eula.2052.txt
        [07/11/2007 08:00|--a------|17734] - C:\eula.3082.txt
        [30/05/2009 15:58|--a------|2709] - C:\fixnavi.txt
        [07/11/2007 08:00|--a------|1110] - C:\globdata.ini
        [04/07/2007 20:07|--a------|164] - C:\install.dat
        [07/11/2007 08:00|--a------|843] - C:\install.ini
        [07/11/2007 08:03|--a------|76304] - C:\install.res.1028.dll
        [07/11/2007 08:03|--a------|96272] - C:\install.res.1031.dll
        [07/11/2007 08:03|--a------|91152] - C:\install.res.1033.dll
        [07/11/2007 08:03|--a------|97296] - C:\install.res.1036.dll
        [07/11/2007 08:03|--a------|95248] - C:\install.res.1040.dll
        [07/11/2007 08:03|--a------|81424] - C:\install.res.1041.dll
        [07/11/2007 08:03|--a------|79888] - C:\install.res.1042.dll
        [07/11/2007 08:03|--a------|75792] - C:\install.res.2052.dll
        [07/11/2007 08:03|--a------|96272] - C:\install.res.3082.dll
        [15/03/2005 15:31|-rahs----|0] - C:\IO.SYS
        [15/03/2005 15:33|--ah-----|736] - C:\IPH.PH
        [15/03/2005 15:31|-rahs----|0] - C:\MSDOS.SYS
        [05/08/2004 15:00|-rahs----|47564] - C:\NTDETECT.COM
        [18/09/2008 12:57|-rahs----|252240] - C:\ntldr
        [?|?|?] - C:\pagefile.sys
        [29/05/2007 18:15|--ah-----|268] - C:\sqmdata00.sqm
        [30/05/2007 12:16|--ah-----|232] - C:\sqmdata01.sqm
        [11/06/2007 14:45|--ah-----|268] - C:\sqmdata02.sqm
        [12/06/2007 09:38|--ah-----|280] - C:\sqmdata03.sqm
        [13/06/2007 12:20|--ah-----|268] - C:\sqmdata04.sqm
        [19/06/2007 11:32|--ah-----|268] - C:\sqmdata05.sqm
        [21/06/2007 20:51|--ah-----|268] - C:\sqmdata06.sqm
        [21/06/2007 22:12|--ah-----|232] - C:\sqmdata07.sqm
        [27/06/2007 15:33|--ah-----|232] - C:\sqmdata08.sqm
        [26/07/2007 13:38|--ah-----|268] - C:\sqmdata09.sqm
        [26/07/2007 13:38|--ah-----|136] - C:\sqmdata10.sqm
        [08/11/2007 18:24|--ah-----|268] - C:\sqmdata11.sqm
        [20/06/2008 23:43|--ah-----|268] - C:\sqmdata12.sqm
        [15/05/2007 11:44|--ah-----|268] - C:\sqmdata13.sqm
        [15/05/2007 18:23|--ah-----|268] - C:\sqmdata14.sqm
        [19/05/2007 13:04|--ah-----|268] - C:\sqmdata15.sqm
        [21/05/2007 09:41|--ah-----|268] - C:\sqmdata16.sqm
        [22/05/2007 18:10|--ah-----|268] - C:\sqmdata17.sqm
        [28/05/2007 11:25|--ah-----|268] - C:\sqmdata18.sqm
        [29/05/2007 15:05|--ah-----|268] - C:\sqmdata19.sqm
        [29/05/2007 18:15|--ah-----|244] - C:\sqmnoopt00.sqm
        [30/05/2007 12:16|--ah-----|244] - C:\sqmnoopt01.sqm
        [11/06/2007 14:45|--ah-----|244] - C:\sqmnoopt02.sqm
        [12/06/2007 09:38|--ah-----|244] - C:\sqmnoopt03.sqm
        [13/06/2007 12:20|--ah-----|244] - C:\sqmnoopt04.sqm
        [19/06/2007 11:32|--ah-----|244] - C:\sqmnoopt05.sqm
        [21/06/2007 20:51|--ah-----|244] - C:\sqmnoopt06.sqm
        [21/06/2007 22:12|--ah-----|244] - C:\sqmnoopt07.sqm
        [27/06/2007 15:33|--ah-----|244] - C:\sqmnoopt08.sqm
        [26/07/2007 13:38|--ah-----|136] - C:\sqmnoopt09.sqm
        [08/11/2007 18:24|--ah-----|244] - C:\sqmnoopt10.sqm
        [20/06/2008 23:43|--ah-----|244] - C:\sqmnoopt11.sqm
        [14/05/2007 11:09|--ah-----|244] - C:\sqmnoopt12.sqm
        [15/05/2007 11:44|--ah-----|244] - C:\sqmnoopt13.sqm
        [15/05/2007 18:23|--ah-----|244] - C:\sqmnoopt14.sqm
        [19/05/2007 13:04|--ah-----|244] - C:\sqmnoopt15.sqm
        [21/05/2007 09:41|--ah-----|244] - C:\sqmnoopt16.sqm
        [22/05/2007 18:10|--ah-----|244] - C:\sqmnoopt17.sqm
        [28/05/2007 11:25|--ah-----|244] - C:\sqmnoopt18.sqm
        [29/05/2007 15:05|--ah-----|244] - C:\sqmnoopt19.sqm
        [15/03/2005 15:31|--ahs----|1248] - C:\tl6jaw3o.sys
        [30/05/2009 16:31|--a------|6988] - C:\UsbFix.txt
        [07/11/2007 08:00|--a------|5686] - C:\vcredist.bmp
        [07/11/2007 08:09|--a------|1442522] - C:\VC_RED.cab
        [07/11/2007 08:12|--a------|232960] - C:\VC_RED.MSI
        [06/07/2007 01:51|--a------|1564] - C:\VundoFix.txt

        ################## [ Vaccination ]

        # C:\autorun.inf ( # Not infected ) -> Folder created by UsbFix.

        ################## [ Informations # Fichier Suspect ]

        ################## [ Cracks # Keygens # Serials ]

        # -> Nothing found !

        ################## [ ! Fin du rapport # UsbFix V3.026 ! ]
        0
        1. Je me suis rendu compte que le rapport info n'est pas entier :s le revoici :

          info.txt logfile of random's system information tool 1.06 2009-05-30 16:08:40

          ======Uninstall list======

          -->c:\apps\skype\phone\unins000.exe
          -->C:\PROGRA~1\FICHIE~1\AOL\ACS\AcsUninstall.exe /c
          -->C:\Program Files\Fichiers communs\AOL\Screensaver\uninst_ygpss.exe
          -->C:\Program Files\Fichiers communs\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
          -->C:\Program Files\Fichiers communs\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
          -->C:\Program Files\Viewpoint\Viewpoint Experience Technology\mtsAxInstaller.exe /u
          -->C:\WINDOWS\IsUn040c.exe -fC:\WINDOWS\orun32.isu
          -->C:\WINDOWS\Modio\SLAMR2KO\Setup.exe /Remove
          -->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{0BEDBD4E-2D34-47B5-9973-57E62B29307C}\setup.exe"
          -->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{2637C347-9DAD-11D6-9EA2-00055D0CA761}\Setup.EXE" -uninstall
          -->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{5AAFE9B0-B60B-4B12-B22D-6B15507502E5}\Setup.exe" -l0x40c
          -->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{63A317D0-60A6-43FC-848A-9FE4A53B29CE}\setup.exe" -l0x40c
          -->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{99CDAF0C-AF5D-422F-B469-33048A949994}\setup.exe" -l0x40c
          -->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{99CDAF0C-AF5D-422F-B469-33048A949994}\setup.exe" -l0x40c /remove
          -->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{9E54F486-CD4A-44A5-B041-16D4E1E56A53}\setup.exe" -l0x40c
          -->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{9E54F486-CD4A-44A5-B041-16D4E1E56A53}\setup.exe" -l0x40c /remove
          -->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{A82F10CB-18B5-4EAC-AEF2-FA49CD565626}\setup.exe" -l0x40c
          -->rundll32 C:\WINDOWS\system32\atiiiexx.dll,_InfEngUnInstallINFFile_RunDLL@16 -force_restart -flags:0x2010001 -inf_class:DISPLAY -clean
          -->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
          ABBYY FineReader 6.0 Sprint-->MsiExec.exe /I{ACF60000-22B9-4CE9-98D6-2CCF359BAC07}
          AbiWord 2.4.6 (remove only)-->C:\Program Files\AbiSuite2\UninstallAbiWord2.exe
          Adobe Acrobat 5.0-->C:\WINDOWS\ISUNINST.EXE -f"C:\Program Files\Fichiers communs\Adobe\Acrobat 5.0\NT\Uninst.isu" -c"C:\Program Files\Fichiers communs\Adobe\Acrobat 5.0\NT\Uninst.dll"
          Adobe Flash Player 10 ActiveX-->C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
          Adobe Flash Player Plugin-->C:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe
          Adobe Reader 7.0 - Français-->MsiExec.exe /I{AC76BA86-7AD7-1036-7B44-A70000000000}
          Adobe Shockwave Player-->C:\WINDOWS\system32\Adobe\SHOCKW~1\UNWISE.EXE C:\WINDOWS\system32\Adobe\SHOCKW~1\Install.log
          Apple Mobile Device Support-->MsiExec.exe /I{162B71B8-8464-4680-A086-601D555B331D}
          Apple Software Update-->MsiExec.exe /I{6956856F-B6B3-4BE0-BA0B-8F495BE32033}
          Archiveur WinRAR-->C:\Program Files\WinRAR\uninstall.exe
          Assistant de connexion Windows Live-->MsiExec.exe /I{D3116CC7-24DC-4CA3-9CE1-23FED836E9F2}
          AVG Anti-Rootkit Free-->C:\Program Files\GRISOFT\AVG Anti-Rootkit Free\Uninstall.exe
          Avira AntiVir Personal - Free Antivirus-->C:\Program Files\Avira\AntiVir Desktop\setup.exe /REMOVE
          Bonjour-->MsiExec.exe /I{07287123-B8AC-41CE-8346-3D777245C35B}
          Camera RAW Plug-In for EPSON Creativity Suite-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{93EA9C3E-BDFD-4309-A605-9B5BBC0CCEFD}\SETUP.EXE" -l0x40c UNINST
          CCleaner (remove only)-->"C:\Program Files\CCleaner\uninst.exe"
          Compatibility Pack for the 2007 Office system-->MsiExec.exe /X{90120000-0020-040C-0000-0000000FF1CE}
          Correctif pour Windows Internet Explorer 7 (KB947864)-->"C:\WINDOWS\ie7updates\KB947864-IE7\spuninst\spuninst.exe"
          Counter-Strike: Source-->MsiExec.exe /I{9580813D-94B1-4C28-9426-A441E2BB29A5}
          Creative MuVo V200-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{903EC56F-EA7E-4309-B0E6-9F1AE22FCC08}\SETUP.EXE" -l0x40c /remove
          Creative System Information-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{63A317D0-60A6-43FC-848A-9FE4A53B29CE}\setup.exe" -l0x40c /remove
          Defraggler (remove only)-->"C:\Program Files\Defraggler\uninst.exe"
          DivX Codec-->C:\Program Files\DivX\DivXCodecUninstall.exe /CODEC
          DivX Player-->C:\Program Files\DivX\DivXPlayerUninstall.exe /PLAYER
          DivX Web Player-->C:\Program Files\DivX\DivXWebPlayerUninstall.exe /PLUGIN
          EPSON Attach To Email-->C:\Program Files\Fichiers communs\InstallShield\Driver\8\Intel 32\IDriver.exe /M{20C45B32-5AB6-46A4-94EF-58950CAF05E5} /l1033 ADDREMOVEDLG
          EPSON Copy Utility 3-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{67EDD823-135A-4D59-87BD-950616D6E857}\SETUP.EXE" -l0x40c -UnInstall
          EPSON Easy Photo Print-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{3D78F2A2-C893-4ABD-B5FE-AD7011837755}\SETUP.EXE" -l0x40c UNINST
          EPSON File Manager-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{2EB81825-E9EE-44F4-8F51-1240C3898DC6}\Setup.exe" -l0x40c UNINST
          EPSON Logiciel imprimante-->C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\EPUPDATE.EXE /R
          EPSON Scan Assistant-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{2A88F1BF-7041-4E42-84B1-6B4ACB83AC64}\Setup.exe" -l0x40c -u
          EPSON Scan-->C:\Program Files\epson\escndv\setup\setup.exe /r
          EPSON Stylus CX7300_CX8300_DX7400_DX8400 Manuel-->C:\Program Files\EPSON\TPMANUAL\ES_CX_DX\FRA\USE_G\DOCUNINS.EXE
          EPSON Web-To-Page-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{7F14F68C-17FA-4F88-B3FD-7F449C1EBF32}\SETUP.EXE" -l0x40c -anything
          HijackThis 2.0.2-->"C:\Program Files\trend micro\HijackThis.exe" /uninstall
          IE7Pro-->C:\Program Files\IEPro\uninst.exe
          IEEE802.11b WLAN Card-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{3CD8D4DB-EDA2-41E9-9560-2F0DD1C48F83}\Setup.exe" -l0x9
          Ink-->MsiExec.exe /I{9FCB2876-554D-491D-A2CD-58F8252D6C64}
          iTunes-->MsiExec.exe /I{C26B06A9-27BB-45B0-9873-9C623EC2BA38}
          Java(TM) 6 Update 13-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216010FF}
          Java(TM) 6 Update 2-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160020}
          Java(TM) 6 Update 7-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160070}
          Java(TM) SE Runtime Environment 6 Update 1-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160010}
          Java(TM) SE Runtime Environment 6-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160000}
          Lecteur Windows Media 11-->"C:\Program Files\Windows Media Player\Setup_wm.exe" /Uninstall
          LG USB Modem Driver-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\10\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{C3ABE126-2BB2-4246-BFE1-6797679B3579}\setup.exe" -l0x40c -removeonly
          LimeWire 4.16.6-->"C:\Program Files\LimeWire\uninstall.exe"
          Logiciel QuickCam de Logitech-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{C191BE7C-8542-4A61-973A-714EF76C5995}\setup.exe" -l0x40c
          Logitech Desktop Messenger-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{900B1197-53F5-4F46-A882-2CFFFE2EEDCB}\setup.exe" -l0x40c UNINSTALL
          Messenger Plus! Live-->"C:\Program Files\Messenger Plus! Live\Uninstall.exe"
          Microsoft .NET Framework 1.1 French Language Pack-->MsiExec.exe /X{9A394342-4A68-4EBA-85A6-55B559F4E700}
          Microsoft .NET Framework 1.1 Hotfix (KB928366)-->"C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\hotfix.exe" "C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\M928366\M928366Uninstall.msp"
          Microsoft .NET Framework 1.1-->msiexec.exe /X {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
          Microsoft .NET Framework 1.1-->MsiExec.exe /X{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
          Microsoft .NET Framework 2.0 Service Pack 1-->MsiExec.exe /I{B508B3F1-A24A-32C0-B310-85786919EF28}
          Microsoft .NET Framework 3.0 French Language Pack-->MsiExec.exe /X{E3C080B0-23F5-49AF-89F8-8E8DBC89E659}
          Microsoft .NET Framework 3.0-->C:\WINDOWS\Microsoft.NET\Framework\v3.0\Microsoft .NET Framework 3.0\setup.exe
          Microsoft SQL Server 2005 Compact Edition [ENU]-->MsiExec.exe /I{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}
          Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
          Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022-->MsiExec.exe /X{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}
          Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17-->MsiExec.exe /X{9A25302D-30C0-39D9-BD6F-21E6EC160475}
          MioTransfer-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{2F6DA398-707F-4D52-AE6A-7E812D1662D6}\Setup.exe" -l0x40c
          Mise à jour de sécurité pour Windows Internet Explorer 7 (KB928090)-->"C:\WINDOWS\ie7updates\KB928090-IE7\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows Internet Explorer 7 (KB929969)-->"C:\WINDOWS\ie7updates\KB929969\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows Internet Explorer 7 (KB931768)-->"C:\WINDOWS\ie7updates\KB931768-IE7\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows Internet Explorer 7 (KB933566)-->"C:\WINDOWS\ie7updates\KB933566-IE7\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows Internet Explorer 7 (KB937143)-->"C:\WINDOWS\ie7updates\KB937143-IE7\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows Internet Explorer 7 (KB938127)-->"C:\WINDOWS\ie7updates\KB938127-IE7\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows Internet Explorer 7 (KB939653)-->"C:\WINDOWS\ie7updates\KB939653-IE7\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows Internet Explorer 7 (KB942615)-->"C:\WINDOWS\ie7updates\KB942615-IE7\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows Internet Explorer 7 (KB944533)-->"C:\WINDOWS\ie7updates\KB944533-IE7\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows Internet Explorer 7 (KB950759)-->"C:\WINDOWS\ie7updates\KB950759-IE7\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows Internet Explorer 7 (KB953838)-->"C:\WINDOWS\ie7updates\KB953838-IE7\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows Internet Explorer 7 (KB956390)-->"C:\WINDOWS\ie7updates\KB956390-IE7\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows Internet Explorer 7 (KB958215)-->"C:\WINDOWS\ie7updates\KB958215-IE7\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows Internet Explorer 7 (KB960714)-->"C:\WINDOWS\ie7updates\KB960714-IE7\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows Internet Explorer 7 (KB961260)-->"C:\WINDOWS\ie7updates\KB961260-IE7\spuninst\spuninst.exe"
          Mise à jour pour Windows Internet Explorer 8 (KB968220)-->"C:\WINDOWS\ie8updates\KB968220-IE8\spuninst\spuninst.exe"
          Module de prise en charge linguistique de Microsoft .NET Framework 2.0 - FRA-->C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0 Language Pack - FRA\install.exe
          Module de prise en charge linguistique du français de Microsoft .NET Framework 3.0-->c:\WINDOWS\Microsoft.NET\Framework\v3.0\Microsoft .NET Framework 3.0 French Language Pack\setup.exe
          Mozilla Firefox (3.0.10)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
          MP3 Player Utilities 3.5.02-->MsiExec.exe /I{0DE7211B-A7CB-4112-8D62-142A0EBDFAD9}
          MSXML 4.0 SP2 (KB927978)-->MsiExec.exe /I{37477865-A3F1-4772-AD43-AAFC6BCFF99F}
          MSXML 4.0 SP2 (KB936181)-->MsiExec.exe /I{C04E32E0-0416-434D-AFB9-6969D703A9EF}
          MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
          MSXML 4.0 SP2 Parser and SDK-->MsiExec.exe /I{716E0306-8318-4364-8B8F-0CC4E9376BAC}
          MSXML 6.0 Parser (KB933579)-->MsiExec.exe /I{0A869A65-8C94-4F7C-A5C7-972D3C8CED9E}
          Mumble and Murmur-->C:\Program Files\Mumble\Uninstall.exe
          MuVo Driver-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{5AAFE9B0-B60B-4B12-B22D-6B15507502E5}\Setup.exe" -l0x40c /remove
          Navilog1 3.7.7-->"C:\Program Files\Navilog1\unins000.exe"
          OpenOffice.org 3.0-->MsiExec.exe /I{6860B340-530D-46B3-91F8-1AE1F70F7C33}
          Outil de téléchargement Windows Live-->MsiExec.exe /I{205C6BDD-7B73-42DE-8505-9A093F35A238}
          Peter's XML Editor-->MsiExec.exe /I{5E770B51-820C-402E-8569-E02D12C212D2}
          Programme de gestion Camera de Logitech®-->"C:\Program Files\Fichiers communs\Logitech\QCDRV\BIN\SETUP.EXE" UNINSTALL REMOVEPROMPT
          PSPad editor-->"C:\Program Files\PSPad editor\Uninst\unins000.exe"
          QuickTime-->MsiExec.exe /I{216AB108-2AE1-4130-B3D5-20B2C4C80F8F}
          S400-->C:\WINDOWS\system32\CNMS400.EXE -@C:\WINDOWS\IsUn040c.exe -f"C:\BJPrinter\CNMWINDOWS\Canon S400 Installer\Inst\DeIsL2.isu" -pCanon S400-c"C:\BJPrinter\CNMWINDOWS\Canon S400 Installer\Inst\bjinst.dll
          SafeCast Shared Components-->C:\Program Files\Fichiers communs\Macrovision Shared\SafeCast\Install\CDAC13BA.EXE /uninstall
          Security Update for CAPICOM (KB931906)-->MsiExec.exe /I{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
          Security Update for CAPICOM (KB931906)-->MsiExec.exe /X{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
          Shared Add-in Support Update for Microsoft .NET Framework 2.0 (KB908002)-->MsiExec.exe /X{64F3B15C-24C7-4B2B-9B72-65CCBBD7F06B}
          Shockwave-->C:\WINDOWS\system32\Macromed\SHOCKW~1\UNWISE.EXE C:\WINDOWS\system32\Macromed\SHOCKW~1\Install.log
          Skype™ 3.8-->MsiExec.exe /X{5C82DAE5-6EB0-4374-9254-BE3319BA4E82}
          Sonic MyDVD-->MsiExec.exe /I{21657574-BD54-48A2-9450-EB03B2C7FC29}
          Sqirlz Morph-->C:\WINDOWS\Sqirlz Morph Uninstaller.exe
          Steam(TM)-->MsiExec.exe /X{048298C9-A4D3-490B-9FF9-AB023A9238F3}
          TeamSpeak 2 RC2-->"C:\Program Files\Teamspeak2_RC2\unins000.exe"
          TES Construction Set-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\Bethesda Softworks\Morrowind\CSUninstall\Setup.exe" -l0x40c
          TuneUp Utilities 2009-->MsiExec.exe /I{55A29068-F2CE-456C-9148-C869879E2357}
          Ulead COOL 360 1.0-->C:\WINDOWS\IsUn040c.exe -f"C:\Program Files\Ulead Systems\Ulead COOL 360\Uninst.isu" -c"C:\Program Files\Ulead Systems\Ulead COOL 360\IS32Inst.dll"
          Ulead DVD PictureShow 2 SE Basic-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{A9212616-FCA2-4173-BD99-5C741EB3A068}\Setup.exe" -l0x40c
          Ulead Photo Explorer 8.0 SE Basic-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\0700\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{D271DAE0-8D68-4C97-8356-A126D48A1D8C}\Setup.exe" -l0x40c
          Ulead Photo Express 4.0 SE-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{BBC0D330-C37B-4472-BFB9-AA217CF0C95F}\Setup.exe" -l0x40c
          VC80CRTRedist - 8.0.50727.762-->MsiExec.exe /I{767CC44C-9BBC-438D-BAD3-FD4595DD148B}
          VDownloader 0.82-->"C:\Program Files\VDOWNLOADER\unins000.exe"
          Veoh Web Player Beta-->"C:\Program Files\Veoh Networks\VeohWebPlayer\uninst.exe"
          VeriSign i-Nav Email Components-->C:\WINDOWS\iun6002.exe "C:\Program Files\VeriSign\irunin.ini"
          Vivicam 3740(Documents)-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{53B7FA71-3D7C-498C-B714-CF14F34516CE}\Setup.exe" -l0x40c
          ViviCam 3740-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{0A9741D4-AAD3-40E5-B451-5882D92EA037}\SETUP.EXE" -l0x40c
          VLC media player 0.9.9-->C:\Program Files\VideoLAN\VLC\uninstall.exe
          Windows Communication Foundation-->MsiExec.exe /X{491DD792-AD81-429C-9EB4-86DD3D22E333}
          Windows Internet Explorer 8-->"C:\WINDOWS\ie8\spuninst\spuninst.exe"
          Windows Live installer-->MsiExec.exe /X{FD44E544-E7D0-4DBA-9FA0-8AE1A1300390}
          Windows Live Mail-->MsiExec.exe /I{C514C594-23AA-4F13-A070-DB8BDB27594F}
          Windows Live Messenger-->MsiExec.exe /X{BADF6744-3787-48F6-B8C9-4C4995401D65}
          Windows Live OneCare safety scanner-->RunDll32.exe "C:\Program Files\Windows Live Safety Center\wlscCore.dll",UninstallFunction WLSC_SCANNER_PRODUCT
          Windows Live Sync-->MsiExec.exe /X{9C5EB781-0D37-44B8-9A58-77B3E4BF5F5E}
          Windows Media Format 11 runtime-->"C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll
          Windows Presentation Foundation Language Pack (FRA)-->MsiExec.exe /X{6901DD22-527A-41EF-9059-E81FEDE9E494}
          Windows Presentation Foundation-->MsiExec.exe /X{BAF78226-3200-4DB4-BE33-4D922A799840}
          Windows Workflow Foundation FR Language Pack-->MsiExec.exe /I{B84C141C-9A13-44BE-9A69-301D7B11D836}
          Windows Workflow Foundation-->MsiExec.exe /I{7D1B85BD-AA07-48B8-808D-67A4067FC6BD}
          Wise Disk Cleaner 4.41-->"C:\Program Files\Wise Disk Cleaner\unins000.exe"
          Wise Registry Cleaner 4 Free 4.43-->"C:\Program Files\Wise Registry Cleaner\unins000.exe"

          ======Hosts File======

          luciolis2.servegame.com 80.239.180.113
          luciolis2.servegame.com 91.121.124.125
          luciolis2.servegame.com 91.121.106.15
          luciolis2.servegame.com 91.121.69.136
          127.0.0.1 www.007guard.com
          127.0.0.1 007guard.com
          127.0.0.1 008i.com
          127.0.0.1 www.008k.com
          127.0.0.1 008k.com
          127.0.0.1 www.00hq.com

          ======Security center information======

          AV: AntiVir Desktop

          ======System event log======

          Computer Name: 404323740009
          Event Code: 7023
          Message: Le service Gestion d'applications s'est arrêté avec l'erreur :
          Le module spécifié est introuvable.

          Record Number: 18647
          Source Name: Service Control Manager
          Time Written: 20090419161535.000000+120
          Event Type: erreur
          User:

          Computer Name: 404323740009
          Event Code: 7036
          Message: Le service Gestion d'applications est entré dans l'état : arrêté.

          Record Number: 18646
          Source Name: Service Control Manager
          Time Written: 20090419161535.000000+120
          Event Type: Informations
          User:

          Computer Name: 404323740009
          Event Code: 7035
          Message: Un contrôle Démarrer a correctement été envoyé au service Gestion d'applications.

          Record Number: 18645
          Source Name: Service Control Manager
          Time Written: 20090419161535.000000+120
          Event Type: Informations
          User: 404323740009\þ}{Ø£Ñ!×

          Computer Name: 404323740009
          Event Code: 7023
          Message: Le service Gestion d'applications s'est arrêté avec l'erreur :
          Le module spécifié est introuvable.

          Record Number: 18644
          Source Name: Service Control Manager
          Time Written: 20090419161535.000000+120
          Event Type: erreur
          User:

          Computer Name: 404323740009
          Event Code: 7036
          Message: Le service Gestion d'applications est entré dans l'état : arrêté.

          Record Number: 18643
          Source Name: Service Control Manager
          Time Written: 20090419161535.000000+120
          Event Type: Informations
          User:

          =====Application event log=====

          Computer Name: 404323740009
          Event Code: 103
          Message: msnmsgr (4456) \\.\C:\Documents and Settings\þ}{Ø£Ñ!×\Local Settings\Application Data\Microsoft\Messenger\meel67@hotmail.fr\SharingMetadata\Working\database_C644_3920_4439_1521\dfsr.db: Le moteur de base de données a arrêté une instance (0).

          Record Number: 36527
          Source Name: ESENT
          Time Written: 20090429200755.000000+120
          Event Type: Informations
          User:

          Computer Name: 404323740009
          Event Code: 102
          Message: msnmsgr (4456) \\.\C:\Documents and Settings\þ}{Ø£Ñ!×\Local Settings\Application Data\Microsoft\Messenger\meel67@hotmail.fr\SharingMetadata\Working\database_C644_3920_4439_1521\dfsr.db: Le moteur de base de données a démarré une nouvelle instance (0).

          Record Number: 36526
          Source Name: ESENT
          Time Written: 20090429200435.000000+120
          Event Type: Informations
          User:

          Computer Name: 404323740009
          Event Code: 100
          Message: msnmsgr (4456) Le moteur de base de données 5.01.2600.5512 est démarré.

          Record Number: 36525
          Source Name: ESENT
          Time Written: 20090429200435.000000+120
          Event Type: Informations
          User:

          Computer Name: 404323740009
          Event Code: 101
          Message: msnmsgr (4456) Le moteur de base de données est arrêté.

          Record Number: 36524
          Source Name: ESENT
          Time Written: 20090429200342.000000+120
          Event Type: Informations
          User:

          Computer Name: 404323740009
          Event Code: 103
          Message: msnmsgr (4456) \\.\C:\Documents and Settings\þ}{Ø£Ñ!×\Local Settings\Application Data\Microsoft\Messenger\meel67@hotmail.fr\SharingMetadata\Working\database_C644_3920_4439_1521\dfsr.db: Le moteur de base de données a arrêté une instance (0).

          Record Number: 36523
          Source Name: ESENT
          Time Written: 20090429200342.000000+120
          Event Type: Informations
          User:

          ======Environment variables======

          "ComSpec"=%SystemRoot%\system32\cmd.exe
          "Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;C:\ATI Technologies\ATI Control Panel;C:\PROGRA~1\FICHIE~1\SONICS~1\;C:\Program Files\Fichiers communs\Ulead Systems\MPEG;C:\Program Files\Fichiers communs\Ulead Systems\DVD;C:\Program Files\QuickTime\QTSystem\
          "windir"=%SystemRoot%
          "FP_NO_HOST_CHECK"=NO
          "OS"=Windows_NT
          "PROCESSOR_ARCHITECTURE"=x86
          "PROCESSOR_LEVEL"=15
          "PROCESSOR_IDENTIFIER"=x86 Family 15 Model 4 Stepping 3, GenuineIntel
          "PROCESSOR_REVISION"=0403
          "NUMBER_OF_PROCESSORS"=2
          "PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
          "TEMP"=%SystemRoot%\TEMP
          "TMP"=%SystemRoot%\TEMP
          "VeriSign"=C:\Program Files\VeriSign
          "VRSN"=C:\Program Files\VeriSign
          "VeriSignTemp"=C:\Program Files\VeriSign\Temp
          "VRSNTemp"=C:\Program Files\VeriSign\Temp
          "sourcesdk"=c:\program files\steam\steamapps\nitrox67\sourcesdk
          "VProject"=c:\program files\steam\steamapps\nitrox67\counter-strike source\cstrike
          "CLASSPATH"=.;C:\Program Files\Java\jre6\lib\ext\QTJava.zip
          "QTJAVA"=C:\Program Files\Java\jre6\lib\ext\QTJava.zip

          -----------------EOF-----------------
          0
          1. Contributeur sécurité
            Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) susceptible d’avoir été infectés sans les ouvrir

            # Double clique sur le raccourci UsbFix présent sur ton bureau

            # choisi l’option 2 ( Suppression )

            # Ton bureau disparaîtra et le pc redémarrera .

            # Au redémarrage, UsbFix scannera ton pc, laisse travailler l’outil.

            # Ensuite poste le rapport UsbFix.txt qui apparaîtra avec le bureau .

            # Note : Le rapport UsbFix.txt est sauvegardé à la racine du disque.( C:\UsbFix.txt )

            ( CTRL+A Pour tout selectionner , CTRL+C pour copier et CTRL+V pour coller )
            0
            1. Voila le rapport UsbFix :

              ############################## [ UsbFix V3.026 | Scan ]

              # User : þ}{Ø£Ñ!× (Administrateurs) # 404323740009
              # Update on 26/05/09 by Chiquitine29, C_XX & Chimay8
              # WebSite : http://pagesperso-orange.fr/NosTools/usbfix.html
              # Start at: 16:17:53 | 30/05/2009

              # Intel(R) Pentium(R) 4 CPU 3.00GHz
              # Microsoft Windows XP Édition familiale (5.1.2600 32-bit) # Service Pack 3
              # Internet Explorer 8.0.6001.18702
              # Windows Firewall Status : Enabled
              # AV : AntiVir Desktop 9.0.1.26 [ Enabled | Updated ]

              # A:\ # Lecteur de disquettes 3 ½ pouces
              # C:\ # Disque fixe local # 226,87 Go (193,39 Go free) [HDD] # NTFS
              # D:\ # Disque CD-ROM
              # E:\ # Disque amovible
              # F:\ # Disque amovible
              # G:\ # Disque amovible
              # H:\ # Disque amovible

              ############################## [ Processus actifs ]

              C:\WINDOWS\System32\smss.exe
              C:\WINDOWS\system32\csrss.exe
              C:\WINDOWS\system32\winlogon.exe
              C:\WINDOWS\system32\services.exe
              C:\WINDOWS\system32\lsass.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\System32\svchost.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\system32\spoolsv.exe
              c:\program files\fichiers communs\logitech\lvmvfm\LVPrcSrv.exe
              C:\Program Files\Avira\AntiVir Desktop\sched.exe
              C:\WINDOWS\Explorer.EXE
              C:\apps\ABoard\ABoard.exe
              C:\WINDOWS\system32\LVCOMSX.EXE
              C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
              C:\apps\ABoard\AOSD.exe
              C:\Program Files\Java\jre6\bin\jusched.exe
              C:\WINDOWS\system32\ElkCtrl.exe
              C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
              C:\program files\steam\steam.exe
              C:\WINDOWS\system32\ctfmon.exe
              C:\Program Files\Avira\AntiVir Desktop\avguard.exe
              C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe
              C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
              C:\Program Files\Bonjour\mDNSResponder.exe
              C:\WINDOWS\system32\drivers\CDAC11BA.EXE
              c:\APPS\Powercinema\Kernel\TV\CLCapSvc.exe
              c:\APPS\Powercinema\Kernel\TV\CLSched.exe
              C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe
              C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLService.exe
              C:\Documents and Settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S40RP7.EXE
              c:\APPS\HIDSERVICE\HIDSERVICE.exe
              C:\Program Files\Java\jre6\bin\jqs.exe
              C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\System32\TUProgSt.exe
              C:\WINDOWS\System32\alg.exe
              C:\WINDOWS\system32\wbem\wmiapsrv.exe
              C:\Program Files\Windows Live\Messenger\usnsvc.exe
              C:\Program Files\Mozilla Firefox\firefox.exe
              C:\Program Files\Internet Explorer\IEXPLORE.EXE
              C:\Program Files\Internet Explorer\IEXPLORE.EXE
              C:\WINDOWS\system32\wbem\wmiprvse.exe

              ################## [ Registre Startup ]

              HKCU_Main: "Search Page"="https://www.google.com/?gws_rd=ssl"
              HKCU_Main: "Start Page"="https://www.google.fr/?gws_rd=ssl"
              HKCU_Main: "Window Title"="Packard Bell"
              HKLM_logon: "Userinit"="C:\\WINDOWS\\system32\\userinit.exe,"
              HKLM_logon: "DefaultUserName"="ç}{œ¥!ž"
              HKLM_logon: "AltDefaultUserName"="ç}{œ¥!ž"
              HKLM_logon: "LegalNoticeCaption"=""
              HKLM_logon: "LegalNoticeText"=""
              HKLM_Run: PHIME2002ASync="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" /SYNC
              HKLM_Run: PHIME2002A="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" /IMEName
              HKLM_Run: Raccourci vers la page des propriétés de High Definition Audio=HDAudPropShortcut.exe
              HKLM_Run: Alcmtr=ALCMTR.EXE
              HKLM_Run: ACTIVBOARD=c:\apps\ABoard\ABoard.exe
              HKLM_Run: LVCOMSX=C:\WINDOWS\system32\LVCOMSX.EXE
              HKLM_Run: KernelFaultCheck=%systemroot%\system32\dumprep 0 -k
              HKLM_Run: avgnt="C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
              HKLM_Run: SunJavaUpdateSched="C:\Program Files\Java\jre6\bin\jusched.exe"
              HKLM_Run: LogitechCameraService(E)="C:\WINDOWS\system32\ElkCtrl.exe" /automation
              HKCU_Run: msnmsgr="C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
              HKCU_Run: Steam="c:\program files\steam\steam.exe" -silent
              HKCU_Run: ctfmon.exe=C:\WINDOWS\system32\ctfmon.exe

              ################## [ Fichiers # Dossiers infectieux ]

              Found ! "C:\Documents and Settings\ç}{œ¥!ž\RavMonLog"
              Found ! C:\DOCUME~1\}{!~1\LOCALS~1\Temp\VP6Install.exe
              Found ! C:\install.exe

              ################## [ Registre # Clés Run infectieuses ]

              Found ! HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\taskmgr.exe

              ################## [ Registre # Mountpoints2 ]

              HKCU\...\Explorer\MountPoints2\{06c768d2-e2a6-11da-a28d-00038a000015}\Shell\Auto\Command
              HKCU\...\Explorer\MountPoints2\{06c768d2-e2a6-11da-a28d-00038a000015}\Shell\AutoRun\Command
              HKCU\...\Explorer\MountPoints2\{5f9f1a5c-0ed9-11dd-a739-00038a000015}\Shell\Auto\Command
              HKCU\...\Explorer\MountPoints2\{5f9f1a5c-0ed9-11dd-a739-00038a000015}\Shell\AutoRun\Command

              ################## [ Informations # Fichier Suspect ]

              ################## [ Cracks # Keygens # Serials ]

              # -> Nothing found !

              ################## [ ! Fin du rapport # UsbFix V3.026 ! ]
              0
              1. Contributeur sécurité
                Télécharge UsbFix de chiquitine29 sur ton bureau

                http://sd-1.archive-host.com/membres/up/127028005715545653/UsbFix.exe

                --> Lance l installation avec les paramètres par défaut

                Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) suceptible d avoir été infectés sans les ouvrir

                --> Double clic sur le raccourci UsbFix sur ton bureau

                --> Choisis l’option 1 (recherche)

                --> Laisse travailler l’outil

                -->Poste le rapport UsbFix.txt

                Note : le rapport UsbFix.txt est sauvegardé a la racine du disque

                Note : Si le Bureau ne réapparait pas presse Ctrl + Alt + Suppr , Onglet "Fichier" , "Nouvelle tâche" , tapes explorer.exe et valide.
                0
                1. Bonjour , merci d'avoir repondu aussi vite :)

                  Voila le rapport log :

                  Logfile of random's system information tool 1.06 (written by random/random)
                  Run by þ}{Ø£Ñ!× at 2009-05-30 16:08:22
                  Microsoft Windows XP Édition familiale Service Pack 3
                  System drive C: has 198 GB (85%) free of 232 GB
                  Total RAM: 1023 MB (46% free)

                  Logfile of Trend Micro HijackThis v2.0.2
                  Scan saved at 16:08:38, on 30/05/2009
                  Platform: Windows XP SP3 (WinNT 5.01.2600)
                  MSIE: Internet Explorer v8.00 (8.00.6001.18702)
                  Boot mode: Normal

                  Running processes:
                  C:\WINDOWS\System32\smss.exe
                  C:\WINDOWS\system32\winlogon.exe
                  C:\WINDOWS\system32\services.exe
                  C:\WINDOWS\system32\lsass.exe
                  C:\WINDOWS\system32\svchost.exe
                  C:\WINDOWS\System32\svchost.exe
                  C:\WINDOWS\system32\spoolsv.exe
                  c:\program files\fichiers communs\logitech\lvmvfm\LVPrcSrv.exe
                  C:\Program Files\Avira\AntiVir Desktop\sched.exe
                  C:\WINDOWS\Explorer.EXE
                  C:\apps\ABoard\ABoard.exe
                  C:\WINDOWS\system32\LVCOMSX.EXE
                  C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
                  C:\apps\ABoard\AOSD.exe
                  C:\Program Files\Java\jre6\bin\jusched.exe
                  C:\WINDOWS\system32\ElkCtrl.exe
                  C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
                  C:\program files\steam\steam.exe
                  C:\WINDOWS\system32\ctfmon.exe
                  C:\Program Files\Avira\AntiVir Desktop\avguard.exe
                  C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe
                  C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                  C:\Program Files\Bonjour\mDNSResponder.exe
                  C:\WINDOWS\system32\drivers\CDAC11BA.EXE
                  c:\APPS\Powercinema\Kernel\TV\CLCapSvc.exe
                  c:\APPS\Powercinema\Kernel\TV\CLSched.exe
                  C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe
                  C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLService.exe
                  C:\Documents and Settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S40RP7.EXE
                  c:\APPS\HIDSERVICE\HIDSERVICE.exe
                  C:\Program Files\Java\jre6\bin\jqs.exe
                  C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
                  C:\WINDOWS\system32\slserv.exe
                  C:\WINDOWS\system32\svchost.exe
                  C:\WINDOWS\System32\TUProgSt.exe
                  C:\WINDOWS\system32\wbem\wmiapsrv.exe
                  C:\Program Files\Windows Live\Messenger\usnsvc.exe
                  C:\Program Files\Grisoft\AVG Anti-Rootkit Free\avgarkt.exe
                  C:\Program Files\Grisoft\AVG Anti-Rootkit Free\eIkQDh.exe
                  C:\Program Files\Mozilla Firefox\firefox.exe
                  C:\Program Files\Internet Explorer\IEXPLORE.EXE
                  C:\Program Files\Internet Explorer\IEXPLORE.EXE
                  C:\Documents and Settings\þ}{Ø£Ñ!×\Bureau\RSIT.exe
                  C:\Program Files\trend micro\þ}{Ø£Ñ!×.exe

                  R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr/
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
                  R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
                  R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
                  R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
                  R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Packard Bell
                  R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
                  R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                  R3 - URLSearchHook: (no name) - {CE000994-A58C-4441-8938-744CD72AB27F} - (no file)
                  O1 - Hosts: ::1 localhost
                  O1 - Hosts: luciolis2.servegame.com 80.239.180.113
                  O1 - Hosts: luciolis2.servegame.com 91.121.124.125
                  O1 - Hosts: luciolis2.servegame.com 91.121.106.15
                  O1 - Hosts: luciolis2.servegame.com 91.121.69.136
                  O2 - BHO: IE7Pro - {00011268-E188-40DF-A514-835FCD78B1BF} - C:\Program Files\IEPro\iepro.dll
                  O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
                  O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                  O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
                  O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
                  O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
                  O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
                  O3 - Toolbar: (no name) - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - (no file)
                  O3 - Toolbar: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - (no file)
                  O3 - Toolbar: Veoh Web Player Video Finder - {0FBB9689-D3D7-4f7a-A2E2-585B10099BFC} - C:\Program Files\Veoh Networks\VeohWebPlayer\VeohIEToolbar.dll
                  O4 - HKLM\..\Run: [PHIME2002ASync] "C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" /SYNC
                  O4 - HKLM\..\Run: [PHIME2002A] "C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" /IMEName
                  O4 - HKLM\..\Run: [Raccourci vers la page des propriétés de High Definition Audio] HDAudPropShortcut.exe
                  O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
                  O4 - HKLM\..\Run: [ACTIVBOARD] c:\apps\ABoard\ABoard.exe
                  O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
                  O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
                  O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
                  O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
                  O4 - HKLM\..\Run: [LogitechCameraService(E)] "C:\WINDOWS\system32\ElkCtrl.exe" /automation
                  O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
                  O4 - HKCU\..\Run: [Steam] "c:\program files\steam\steam.exe" -silent
                  O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                  O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
                  O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
                  O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
                  O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
                  O9 - Extra button: IE7Pro Grab and Drag - {000002a3-84fe-43f1-b958-f2c3ca804f1a} - C:\Program Files\IEPro\iepro.dll
                  O9 - Extra 'Tools' menuitem: IE7Pro Grab and Drag - {000002a3-84fe-43f1-b958-f2c3ca804f1a} - C:\Program Files\IEPro\iepro.dll
                  O9 - Extra button: IE7Pro Preferences - {0026439F-A980-4f18-8C95-4F1CBBF9C1D8} - C:\Program Files\IEPro\iepro.dll
                  O9 - Extra 'Tools' menuitem: IE7Pro Preferences - {0026439F-A980-4f18-8C95-4F1CBBF9C1D8} - C:\Program Files\IEPro\iepro.dll
                  O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                  O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                  O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                  O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                  O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
                  O14 - IERESET.INF: START_PAGE_URL=file://C:\APPS\IE\offline\fr.htm
                  O16 - DPF: {029FDBA6-3547-11D7-AA4C-0050BF051A00} (Rawflow ICD Client) - http://s.tf1.fr/mmdia/static/rawflow/clients/5.3.1.0/Rawflow.cab
                  O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
                  O16 - DPF: {5C051655-FCD5-4969-9182-770EA5AA5565} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab56986.cab
                  O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.cab
                  O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
                  O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab
                  O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
                  O16 - DPF: {CD995117-98E5-4169-9920-6C12D4C0B548} (HGPlugin9USA Class) - http://gamedownload.ijjimax.com/gamedownload/dist/hgstart/HGPlugin9USA.cab
                  O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
                  O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
                  O18 - Protocol: bw+0 - {E482AD62-19D1-47D8-809A-AACF51B557F0} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
                  O18 - Protocol: bw+0s - {E482AD62-19D1-47D8-809A-AACF51B557F0} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
                  O18 - Protocol: bw-0 - {E482AD62-19D1-47D8-809A-AACF51B557F0} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
                  O18 - Protocol: bw-0s - {E482AD62-19D1-47D8-809A-AACF51B557F0} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
                  O18 - Protocol: bw00 - {E482AD62-19D1-47D8-809A-AACF51B557F0} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
                  O18 - Protocol: bw00s - {E482AD62-19D1-47D8-809A-AACF51B557F0} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
                  O18 - Protocol: bw10 - {E482AD62-19D1-47D8-809A-AACF51B557F0} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
                  O18 - Protocol: bw10s - {E482AD62-19D1-47D8-809A-AACF51B557F0} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
                  O18 - Protocol: bw20 - {E482AD62-19D1-47D8-809A-AACF51B557F0} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
                  O18 - Protocol: bw20s - {E482AD62-19D1-47D8-809A-AACF51B557F0} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
                  O18 - Protocol: bw30 - {E482AD62-19D1-47D8-809A-AACF51B557F0} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
                  O18 - Protocol: bw30s - {E482AD62-19D1-47D8-809A-AACF51B557F0} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
                  O18 - Protocol: bw40 - {E482AD62-19D1-47D8-809A-AACF51B557F0} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
                  O18 - Protocol: bw40s - {E482AD62-19D1-47D8-809A-AACF51B557F0} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
                  O18 - Protocol: bw50 - {E482AD62-19D1-47D8-809A-AACF51B557F0} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
                  O18 - Protocol: bw50s - {E482AD62-19D1-47D8-809A-AACF51B557F0} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
                  O18 - Protocol: bw60 - {E482AD62-19D1-47D8-809A-AACF51B557F0} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
                  O18 - Protocol: bw60s - {E482AD62-19D1-47D8-809A-AACF51B557F0} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
                  O18 - Protocol: bw70 - {E482AD62-19D1-47D8-809A-AACF51B557F0} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
                  O18 - Protocol: bw70s - {E482AD62-19D1-47D8-809A-AACF51B557F0} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
                  O18 - Protocol: bw80 - {E482AD62-19D1-47D8-809A-AACF51B557F0} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
                  O18 - Protocol: bw80s - {E482AD62-19D1-47D8-809A-AACF51B557F0} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
                  O18 - Protocol: bw90 - {E482AD62-19D1-47D8-809A-AACF51B557F0} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
                  O18 - Protocol: bw90s - {E482AD62-19D1-47D8-809A-AACF51B557F0} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
                  O18 - Protocol: bwa0 - {E482AD62-19D1-47D8-809A-AACF51B557F0} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
                  O18 - Protocol: bwa0s - {E482AD62-19D1-47D8-809A-AACF51B557F0} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
                  O18 - Protocol: bwb0 - {E482AD62-19D1-47D8-809A-AACF51B557F0} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
                  O18 - Protocol: bwb0s - {E482AD62-19D1-47D8-809A-AACF51B557F0} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
                  O18 - Protocol: bwc0 - {E482AD62-19D1-47D8-809A-AACF51B557F0} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
                  O18 - Protocol: bwc0s - {E482AD62-19D1-47D8-809A-AACF51B557F0} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
                  O18 - Protocol: bwd0 - {E482AD62-19D1-47D8-809A-AACF51B557F0} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
                  O18 - Protocol: bwd0s - {E482AD62-19D1-47D8-809A-AACF51B557F0} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
                  O18 - Protocol: bwe0 - {E482AD62-19D1-47D8-809A-AACF51B557F0} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
                  O18 - Protocol: bwe0s - {E482AD62-19D1-47D8-809A-AACF51B557F0} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
                  O18 - Protocol: bwf0 - {E482AD62-19D1-47D8-809A-AACF51B557F0} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
                  O18 - Protocol: bwf0s - {E482AD62-19D1-47D8-809A-AACF51B557F0} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
                  O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
                  O18 - Protocol: bwg0 - {E482AD62-19D1-47D8-809A-AACF51B557F0} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
                  O18 - Protocol: bwg0s - {E482AD62-19D1-47D8-809A-AACF51B557F0} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
                  O18 - Protocol: bwh0 - {E482AD62-19D1-47D8-809A-AACF51B557F0} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
                  O18 - Protocol: bwh0s - {E482AD62-19D1-47D8-809A-AACF51B557F0} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
                  O18 - Protocol: bwi0 - {E482AD62-19D1-47D8-809A-AACF51B557F0} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
                  O18 - Protocol: bwi0s - {E482AD62-19D1-47D8-809A-AACF51B557F0} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
                  O18 - Protocol: bwj0 - {E482AD62-19D1-47D8-809A-AACF51B557F0} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
                  O18 - Protocol: bwj0s - {E482AD62-19D1-47D8-809A-AACF51B557F0} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
                  O18 - Protocol: bwk0 - {E482AD62-19D1-47D8-809A-AACF51B557F0} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
                  O18 - Protocol: bwk0s - {E482AD62-19D1-47D8-809A-AACF51B557F0} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
                  O18 - Protocol: bwl0 - {E482AD62-19D1-47D8-809A-AACF51B557F0} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
                  O18 - Protocol: bwl0s - {E482AD62-19D1-47D8-809A-AACF51B557F0} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
                  O18 - Protocol: bwm0 - {E482AD62-19D1-47D8-809A-AACF51B557F0} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
                  O18 - Protocol: bwm0s - {E482AD62-19D1-47D8-809A-AACF51B557F0} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
                  O18 - Protocol: bwn0 - {E482AD62-19D1-47D8-809A-AACF51B557F0} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
                  O18 - Protocol: bwn0s - {E482AD62-19D1-47D8-809A-AACF51B557F0} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
                  O18 - Protocol: bwo0 - {E482AD62-19D1-47D8-809A-AACF51B557F0} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
                  O18 - Protocol: bwo0s - {E482AD62-19D1-47D8-809A-AACF51B557F0} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
                  O18 - Protocol: bwp0 - {E482AD62-19D1-47D8-809A-AACF51B557F0} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
                  O18 - Protocol: bwp0s - {E482AD62-19D1-47D8-809A-AACF51B557F0} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
                  O18 - Protocol: bwq0 - {E482AD62-19D1-47D8-809A-AACF51B557F0} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
                  O18 - Protocol: bwq0s - {E482AD62-19D1-47D8-809A-AACF51B557F0} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
                  O18 - Protocol: bwr0 - {E482AD62-19D1-47D8-809A-AACF51B557F0} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
                  O18 - Protocol: bwr0s - {E482AD62-19D1-47D8-809A-AACF51B557F0} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
                  O18 - Protocol: bws0 - {E482AD62-19D1-47D8-809A-AACF51B557F0} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
                  O18 - Protocol: bws0s - {E482AD62-19D1-47D8-809A-AACF51B557F0} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
                  O18 - Protocol: bwt0 - {E482AD62-19D1-47D8-809A-AACF51B557F0} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
                  O18 - Protocol: bwt0s - {E482AD62-19D1-47D8-809A-AACF51B557F0} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
                  O18 - Protocol: bwu0 - {E482AD62-19D1-47D8-809A-AACF51B557F0} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
                  O18 - Protocol: bwu0s - {E482AD62-19D1-47D8-809A-AACF51B557F0} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
                  O18 - Protocol: bwv0 - {E482AD62-19D1-47D8-809A-AACF51B557F0} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
                  O18 - Protocol: bwv0s - {E482AD62-19D1-47D8-809A-AACF51B557F0} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
                  O18 - Protocol: bww0 - {E482AD62-19D1-47D8-809A-AACF51B557F0} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
                  O18 - Protocol: bww0s - {E482AD62-19D1-47D8-809A-AACF51B557F0} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
                  O18 - Protocol: bwx0 - {E482AD62-19D1-47D8-809A-AACF51B557F0} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
                  O18 - Protocol: bwx0s - {E482AD62-19D1-47D8-809A-AACF51B557F0} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
                  O18 - Protocol: bwy0 - {E482AD62-19D1-47D8-809A-AACF51B557F0} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
                  O18 - Protocol: bwy0s - {E482AD62-19D1-47D8-809A-AACF51B557F0} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
                  O18 - Protocol: bwz0 - {E482AD62-19D1-47D8-809A-AACF51B557F0} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
                  O18 - Protocol: bwz0s - {E482AD62-19D1-47D8-809A-AACF51B557F0} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
                  O18 - Protocol: offline-8876480 - {E482AD62-19D1-47D8-809A-AACF51B557F0} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
                  O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
                  O23 - Service: Avira AntiVir Planificateur (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
                  O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
                  O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe
                  O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                  O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
                  O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
                  O23 - Service: Boonty Games - Unknown owner - C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe (file missing)
                  O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\system32\drivers\CDAC11BA.EXE
                  O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - c:\APPS\Powercinema\Kernel\TV\CLCapSvc.exe
                  O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - c:\APPS\Powercinema\Kernel\TV\CLSched.exe
                  O23 - Service: CyberLink Media Library Service - Cyberlink - C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe
                  O23 - Service: EPSON V3 Service4(01) (EPSON_PM_RPCV4_01) - SEIKO EPSON CORPORATION - C:\Documents and Settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S40RP7.EXE
                  O23 - Service: Generic Service for HID Keyboard Input Collections (GenericHidService) - Unknown owner - c:\APPS\HIDSERVICE\HIDSERVICE.exe
                  O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
                  O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
                  O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
                  O23 - Service: Logitech Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\fichiers communs\logitech\lvmvfm\LVPrcSrv.exe
                  O23 - Service: MysqlInventime - Unknown owner - c:\mysql\bin\mysqld-nt.exe
                  O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe
                  O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software - C:\WINDOWS\System32\TuneUpDefragService.exe
                  O23 - Service: TuneUp Program Statistics Service (TuneUp.ProgramStatisticsSvc) - TuneUp Software - C:\WINDOWS\System32\TUProgSt.exe
                  0
                  1. Contributeur sécurité
                    Bonjour

                    Il n'y a pas que navipromo qui donne des pubs.

                    • Télécharge Random's System Information Tool (RSIT) de Random / Random et sauvegarde-le sur ton Bureau,

                    -> http://images.malwareremoval.com/random/RSIT.exe

                    • Double-clique sur RSIT.exe pour lancer le programme,
                    • Clique sur continuer sur l'écran Disclaimer,
                    • Si l'outil HijackThis (version à jour) n'est pas présent ou non détecté sur l'ordinateur, RSIT le téléchargera et tu devras accepter la licence.
                    • Lorsque l'analyse sera terminée, deux fichiers texte s'ouvriront. Poste le contenu de log.txt (<<qui sera affiché)
                    ainsi que de info.txt (<<qui sera réduit dans la Barre des Tâches).

                    Tuto si besoin : https://forum.pcastuces.com/randoms_system_information_tool_rsit-f31s31.htm
                    0