Virus system security

Bonjour,

j'ai trouvé des messages qui présentaient des problèmes similaires au mien, j'ai depuis quelques jours un virus qui se présente par l'ouverture d'une fenetre security system et qui bloque tout mon ordinateur; je n'arrive plus à ouvrir de logiciel ni à aller sur internet.
J'ai vu qu'il fallair télécharger RSIT ce que j'ai fait et voici les messages qui s'affichent:

Logfile of random's system information tool 1.06 (written by random/random)
Run by Olive at 2009-06-20 16:41:37
Microsoft® Windows Vista™ Édition Familiale Premium Service Pack 1
System drive C: has 196 GB (67%) free of 293 GB
Total RAM: 3070 MB (67% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 16:42:24, on 20/06/2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18248)
Boot mode: Normal

Running processes:
C:\Windows\Explorer.EXE
C:\Users\Olive\AppData\Roaming\eoRezo\SoftwareUpdate\SoftwareUpdateHP.exe
C:\Program Files\Apoint2K\ApMsgFwd.exe
C:\ProgramData\13268674\13268674.exe
C:\Users\Olive\Documents\Desktop\RSIT.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\trend micro\Olive.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/...
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://y.lo.st
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/...
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/...
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,First Home Page = http://y.lo.st
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\Program Files\OrangeHSS\SearchURLHook\SearchPageURL.dll
O1 - Hosts: ::1 localhost
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: Windows Live Family Safety Browser Helper - {4f3ed5cd-0726-42a9-87f5-d13f3d2976ac} - C:\Program Files\Windows Live\Family Safety\fssbho.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - (no file)
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
O2 - BHO: EoBHO - {C7B76B90-3455-4AE6-A752-EAC4D19689E5} - C:\Program Files\EoRezo\EoAdv\EoRezoBHO.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - (no file)
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [OnScreenDisplay] C:\Program Files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exe
O4 - HKLM\..\Run: [UCam_Menu] "C:\Program Files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\YouCam" update "Software\CyberLink\YouCam\1.0"
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [HP Health Check Scheduler] [ProgramFilesFolder]Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
O4 - HKLM\..\Run: [WAWifiMessage] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\Orange\AntivirusFirewall\Common\FSM32.EXE" /splash
O4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\Orange\AntivirusFirewall\FSGUI\TNBUtil.exe" /CHECKALL /WAITFORSW
O4 - HKLM\..\Run: [EoEngine] "C:\Program Files\EoRezo\EoEngine.exe"
O4 - HKLM\..\Run: [ORAHSSSessionManager] C:\Program Files\OrangeHSS\SessionManager\SessionManager.exe
O4 - HKLM\..\Run: [fssui] "C:\Program Files\Windows Live\Family Safety\fsui.exe" -autorun
O4 - HKLM\..\Run: [Windows UDP Control Center] msnmsgrss.exe
O4 - HKLM\..\Run: [sysldtray] c:\windows\ld09.exe
O4 - HKLM\..\Run: [pp] c:\windows\pp10.exe
O4 - HKLM\..\Run: [sysfbtray] c:\windows\freddy46.exe
O4 - HKLM\..\Run: [19462744] C:\ProgramData\19462744\19462744.exe
O4 - HKLM\..\Run: [13268674] C:\ProgramData\13268674\13268674.exe
O4 - HKLM\..\Run: [MRT] "C:\Windows\system32\MRT.exe" /R
O4 - HKLM\..\RunOnce: [SoftwareHelper] C:\Users\Olive\AppData\Roaming\eoRezo\SoftwareUpdate\SoftwareUpdateHP.exe -runonce
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
O4 - HKCU\..\Run: [HPAdvisor] C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe autoRun
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
O4 - Startup: Outil de notification Live Search.lnk = C:\Users\Olive\AppData\Roaming\Microsoft\Live Search\Notification-LiveSearch.exe
O4 - Global Startup: BTTray.lnk = ?
O8 - Extra context menu item: &Recherche AOL Toolbar - c:\program files\aol\aol toolbar 5.0\resources\fr-fr\local\search.html
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Envoyer au périphérique &Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O8 - Extra context menu item: Envoyer l'&image au périphérique Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O13 - Gopher Prefix:
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O20 - AppInit_DLLs: C:\Windows\System32\dsdmo32.dll
O23 - Service: Com4Qlb - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4Qlb.exe
O23 - Service: FSGKHS (F-Secure Gatekeeper Handler Starter) - F-Secure Corporation - C:\Program Files\Orange\AntivirusFirewall\Anti-Virus\fsgk32st.exe
O23 - Service: F-Secure Automatic Update Agent (FSAUA) - F-Secure Corporation - C:\Program Files\Orange\AntivirusFirewall\FSAUA\program\fsaua.exe
O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\Orange\AntivirusFirewall\FWES\Program\fsdfwd.exe
O23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Program Files\Orange\AntivirusFirewall\Common\FSMA32.EXE
O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom SA - C:\PROGRA~1\COMMON~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files\HP Games\My HP Game Console\GameConsoleService.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: QuickPlay Background Capture Service (QBCS) (QPCapSvc) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\QPCapSvc.exe
O23 - Service: QuickPlay Task Scheduler (QTS) (QPSched) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\QPSched.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

--
End of file - 12583 bytes

======Scheduled tasks folder======

C:\Windows\tasks\Google Software Updater.job
C:\Windows\tasks\User_Feed_Synchronization-{EACA1F9D-7DA9-463A-A478-B21C79F75452}.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
Aide pour le lien d'Adobe PDF Reader - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2006-10-23 62080]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{22BF413B-C6D2-4d91-82A9-A0F997BA588C}]
Skype add-on (mastermind) - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2008-11-18 1082880]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4f3ed5cd-0726-42a9-87f5-d13f3d2976ac}]
Windows Live Family Safety Browser Helper Class - C:\Program Files\Windows Live\Family Safety\fssbho.dll [2009-02-06 61808]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{602ADB0E-4AFF-4217-8AA1-95DAC4DFA408}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6EBF7485-159F-4bff-A14F-B9E3AAC4465B}]
Search Helper - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll [2009-05-19 137600]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
SSVHelper Class - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll [2007-07-12 501136]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7C554162-8CB7-45A4-B8F4-8EA1C75885F9}]
AOL Toolbar Launcher - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll [2007-07-30 1086816]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Programme d'aide de l'Assistant de connexion Windows Live - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-01-22 408448]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll [2009-06-09 259696]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
Google Toolbar Notifier BHO - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll [2009-03-24 668656]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C7B76B90-3455-4AE6-A752-EAC4D19689E5}]
EoBHO Class - C:\Program Files\EoRezo\EoAdv\EoRezoBHO.dll [2008-11-18 42792]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C84D72FE-E17D-4195-BB24-76C02E2E7C4E}]
Google Dictionary Compression sdch - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll [2009-04-24 470512]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E15A8DC0-8516-42A1-81EA-DC94EC1ACF10}]
Windows Live Toolbar Helper - C:\Program Files\Windows Live\Toolbar\wltcore.dll [2009-02-06 1068904]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA}
{DE9C389F-3316-41A7-809B-AA305ED9D922} - AOL Toolbar - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll [2007-07-30 1086816]
{21FA44EF-376D-4D53-9B0F-8A89D3229068} - &Windows Live Toolbar - C:\Program Files\Windows Live\Toolbar\wltcore.dll [2009-02-06 1068904]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll [2009-06-09 259696]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"NvSvc"=C:\Windows\system32\nvsvc.dll [2007-09-19 86016]
"NvCplDaemon"=C:\Windows\system32\NvCpl.dll [2007-09-19 8497696]
"NvMediaCenter"=C:\Windows\system32\NvMcTray.dll [2007-09-19 81920]
"Apoint"=C:\Program Files\Apoint2K\Apoint.exe [2007-03-11 159744]
"IAAnotif"=C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe [2007-07-25 174616]
"QPService"=C:\Program Files\HP\QuickPlay\QPService.exe [2007-12-19 468264]
"QlbCtrl"=C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe [2007-09-19 202032]
"OnScreenDisplay"=C:\Program Files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exe [2007-09-04 554320]
"UCam_Menu"=C:\Program Files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe [2007-08-16 218408]
"Windows Defender"=C:\Program Files\Windows Defender\MSASCui.exe [2008-01-21 1008184]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe [2007-05-11 40048]
"HP Health Check Scheduler"=[ProgramFilesFolder]Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe []
"HP Software Update"=C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe [2007-05-08 54840]
"hpWirelessAssistant"=C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe [2007-09-13 480560]
"WAWifiMessage"=C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe [2007-01-08 311296]
"SunJavaUpdateSched"=C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe [2007-07-12 132496]
"F-Secure Manager"=C:\Program Files\Orange\AntivirusFirewall\Common\FSM32.EXE [2008-04-23 182936]
"F-Secure TNB"=C:\Program Files\Orange\AntivirusFirewall\FSGUI\TNBUtil.exe [2008-04-23 744032]
"EoEngine"=C:\Program Files\EoRezo\EoEngine.exe [2009-02-23 472872]
"ORAHSSSessionManager"=C:\Program Files\OrangeHSS\SessionManager\SessionManager.exe [2007-12-12 107248]
"fssui"=C:\Program Files\Windows Live\Family Safety\fsui.exe [2009-02-06 454000]
"Windows UDP Control Center"=msnmsgrss.exe []
"sysldtray"=c:\windows\ld09.exe []
"pp"=c:\windows\pp10.exe []
"sysfbtray"=c:\windows\freddy46.exe []
"19462744"=C:\ProgramData\19462744\19462744.exe []
"13268674"=C:\ProgramData\13268674\13268674.exe [2009-06-14 369213]
"MRT"=C:\Windows\system32\MRT.exe [2009-06-01 23635392]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"SoftwareHelper"=C:\Users\Olive\AppData\Roaming\eoRezo\SoftwareUpdate\SoftwareUpdateHP.exe [2008-12-09 368224]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2008-01-21 1233920]
"LightScribe Control Panel"=C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe [2007-08-23 455968]
"HPAdvisor"=C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe [2007-10-01 1783136]
"msnmsgr"=C:\Program Files\Windows Live\Messenger\msnmsgr.exe [2009-02-06 3885408]
"Skype"=C:\Program Files\Skype\Phone\Skype.exe [2008-11-18 21633320]
"swg"=C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2009-01-25 39408]
"ehTray.exe"=C:\Windows\ehome\ehTray.exe [2008-01-21 125952]
"WMPNSCFG"=C:\Program Files\Windows Media Player\WMPNSCFG.exe [2008-01-21 202240]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
BTTray.lnk - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe

C:\Users\Olive\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
Outil de notification Live Search.lnk - C:\Users\Olive\AppData\Roaming\Microsoft\Live Search\Notification-LiveSearch.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLS"="C:\Windows\System32\dsdmo32.dll"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableUIADesktopToggle"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\Program Files\OrangeHSS\Connectivity\ConnectivityManager.exe"="C:\Program Files\OrangeHSS\Connectivity\ConnectivityManager.exe:*:enabled:CSS"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{9c5cc229-5ceb-11de-a75f-002186076d4b}]
shell\AutoRun\command - ReCycLEr\S-1-5-21-1482276501-1663491937-6831267430-1013\svchost.exe
shell\OpEN\command - ReCycLEr\S-1-5-21-1482276501-1663491937-6831267430-1013\svchost.exe

======List of files/folders created in the last 1 months======

2009-06-20 16:41:38 ----D---- C:\Program Files\trend micro
2009-06-20 16:41:37 ----D---- C:\rsit
2009-06-19 17:23:00 ----A---- C:\Windows\system32\infocardapi.dll
2009-06-19 17:22:59 ----A---- C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll
2009-06-19 17:22:56 ----A---- C:\Windows\system32\icardagt.exe
2009-06-19 17:22:55 ----A---- C:\Windows\system32\PresentationHostProxy.dll
2009-06-19 17:22:55 ----A---- C:\Windows\system32\icardres.dll
2009-06-19 17:22:51 ----A---- C:\Windows\system32\PresentationNative_v0300.dll
2009-06-19 17:22:41 ----A---- C:\Windows\system32\PresentationHost.exe
2009-06-19 17:15:42 ----A---- C:\Windows\system32\dfshim.dll
2009-06-19 17:15:35 ----A---- C:\Windows\system32\mscoree.dll
2009-06-19 17:15:33 ----A---- C:\Windows\system32\netfxperf.dll
2009-06-19 17:15:08 ----A---- C:\Windows\system32\mscorier.dll
2009-06-19 17:14:51 ----A---- C:\Windows\system32\mscories.dll
2009-06-19 17:14:24 ----A---- C:\Windows\system32\MRT.INI
2009-06-14 17:52:08 ----D---- C:\ProgramData\13268674
2009-06-14 17:29:07 ----D---- C:\ProgramData\19462744
2009-06-11 12:20:50 ----A---- C:\Windows\system32\localspl.dll
2009-06-11 12:20:47 ----A---- C:\Windows\system32\rpcrt4.dll
2009-06-11 12:20:27 ----A---- C:\Windows\system32\mshtml.dll
2009-06-11 12:20:18 ----A---- C:\Windows\system32\ieframe.dll
2009-06-11 12:20:14 ----A---- C:\Windows\system32\urlmon.dll
2009-06-11 12:20:05 ----A---- C:\Windows\system32\wininet.dll
2009-06-11 12:20:02 ----A---- C:\Windows\system32\iertutil.dll
2009-06-11 12:20:00 ----A---- C:\Windows\system32\msfeeds.dll
2009-06-11 12:20:00 ----A---- C:\Windows\system32\iedkcs32.dll
2009-06-11 12:19:58 ----A---- C:\Windows\system32\occache.dll
2009-06-11 12:19:58 ----A---- C:\Windows\system32\ieaksie.dll
2009-06-11 12:19:55 ----A---- C:\Windows\system32\ieUnatt.exe
2009-06-11 12:19:52 ----A---- C:\Windows\system32\mstime.dll
2009-06-11 12:19:52 ----A---- C:\Windows\system32\jsproxy.dll
2009-06-11 12:19:52 ----A---- C:\Windows\system32\ieencode.dll

======List of files/folders modified in the last 1 months======

2009-06-20 16:42:20 ----D---- C:\Windows\Temp
2009-06-20 16:42:11 ----D---- C:\Windows\Prefetch
2009-06-20 16:42:01 ----D---- C:\Windows\Tasks
2009-06-20 16:41:38 ----RD---- C:\Program Files
2009-06-20 13:28:34 ----SHD---- C:\System Volume Information
2009-06-20 12:58:51 ----D---- C:\Windows\rescache
2009-06-20 12:45:14 ----D---- C:\ProgramData\Google Updater
2009-06-20 12:15:44 ----D---- C:\Users\Olive\AppData\Roaming\EoRezo
2009-06-19 18:40:36 ----D---- C:\Windows\Microsoft.NET
2009-06-19 18:40:28 ----RSD---- C:\Windows\assembly
2009-06-19 18:21:12 ----D---- C:\Windows\System32
2009-06-19 18:21:12 ----A---- C:\Windows\system32\PerfStringBackup.INI
2009-06-19 18:21:11 ----D---- C:\Windows\inf
2009-06-19 18:10:29 ----D---- C:\Windows\system32\fr-FR
2009-06-19 18:10:21 ----D---- C:\Windows\system32\XPSViewer
2009-06-19 18:10:21 ----D---- C:\Windows\system32\en-US
2009-06-19 18:10:20 ----D---- C:\Windows\system32\wbem
2009-06-19 18:09:19 ----D---- C:\Windows\winsxs
2009-06-19 17:42:59 ----D---- C:\Windows
2009-06-19 17:42:56 ----SHD---- C:\Windows\Installer
2009-06-19 17:41:56 ----D---- C:\ProgramData\Microsoft Help
2009-06-19 17:41:05 ----RSD---- C:\Windows\Fonts
2009-06-19 17:40:52 ----D---- C:\Program Files\Common Files\microsoft shared
2009-06-19 17:38:54 ----A---- C:\Windows\win.ini
2009-06-19 17:37:08 ----D---- C:\Windows\system32\catroot2
2009-06-19 17:37:08 ----D---- C:\Windows\system32\catroot
2009-06-19 17:12:40 ----D---- C:\Windows\Debug
2009-06-15 00:02:46 ----D---- C:\Users\Olive\AppData\Roaming\skypePM
2009-06-14 19:05:47 ----D---- C:\Users\Olive\AppData\Roaming\LimeWire
2009-06-14 17:52:08 ----HD---- C:\ProgramData
2009-06-12 09:08:13 ----D---- C:\Program Files\Internet Explorer
2009-06-12 09:08:11 ----D---- C:\Windows\system32\Macromed
2009-06-12 00:28:58 ----D---- C:\Program Files\Microsoft Works
2009-06-11 08:10:00 ----SD---- C:\Windows\Downloaded Program Files
2009-06-07 09:09:58 ----D---- C:\Windows\system32\Tasks
2009-06-04 00:21:50 ----D---- C:\Users\Olive\AppData\Roaming\dvdcss
2009-06-01 09:51:14 ----A---- C:\Windows\system32\mrt.exe
2009-05-22 20:25:25 ----SD---- C:\Users\Olive\AppData\Roaming\Microsoft

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 F-Secure HIPS;F-Secure HIPS; \??\C:\Program Files\Orange\AntivirusFirewall\HIPS\fshs.sys [2008-12-23 41184]
R1 FSES;F-Secure Email Scanning Driver; C:\Windows\System32\drivers\fses.sys [2008-04-23 34752]
R1 FSFW;F-Secure Firewall Driver; C:\Windows\System32\drivers\fsdfw.sys [2008-12-23 60064]
R1 fsvista;F-Secure Vista Support Driver; \??\C:\Program Files\Orange\AntivirusFirewall\Anti-Virus\minifilter\fsvista.sys [2008-04-23 12896]
R2 fssfltr;FssFltr; C:\Windows\system32\DRIVERS\fssfltr.sys [2008-12-08 55264]
R2 mdmxsdk;mdmxsdk; C:\Windows\system32\DRIVERS\mdmxsdk.sys [2006-06-19 12672]
R2 rimmptsk;rimmptsk; C:\Windows\system32\DRIVERS\rimmptsk.sys [2007-08-08 45568]
R2 rimsptsk;rimsptsk; C:\Windows\system32\DRIVERS\rimsptsk.sys [2007-07-30 43008]
R2 rismxdp;Ricoh xD-Picture Card Driver; C:\Windows\system32\DRIVERS\rixdptsk.sys [2007-07-30 38400]
R2 XAudio;XAudio; C:\Windows\system32\DRIVERS\xaudio.sys [2007-07-10 8704]
R3 ApfiltrService;Alps Pointing-device Filter Driver; C:\Windows\system32\DRIVERS\Apfiltr.sys [2007-04-18 141312]
R3 BthEnum;Service d'énumérateur Bluetooth; C:\Windows\system32\DRIVERS\BthEnum.sys [2008-01-21 19456]
R3 BthPan;Périphérique Bluetooth (réseau personnel); C:\Windows\system32\DRIVERS\bthpan.sys [2008-01-21 92160]
R3 BTHUSB;Pilote USB radio Bluetooth; C:\Windows\System32\Drivers\BTHUSB.sys [2008-04-29 29184]
R3 btwaudio;Périphérique audio Bluetooth; C:\Windows\system32\drivers\btwaudio.sys [2007-09-18 80424]
R3 btwavdt;Bluetooth AVDT; C:\Windows\system32\drivers\btwavdt.sys [2007-09-18 80936]
R3 btwrchid;btwrchid; C:\Windows\system32\DRIVERS\btwrchid.sys [2007-09-18 16168]
R3 CmBatt;Pilote pour Batterie à méthode de contrôle ACPI Microsoft; C:\Windows\system32\DRIVERS\CmBatt.sys [2008-01-21 14208]
R3 CnxtHdAudService;Conexant UAA Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\CHDRT32.sys [2008-03-04 188416]
R3 F-Secure Gatekeeper;F-Secure Gatekeeper; \??\C:\Program Files\Orange\AntivirusFirewall\Anti-Virus\minifilter\fsgk.sys [2008-04-23 62048]
R3 HpqKbFiltr;HpqKbFilter Driver; C:\Windows\system32\DRIVERS\HpqKbFiltr.sys [2007-06-18 16768]
R3 HpqRemHid;HP Remote Control HID Device; C:\Windows\system32\DRIVERS\HpqRemHid.sys [2007-07-11 7168]
R3 HSF_DPV;HSF_DPV; C:\Windows\system32\DRIVERS\HSX_DPV.sys [2007-06-20 984064]
R3 HSXHWAZL;HSXHWAZL; C:\Windows\system32\DRIVERS\HSXHWAZL.sys [2007-06-20 208896]
R3 NETw4v32;Pilote de carte Intel(R) Wireless WiFi Link pour Windows Vista 32 bits; C:\Windows\system32\DRIVERS\NETw4v32.sys [2007-06-28 2222080]
R3 nvlddmkm;nvlddmkm; C:\Windows\system32\DRIVERS\nvlddmkm.sys [2007-09-19 7626400]
R3 RFCOMM;Périphérique Bluetooth (TDI protocole RFCOMM); C:\Windows\system32\DRIVERS\rfcomm.sys [2008-01-21 49664]
R3 sdbus;sdbus; C:\Windows\system32\DRIVERS\sdbus.sys [2008-01-21 88576]
R3 usbvideo;Périphérique vidéo USB (WDM); C:\Windows\System32\Drivers\usbvideo.sys [2008-01-21 134016]
R3 winachsf;winachsf; C:\Windows\system32\DRIVERS\HSX_CNXT.sys [2007-06-20 660480]
R3 WmiAcpi;Microsoft Windows Management Interface for ACPI; C:\Windows\system32\DRIVERS\wmiacpi.sys [2008-01-21 11264]
R3 yukonwlh;NDIS6.0 Miniport Driver for Marvell Yukon Ethernet Controller; C:\Windows\system32\DRIVERS\yk60x86.sys [2007-08-15 278528]
S3 BCM43XV;Broadcom Extensible 802.11 Network Adapter Driver; C:\Windows\system32\DRIVERS\bcmwl6.sys [2006-11-02 464384]
S3 BTHPORT;Pilote de port Bluetooth; C:\Windows\System32\Drivers\BTHport.sys [2008-04-29 220160]
S3 drmkaud;Filtre de décodeur DRM (Noyau Microsoft); C:\Windows\system32\drivers\drmkaud.sys [2008-01-21 5632]
S3 HdAudAddService;Microsoft UAA Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\CHDART.sys [2007-10-01 183352]
S3 HSFHWAZL;HSFHWAZL; C:\Windows\system32\DRIVERS\VSTAZL3.SYS [2008-01-21 200704]
S3 MSKSSRV;Proxy de service de répartition Microsoft; C:\Windows\system32\drivers\MSKSSRV.sys [2008-01-21 8192]
S3 MSPCLOCK;Proxy d'horloge de répartition Microsoft; C:\Windows\system32\drivers\MSPCLOCK.sys [2008-01-21 5888]
S3 MSPQM;Proxy de gestion de qualité de répartition Microsoft; C:\Windows\system32\drivers\MSPQM.sys [2008-01-21 5504]
S3 MSTEE;Convertisseur en T/site-à-site de répartition Microsoft; C:\Windows\system32\drivers\MSTEE.sys [2008-01-21 6016]
S3 NVENETFD;NVIDIA nForce Networking Controller Driver; C:\Windows\system32\DRIVERS\nvm60x32.sys [2006-11-02 429056]
S3 PCAMp50;PCAMp50 NDIS Protocol Driver; C:\Windows\System32\Drivers\PCAMp50.sys [2006-11-28 28224]
S3 PCASp50;PCASp50 NDIS Protocol Driver; C:\Windows\System32\Drivers\PCASp50.sys [2006-11-28 27072]
S3 SymIM;Symantec Network Security Intermediate Filter Service; C:\Windows\system32\DRIVERS\SymIM.sys []
S3 SymIMMP;SymIMMP; C:\Windows\system32\DRIVERS\SymIM.sys []
S3 WpdUsb;WpdUsb; C:\Windows\system32\DRIVERS\wpdusb.sys [2008-01-21 39936]
S3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [2008-01-21 83328]
S4 ErrDev;Microsoft Hardware Error Device Driver; C:\Windows\system32\drivers\errdev.sys [2008-01-21 6656]
S4 F-Secure Filter;F-Secure File System Filter; \??\C:\Program Files\Orange\AntivirusFirewall\Anti-Virus\Win2K\FSfilter.sys [2008-04-23 39776]
S4 F-Secure Recognizer;F-Secure File System Recognizer; \??\C:\Program Files\Orange\AntivirusFirewall\Anti-Virus\Win2K\FSrec.sys [2008-04-23 25184]
S4 MegaSR;MegaSR; C:\Windows\system32\drivers\megasr.sys [2008-01-21 386616]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 BthServ;@%SystemRoot%\System32\bthserv.dll,-101; C:\Windows\system32\svchost.exe [2008-01-21 21504]
R2 F-Secure Gatekeeper Handler Starter;FSGKHS; C:\Program Files\Orange\AntivirusFirewall\Anti-Virus\fsgk32st.exe [2008-04-23 47800]
R2 FSMA;F-Secure Management Agent; C:\Program Files\Orange\AntivirusFirewall\Common\FSMA32.EXE [2008-04-23 113304]
R2 fsssvc;Windows Live Contrôle parental; C:\Program Files\Windows Live\Family Safety\fsssvc.exe [2009-02-06 533360]
R2 FTRTSVC;France Telecom Routing Table Service; C:\PROGRA~1\COMMON~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe [2007-12-11 65536]
R2 gusvc;Google Software Updater; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-03-24 183280]
R2 HP Health Check Service;HP Health Check Service; c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe [2007-09-19 65536]
R2 hpqwmiex;hpqwmiex; C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe [2006-05-02 135168]
R2 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [2007-08-23 79136]
R2 QPCapSvc;QuickPlay Background Capture Service (QBCS); C:\Program Files\HP\QuickPlay\Kernel\TV\QPCapSvc.exe [2007-12-19 271760]
R2 QPSched;QuickPlay Task Scheduler (QTS); C:\Program Files\HP\QuickPlay\Kernel\TV\QPSched.exe [2007-12-19 112016]
R2 RichVideo;Cyberlink RichVideo Service(CRVS); C:\Program Files\CyberLink\Shared Files\RichVideo.exe [2007-01-09 272024]
R2 SeaPort;SeaPort; C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe [2009-05-19 240512]
R2 XAudioService;XAudioService; C:\Windows\system32\DRIVERS\xaudio.exe [2007-07-10 386560]
R3 FSAUA;F-Secure Automatic Update Agent; C:\Program Files\Orange\AntivirusFirewall\FSAUA\program\fsaua.exe [2008-04-23 461408]
R3 FSDFWD;F-Secure Anti-Virus Firewall Daemon; C:\Program Files\Orange\AntivirusFirewall\FWES\Program\fsdfwd.exe [2008-04-23 453216]
S3 Com4Qlb;Com4Qlb; C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4Qlb.exe [2007-03-05 110592]
S3 GameConsoleService;GameConsoleService; C:\Program Files\HP Games\My HP Game Console\GameConsoleService.exe [2007-07-24 181800]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2008-11-04 441712]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]

-----------------EOF-----------------

et

info.txt logfile of random's system information tool 1.06 2009-06-20 16:42:26

======Uninstall list======

-->"C:\Program Files\HP Games\Bejeweled 2 Deluxe\Uninstall.exe"
-->"C:\Program Files\HP Games\Blasterball 2 Revolution\Uninstall.exe"
-->"C:\Program Files\HP Games\Blasterball 3\Uninstall.exe"
-->"C:\Program Files\HP Games\Bricks of Egypt\Uninstall.exe"
-->"C:\Program Files\HP Games\Chicken Invaders 3 - Revenge of the Yolk\Uninstall.exe"
-->"C:\Program Files\HP Games\Chuzzle Deluxe\Uninstall.exe"
-->"C:\Program Files\HP Games\Crystal Maze\Uninstall.exe"
-->"C:\Program Files\HP Games\Diner Dash 2 Restaurant Rescue\Uninstall.exe"
-->"C:\Program Files\HP Games\Diner Dash\Uninstall.exe"
-->"C:\Program Files\HP Games\FATE\Uninstall.exe"
-->"C:\Program Files\HP Games\Fish Tycoon\Uninstall.exe"
-->"C:\Program Files\HP Games\Gem Shop\Uninstall.exe"
-->"C:\Program Files\HP Games\Insaniquarium Deluxe\Uninstall.exe"
-->"C:\Program Files\HP Games\Jewel Quest\Uninstall.exe"
-->"C:\Program Files\HP Games\Magic Academy\Uninstall.exe"
-->"C:\Program Files\HP Games\Mah Jong Quest\Uninstall.exe"
-->"C:\Program Files\HP Games\My HP Game Console\Uninstall.exe"
-->"C:\Program Files\HP Games\Ocean Express\Uninstall.exe"
-->"C:\Program Files\HP Games\Peggle\Uninstall.exe"
-->"C:\Program Files\HP Games\Penguins!\Uninstall.exe"
-->"C:\Program Files\HP Games\Polar Bowler\Uninstall.exe"
-->"C:\Program Files\HP Games\Polar Golfer Pineapple Cup\Uninstall.exe"
-->"C:\Program Files\HP Games\Polar Golfer\Uninstall.exe"
-->"C:\Program Files\HP Games\Puzzle Express\Uninstall.exe"
-->"C:\Program Files\HP Games\Shooting Stars Pool\Uninstall.exe"
-->"C:\Program Files\HP Games\Slingo Deluxe\Uninstall.exe"
-->"C:\Program Files\HP Games\Sudoku Quest\Uninstall.exe"
-->"C:\Program Files\HP Games\Super Granny\Uninstall.exe"
-->"C:\Program Files\HP Games\Tradewinds\Uninstall.exe"
-->"C:\Program Files\HP Games\Virtual Villagers - A New Home\Uninstall.exe"
-->"C:\Program Files\HP Games\Zuma Deluxe\Uninstall.exe"
-->"C:\Program Files\Orange\AntivirusFirewall\Uninstall\fsuninst.exe" /UninstRegKey:"F-Secure Anti-Spyware Scanner"
-->"C:\Program Files\Orange\AntivirusFirewall\Uninstall\fsuninst.exe" /UninstRegKey:"F-Secure Anti-Spyware"
-->"C:\Program Files\Orange\AntivirusFirewall\Uninstall\fsuninst.exe" /UninstRegKey:"F-Secure Anti-Virus Client Security Installer"
-->"C:\Program Files\Orange\AntivirusFirewall\Uninstall\fsuninst.exe" /UninstRegKey:"F-Secure Anti-Virus"
-->"C:\Program Files\Orange\AntivirusFirewall\Uninstall\fsuninst.exe" /UninstRegKey:"F-Secure Automatic Update Agent"
-->"C:\Program Files\Orange\AntivirusFirewall\Uninstall\fsuninst.exe" /UninstRegKey:"F-Secure DAAS"
-->"C:\Program Files\Orange\AntivirusFirewall\Uninstall\fsuninst.exe" /UninstRegKey:"F-Secure Diagnostics"
-->"C:\Program Files\Orange\AntivirusFirewall\Uninstall\fsuninst.exe" /UninstRegKey:"F-Secure E-mail Scanning"
-->"C:\Program Files\Orange\AntivirusFirewall\Uninstall\fsuninst.exe" /UninstRegKey:"F-Secure FWES"
-->"C:\Program Files\Orange\AntivirusFirewall\Uninstall\fsuninst.exe" /UninstRegKey:"F-Secure GateKeeper Interface"
-->"C:\Program Files\Orange\AntivirusFirewall\Uninstall\fsuninst.exe" /UninstRegKey:"F-Secure Gemini"
-->"C:\Program Files\Orange\AntivirusFirewall\Uninstall\fsuninst.exe" /UninstRegKey:"F-Secure GUI"
-->"C:\Program Files\Orange\AntivirusFirewall\Uninstall\fsuninst.exe" /UninstRegKey:"F-Secure Help"
-->"C:\Program Files\Orange\AntivirusFirewall\Uninstall\fsuninst.exe" /UninstRegKey:"F-Secure HIPS"
-->"C:\Program Files\Orange\AntivirusFirewall\Uninstall\fsuninst.exe" /UninstRegKey:"F-Secure Internet Shield"
-->"C:\Program Files\Orange\AntivirusFirewall\Uninstall\fsuninst.exe" /UninstRegKey:"F-Secure Localization API"
-->"C:\Program Files\Orange\AntivirusFirewall\Uninstall\fsuninst.exe" /UninstRegKey:"F-Secure Management Agent"
-->"C:\Program Files\Orange\AntivirusFirewall\Uninstall\fsuninst.exe" /UninstRegKey:"F-Secure Pegasus Engine"
-->"C:\Program Files\Orange\AntivirusFirewall\Uninstall\fsuninst.exe" /UninstRegKey:"F-Secure Protocol Scanner"
-->"C:\Program Files\Orange\AntivirusFirewall\Uninstall\fsuninst.exe" /UninstRegKey:"F-Secure Spam Control"
-->"C:\Program Files\Orange\AntivirusFirewall\Uninstall\fsuninst.exe" /UninstRegKey:"F-Secure Spam Scanner"
-->"C:\Program Files\Orange\AntivirusFirewall\Uninstall\fsuninst.exe" /UninstRegKey:"F-Secure TNB"
-->"C:\Program Files\Orange\AntivirusFirewall\Uninstall\fsuninst.exe" /UninstRegKey:"F-Secure Uninstall"
-->C:\Program Files\Conexant\SmartAudio\SETUP.EXE -U -ISmartAudio -SM=SMAUDIO.EXE,1801
Activation Assistant for the 2007 Microsoft Office suites-->"C:\ProgramData\{174892B1-CBE7-44F5-86FF-AB555EFD73A3}\Microsoft Office Activation Assistant.exe" REMOVE=TRUE MODIFY=FALSE
Adobe Flash Player 10 ActiveX-->C:\Windows\system32\Macromed\Flash\uninstall_activeX.exe
Adobe Reader 8.1.0 - Français-->MsiExec.exe /I{AC76BA86-7AD7-1036-7B44-A81000000003}
Adobe Shockwave Player-->MsiExec.exe /X{1BDC9633-895B-4842-BCB6-8FA1EC2A3C5A}
AIM 6-->C:\Program Files\AIM6\uninst.exe
AntiVirus Firewall-->"C:\Program Files\Orange\AntivirusFirewall\FSGUI\PostInstall.exe" /tUnInstall
AOL Toolbar 5.0-->"C:\Program Files\AOL\AOL Toolbar 5.0\uninstall.exe"
Assistant de connexion Windows Live-->MsiExec.exe /I{DCE8CD14-FBF5-4464-B9A4-E18E473546C7}
Choice Guard-->MsiExec.exe /I{8FFC5648-FAF8-43A3-BC8F-42BA1E275C4E}
Conexant HD Audio-->C:\Program Files\CONEXANT\CNXT_AUDIO_HDA\UIU32a.exe -U -IWiSVHez.INF
CyberLink YouCam-->"C:\Program Files\InstallShield Installation Information\{01FB4998-33C4-4431-85ED-079E3EEFE75D}\setup.exe" /z-uninstall
DivX Web Player-->C:\Program Files\DivX\DivXWebPlayerUninstall.exe /PLUGIN
DVD Suite-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}\setup.exe" -uninstall
EA Link-->C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\11\INTEL3~1\IDriver.exe /M{F5577101-33CC-4711-8235-3A95BCD49DB0} /l1036
eoEngine 9.1-->"C:\Program Files\EoRezo\unins000.exe"
FlightGear v1.0.0-->"C:\Program Files\FlightGear\unins000.exe"
Galerie de photos Windows Live-->MsiExec.exe /X{44E54A81-9D91-4AA1-9417-80AFF134F5FF}
Google Earth-->MsiExec.exe /I{1D14373E-7970-4F2F-A467-ACA4F0EA21E3}
Google Toolbar for Internet Explorer-->"C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarManager_9DE96A29E721D90A.exe" /uninstall
Google Toolbar for Internet Explorer-->MsiExec.exe /I{18455581-E099-4BA8-BC6B-F34B2F06600C}
Hauppauge MCE XP/Vista Software Encoder (2.0.25149)-->C:\PROGRA~1\WinTV\UNSftMCE.EXE C:\PROGRA~1\WinTV\softMCE.LOG
HDAUDIO Soft Data Fax Modem with SmartCP-->C:\Program Files\CONEXANT\CNXT_MODEM_HDA_HSF\UIU32m.exe -U -I*.INF
Hewlett-Packard Active Check-->MsiExec.exe /X{254C37AA-6B72-4300-84F6-98A82419187E}
Hewlett-Packard Asset Agent for Health Check-->MsiExec.exe /X{669D4A35-146B-4314-89F1-1AC3D7B88367}
HijackThis 2.0.2-->"C:\Program Files\trend micro\HijackThis.exe" /uninstall
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)-->C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall /qb+ REBOOTPROMPT=""
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)-->C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {A7EEA2F2-BFCD-4A54-A575-7B81A786E658} /qb+ REBOOTPROMPT=""
HP Customer Experience Enhancements-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{BD0E2B92-3814-46F0-893B-4612EA010C7E}\setup.exe" -l0x9 -removeonly
HP Doc Viewer-->MsiExec.exe /I{082702D5-5DD8-4600-BCE5-48B15174687F}
HP Easy Setup - Frontend-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{9885A11E-60E4-417C-B58B-8B31B21C0B8A}\setup.exe" -l0x9 -removeonly
HP Help and Support-->MsiExec.exe /X{31216452-5540-4C96-B754-94890A63D5AB}
HP Integrated Module with Bluetooth wireless technology 6.0.1.5500-->MsiExec.exe /X{03D1988F-469F-4843-8E6E-E5FE9D17889D}
HP Quick Launch Buttons 6.30 E1-->C:\Program Files\InstallShield Installation Information\{34D2AB40-150D-475D-AE32-BD23FB5EE355}\setup.exe -runfromtemp -l0x040c uninst
HP QuickPlay 3.6-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{45D707E9-F3C4-11D9-A373-0050BAE317E1}\Setup.exe" -uninstall
HP QuickTouch 1.00 C4-->MsiExec.exe /I{7DC4A410-9986-4329-9E5D-687B2C42CA39}
HP Total Care Advisor-->MsiExec.exe /X{b02df929-29a7-4fd2-9a70-81a644b635f7}
HP Update-->MsiExec.exe /X{D063F201-FAC4-4D5C-B10B-615058ADE5A7}
HP User Guides 0090-->MsiExec.exe /I{B53620C0-3A83-4F50-A7AB-175DB64C1CE3}
HP Wireless Assistant-->MsiExec.exe /I{CBAE4F50-9FC9-4557-AB36-9826DF3C103C}
Installation Windows Live-->C:\Program Files\Windows Live\Installer\wlarp.exe
Installation Windows Live-->MsiExec.exe /I{7370DF47-B4F9-4279-BFC3-3F09919F720D}
Java(TM) 6 Update 2-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160020}
Junk Mail filter update-->MsiExec.exe /I{4DE3E3D9-AE81-45DE-9195-3015F7B1DBF3}
LabelPrint-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{C59C179C-668D-49A9-B6EA-0121CCFC1243}\setup.exe" -uninstall
Les Sims™ Histoires de vie-->MsiExec.exe /I{2284D904-C138-4B58-93EC-5C362AB5130A}
LimeWire 4.18.8-->"C:\Program Files\LimeWire\uninstall.exe"
Marvell Miniport Driver-->C:\Program Files\Marvell\Miniport Driver\Uninst.exe
Microsoft .NET Framework 3.5 SP1-->c:\Windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setup.exe
Microsoft .NET Framework 3.5 SP1-->MsiExec.exe /I{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0015-040C-0000-0000000FF1CE} /uninstall {AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0016-040C-0000-0000000FF1CE} /uninstall {AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0018-040C-0000-0000000FF1CE} /uninstall {AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0019-040C-0000-0000000FF1CE} /uninstall {AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001A-040C-0000-0000000FF1CE} /uninstall {AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001B-040C-0000-0000000FF1CE} /uninstall {AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0044-040C-0000-0000000FF1CE} /uninstall {AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-006E-040C-0000-0000000FF1CE} /uninstall {B165D3C2-40AE-4D39-86F7-E5C87C4264C0}
Microsoft Office Access MUI (French) 2007-->MsiExec.exe /X{90120000-0015-040C-0000-0000000FF1CE}
Microsoft Office Excel MUI (French) 2007-->MsiExec.exe /X{90120000-0016-040C-0000-0000000FF1CE}
Microsoft Office InfoPath MUI (French) 2007-->MsiExec.exe /X{90120000-0044-040C-0000-0000000FF1CE}
Microsoft Office Live Add-in 1.3-->MsiExec.exe /I{57F0ED40-8F11-41AA-B926-4A66D0D1A9CC}
Microsoft Office Outlook Connector-->MsiExec.exe /I{95120000-0120-040C-0000-0000000FF1CE}
Microsoft Office Outlook MUI (French) 2007-->MsiExec.exe /X{90120000-001A-040C-0000-0000000FF1CE}
Microsoft Office PowerPoint MUI (French) 2007-->MsiExec.exe /X{90120000-0018-040C-0000-0000000FF1CE}
Microsoft Office PowerPoint Viewer 2007 (French)-->MsiExec.exe /X{95120000-00AF-040C-0000-0000000FF1CE}
Microsoft Office Professional Plus 2007-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE12\Office Setup Controller\setup.exe" /uninstall PROPLUS /dll OSETUP.DLL
Microsoft Office Professional Plus 2007-->MsiExec.exe /X{90120000-0011-0000-0000-0000000FF1CE}
Microsoft Office Proof (Arabic) 2007-->MsiExec.exe /X{90120000-001F-0401-0000-0000000FF1CE}
Microsoft Office Proof (Dutch) 2007-->MsiExec.exe /X{90120000-001F-0413-0000-0000000FF1CE}
Microsoft Office Proof (English) 2007-->MsiExec.exe /X{90120000-001F-0409-0000-0000000FF1CE}
Microsoft Office Proof (French) 2007-->MsiExec.exe /X{90120000-001F-040C-0000-0000000FF1CE}
Microsoft Office Proof (German) 2007-->MsiExec.exe /X{90120000-001F-0407-0000-0000000FF1CE}
Microsoft Office Proof (Spanish) 2007-->MsiExec.exe /X{90120000-001F-0C0A-0000-0000000FF1CE}
Microsoft Office Proofing (French) 2007-->MsiExec.exe /X{90120000-002C-040C-0000-0000000FF1CE}
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0401-0000-0000000FF1CE} /uninstall {14809F99-C601-4D4A-9391-F1E8FAA964C5}
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0407-0000-0000000FF1CE} /uninstall {A0516415-ED61-419A-981D-93596DA74165}
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0409-0000-0000000FF1CE} /uninstall {ABDDE972-355B-4AF1-89A8-DA50B7B5C045}
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-040C-0000-0000000FF1CE} /uninstall {F580DDD5-8D37-4998-968E-EBB76BB86787}
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0413-0000-0000000FF1CE} /uninstall {D66D5A44-E480-4BA4-B4F2-C554F6B30EBB}
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0C0A-0000-0000000FF1CE} /uninstall {187308AB-5FA7-4F14-9AB9-D290383A10D9}
Microsoft Office Publisher MUI (French) 2007-->MsiExec.exe /X{90120000-0019-040C-0000-0000000FF1CE}
Microsoft Office Shared MUI (French) 2007-->MsiExec.exe /X{90120000-006E-040C-0000-0000000FF1CE}
Microsoft Office Word MUI (French) 2007-->MsiExec.exe /X{90120000-001B-040C-0000-0000000FF1CE}
Microsoft Search Enhancement Pack-->MsiExec.exe /X{4CBA3D4C-8F51-4D60-B27E-F6B641C571E7}
Microsoft Silverlight-->MsiExec.exe /X{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
Microsoft SQL Server 2005 Compact Edition [ENU]-->MsiExec.exe /I{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}
Microsoft Sync Framework Runtime Native v1.0 (x86)-->MsiExec.exe /I{8A74E887-8F0F-4017-AF53-CBA42211AAA5}
Microsoft Sync Framework Services Native v1.0 (x86)-->MsiExec.exe /I{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}
Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
Microsoft Works-->MsiExec.exe /I{3B160861-7250-451E-B5EE-8B92BF30A710}
Module de compatibilité pour Microsoft Office System 2007-->MsiExec.exe /X{90120000-0020-040C-0000-0000000FF1CE}
MSVCRT-->MsiExec.exe /I{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}
MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
muvee autoProducer 6.1-->C:\Program Files\InstallShield Installation Information\{250E9609-E830-43EB-B379-DAB7546A2422}\muveesetup.exe -removeonly -runfromtemp
My HP Games-->"C:\Program Files\HP Games\Uninstall.exe"
NetWaiting-->C:\Program Files\InstallShield Installation Information\{3F92ABBB-6BBF-11D5-B229-002078017FBF}\setup.exe -runfromtemp -l0x040c -removeonly
NVIDIA Drivers-->C:\Windows\system32\NVUNINST.EXE UninstallGUI
Orange - Logiciels Internet-->C:\Program Files\OrangeHSS\installation\core\Installgui.exe -u
Outil de mise à jour Google-->"C:\Program Files\Google\Google Updater\GoogleUpdater.exe" -uninstall
Outil de téléchargement Windows Live-->MsiExec.exe /I{205C6BDD-7B73-42DE-8505-9A093F35A238}
Power2Go-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{40BF1E83-20EB-11D8-97C5-0009C5020658}\setup.exe" -uninstall
PowerDirector-->"C:\Program Files\InstallShield Installation Information\{CB099890-1D5F-11D5-9EA9-0050BAE317E1}\setup.exe" /z-uninstall
QuickPlay SlingPlayer 0.4.6-->"C:\Program Files\HP\QuickPlay\unins000.exe"
Ray-Ban Virtual Mirror-->C:\Program Files\RaybanMirror\app\Launcher.exe -u
RICOH R5C83x/84x Flash Media Controller Driver Ver.3.52.02-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{59F6A514-9813-47A3-948C-8A155460CC2A}\setup.exe" -l0x40c anything
SAMSUNG Mobile Modem Driver Set-->C:\Windows\system32\Samsung_USB_Drivers\3\SSCDUninstall.exe
Samsung Mobile phone USB driver Software-->C:\Windows\system32\Samsung_USB_Drivers\5\SSSDUninstall.exe
SAMSUNG Mobile USB Modem 1.0 Software-->C:\Windows\system32\Samsung_USB_Drivers\1\SS_Uninstall.exe
SAMSUNG Mobile USB Modem Software-->C:\Windows\system32\Samsung_USB_Drivers\2\SSM_Uninstall.exe
Samsung PC Studio 3 USB Driver Installer-->"C:\Program Files\InstallShield Installation Information\{EBA29752-DDD2-4B62-B2E3-9841F92A3E3A}\setup.exe" -runfromtemp -l0x040c -removeonly
Security Update for 2007 Microsoft Office System (KB969559)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {69F52148-9BF6-4CDC-BF76-103DEAF3DD08}
Security Update for 2007 Microsoft Office System (KB969679)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {C66E4A6C-6E07-4C63-8CCD-2493B5087C73}
Security Update for Microsoft Office Excel 2007 (KB969682)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {C03803BD-745A-46F8-8557-817DED578780}
Security Update for Microsoft Office PowerPoint 2007 (KB957789)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {7559E742-FF9F-4FAE-B279-008ED296CB4D}
Security Update for Microsoft Office system 2007 (KB969613)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {5ECEB317-CBE9-4E08-AB10-756CB6F0FB6C}
Security Update for Microsoft Office Word 2007 (KB969604)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {CF3D6499-709C-43D0-8908-BC5652656050}
Skype™ 3.8-->MsiExec.exe /X{5C82DAE5-6EB0-4374-9254-BE3319BA4E82}
SoftwareUpdate 1.0-->"C:\Users\Olive\AppData\Roaming\eoRezo\SoftwareUpdate\unins000.exe"
Touch Pad Driver-->C:\Program Files\Apoint2K\Uninstap.exe ADDREMOVE
Update for 2007 Microsoft Office System (KB967642)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {C444285D-5E4F-48A4-91DD-47AAAA68E92D}
Update for Microsoft Office Outlook 2007 (KB969907)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {74F98B24-AFBD-4800-9BD6-87D349B5C462}
Update for Outlook 2007 Junk Email Filter (kb970012)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {DC4A962B-9EC2-469C-BC9C-87312ADAEE81}
VC80CRTRedist - 8.0.50727.762-->MsiExec.exe /I{767CC44C-9BBC-438D-BAD3-FD4595DD148B}
Viewpoint Media Player-->C:\Program Files\Viewpoint\Viewpoint Experience Technology\mtsAxInstaller.exe /u
VLC media player 0.9.8a-->C:\Program Files\VideoLAN\VLC\uninstall.exe
Windows Live Call-->MsiExec.exe /I{82C7B308-0BDD-49D8-8EA5-9CD3A3F9DF41}
Windows Live Communications Platform-->MsiExec.exe /I{3B4E636E-9D65-4D67-BA61-189800823F52}
Windows Live Contrôle parental-->MsiExec.exe /X{D6A2DDE3-9D7C-412C-932A-756580D29919}
Windows Live Mail-->MsiExec.exe /I{63DC2DA0-2A6C-4C38-9249-B75395458657}
Windows Live Messenger-->MsiExec.exe /X{059C042E-796A-4ACC-A81A-ECC2010BB78C}
Windows Live Movie Maker Bêta-->MsiExec.exe /X{F874DF52-A31F-44C1-A606-EF40F1549261}
Windows Live Sync-->MsiExec.exe /X{9C5EB781-0D37-44B8-9A58-77B3E4BF5F5E}
Windows Live Toolbar-->MsiExec.exe /X{F7D27C70-90F5-49B9-B188-0A133C0CE353}
Windows Live Writer-->MsiExec.exe /X{2231CE39-B963-4B9D-823A-F412ECA637B1}

======Security center information======

AV: AntiVirus Firewall 7.03
FW: AntiVirus Firewall 7.03
AS: Windows Defender
AS: AntiVirus Firewall 7.03

======System event log======

Computer Name: PC-de-Olive
Event Code: 1003
Message: Votre ordinateur n'a pas pu renouveler son adresse à partir du réseau (à partir du serveur DHCP) pour la carte réseau dont l'adresse réseau est 001F3BB37489. Il s'est produit l'erreur suivante :
L'opération a été annulée par l'utilisateur.. Votre ordinateur va continuer à essayer d'obtenir sa propre adresse auprès du serveur d'adresse réseau (DHCP).
Record Number: 59451
Source Name: Microsoft-Windows-Dhcp-Client
Time Written: 20090620143132.000000-000
Event Type: Avertissement
User:

Computer Name: PC-de-Olive
Event Code: 225
Message: L’application \Device\HarddiskVolume1\Windows\explorer.exe avec l’ID de processus 2096 a arrêté le retrait ou l’éjection pour le périphérique USB\VID_13FE&PID_1E23\077A131008BE.
Record Number: 59458
Source Name: Microsoft-Windows-Kernel-PnP
Time Written: 20090620143450.167600-000
Event Type: Avertissement
User: AUTORITE NT\SYSTEM

Computer Name: PC-de-Olive
Event Code: 4001
Message: Le Service d’autoconfiguration WLAN s’est arrêté correctement.

Record Number: 59469
Source Name: Microsoft-Windows-WLAN-AutoConfig
Time Written: 20090620143851.635600-000
Event Type: Avertissement
User: AUTORITE NT\SYSTEM

Computer Name: PC-de-Olive
Event Code: 15016
Message: Impossible d’initialiser le package de sécurité Kerberos pour l’authentification côté serveur. Le champ de données contient le numéro de l’erreur.
Record Number: 59480
Source Name: Microsoft-Windows-HttpEvent
Time Written: 20090620143943.761342-000
Event Type: Erreur
User:

Computer Name: PC-de-Olive
Event Code: 7000
Message: Le service Parallel port driver n'a pas pu démarrer en raison de l'erreur :
Le service ne peut pas être démarré parce qu'il est désactivé ou qu'aucun périphérique activé ne lui est associé.
Record Number: 59522
Source Name: Service Control Manager
Time Written: 20090620144053.000000-000
Event Type: Erreur
User:

=====Application event log=====

Computer Name: PC-de-Olive
Event Code: 1530
Message: Windows a détecté que votre fichier de Registre est toujours utilisé par d'autres applications ou services. Le fichier va être déchargé. Les applications ou services qui ont accès à votre Registre risquent de ne pas fonctionner correctement après cela.

DÉTAIL -
1 user registry handles leaked from \Registry\User\S-1-5-21-2953666331-2871950449-2251577109-1000_Classes:
Process 1016 (\Device\HarddiskVolume1\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-2953666331-2871950449-2251577109-1000_CLASSES

Record Number: 32754
Source Name: Microsoft-Windows-User Profiles Service
Time Written: 20090620104213.000000-000
Event Type: Avertissement
User: AUTORITE NT\SYSTEM

Computer Name: PC-de-Olive
Event Code: 10
Message: Le filtre d’événement avec la requête « SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99 » n’a pas pu être réactivé dans l’espace de noms « //./root/CIMV2 » à cause de l’erreur 0x80041003. Les événements ne peuvent pas être délivrés à travers ce filtre tant que le problème ne sera pas corrigé.
Record Number: 32776
Source Name: Microsoft-Windows-WMI
Time Written: 20090620104438.000000-000
Event Type: Erreur
User:

Computer Name: PC-de-Olive
Event Code: 1530
Message: Windows a détecté que votre fichier de Registre est toujours utilisé par d'autres applications ou services. Le fichier va être déchargé. Les applications ou services qui ont accès à votre Registre risquent de ne pas fonctionner correctement après cela.

41 réponses

Résumé de la discussion

Infection décrite comme une fenêtre 'security system' qui s’ouvre et bloque l’accès à tout logiciel ou navigation, rendant l’ordinateur pratiquement inutilisable et provoquant une immobilisation prolongée. Le contenu partagé montre l’utilisation d’un outil RSIT et d’un rapport HijackThis détaillant de nombreuses entrées suspectes, des services et des démarrages modifiés, indiquant une compromission système. Des symptômes récurrents incluent des modifications du navigateur, des pages de démarrage et des modules BHO, ce qui complique le nettoyage et suggère une infection persistante nécessitant une détection ciblée. En cas de contamination avérée, des conseils pratiques consistent à privilégier des outils de détection réputés hors ligne ou en mode sécurisé, limiter les dégâts et envisager une réinstallation ou une restauration système.

Bobot (l’IA à votre service)
  1. Contributeur sécurité
    Hello , tu es toujours là ?

    SI oui fait les procédures ....

    @+

    0
    1. Contributeur sécurité
      Bonjour ...

      Il y a quelque chose qui résiste a mes tentatives de suppression .. c:\windows\system32\ezsidmv.dat

      Tu peux faire la suite, ensuite on va la traiter ....

      ++++

      0
      1. Bonjour, voici le premier rapport (de Combofixe ), je m'attaque à la suite :

        ComboFix 09-06-22.0D - Olive 24/06/2009 9:01.3 - NTFSx86
        Microsoft® Windows Vista™ Édition Familiale Premium 6.0.6001.1.1252.33.1036.18.3070.1908 [GMT 2:00]
        Lancé depuis: c:\users\Olive\Documents\Desktop\C-FIX.exe
        Commutateurs utilisés :: c:\users\Olive\Documents\Desktop\CFScript.txt
        AV: AntiVirus Firewall 7.03 *On-access scanning disabled* (Updated) {E7512ED5-4245-4B4D-AF3A-382D3F313F15}
        FW: AntiVirus Firewall 7.03 *enabled* {D4747503-0346-49EB-9262-997542F79BF4}
        SP: AntiVirus Firewall 7.03 *disabled* (Updated) {0651C4B0-1D7E-4682-B965-2E9523C483A5}
        SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}

        FILE ::
        "c:\users\Olive\AppData\Local\d3d9caps.dat"
        .

        (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
        .

        c:\users\Olive\AppData\Roaming\EoRezo
        c:\users\Olive\AppData\Local\d3d9caps.dat
        c:\users\Olive\AppData\Roaming\EoRezo\cmhost.cyp
        c:\users\Olive\AppData\Roaming\EoRezo\ConfMedia.cyp
        c:\users\Olive\AppData\Roaming\EoRezo\db\cat.cyp
        c:\users\Olive\AppData\Roaming\EoRezo\eoDesktop\config.xml
        c:\users\Olive\AppData\Roaming\EoRezo\eoDesktop\eoDesktop.html
        c:\users\Olive\AppData\Roaming\EoRezo\eoDesktop\userConfig.xml
        c:\users\Olive\AppData\Roaming\EoRezo\eoStats\eoStats.txt
        c:\users\Olive\AppData\Roaming\EoRezo\host.cyp
        c:\users\Olive\AppData\Roaming\EoRezo\SoftwareUpdate\help_config.cyp
        c:\users\Olive\AppData\Roaming\EoRezo\SoftwareUpdate\SoftwareUpdate.exe
        c:\users\Olive\AppData\Roaming\EoRezo\SoftwareUpdate\SoftwareUpdateHP.exe
        c:\users\Olive\AppData\Roaming\EoRezo\SoftwareUpdate\unins000.dat
        c:\users\Olive\AppData\Roaming\EoRezo\SoftwareUpdate\unins000.exe
        c:\users\Olive\AppData\Roaming\EoRezo\SoftwareUpdate\user_config.cyp
        c:\users\Olive\AppData\Roaming\EoRezo\SoftwareUpdate\user_profil.cyp
        c:\users\Olive\AppData\Roaming\EoRezo\user.cyp

        .
        ((((((((((((((((((((((((((((( Fichiers créés du 2009-05-24 au 2009-06-24 ))))))))))))))))))))))))))))))))))))
        .

        2009-06-24 06:54 . 2009-06-24 06:54 48 ---ha-w- c:\windows\system32\ezsidmv.dat
        2009-06-21 09:44 . 2009-06-21 09:45 -------- d-----w- c:\program files\Ad-remover
        2009-06-21 09:18 . 2009-06-21 09:20 -------- d-----w- C:\GenProc
        2009-06-20 14:41 . 2009-06-20 14:42 -------- d-----w- c:\program files\trend micro
        2009-06-20 14:41 . 2009-06-20 14:42 -------- d-----w- C:\rsit
        2009-06-19 15:23 . 2008-06-20 01:14 97800 ----a-w- c:\windows\system32\infocardapi.dll
        2009-06-19 15:22 . 2008-06-20 01:14 105016 ----a-w- c:\windows\system32\PresentationCFFRasterizerNative_v0300.dll
        2009-06-19 15:22 . 2008-06-20 01:14 622080 ----a-w- c:\windows\system32\icardagt.exe
        2009-06-19 15:22 . 2008-06-20 01:14 43544 ----a-w- c:\windows\system32\PresentationHostProxy.dll
        2009-06-19 15:22 . 2008-06-20 01:14 11264 ----a-w- c:\windows\system32\icardres.dll
        2009-06-19 15:22 . 2008-06-20 01:14 781344 ----a-w- c:\windows\system32\PresentationNative_v0300.dll
        2009-06-19 15:22 . 2008-06-20 01:14 326160 ----a-w- c:\windows\system32\PresentationHost.exe
        2009-06-19 15:15 . 2008-07-27 18:03 96760 ----a-w- c:\windows\system32\dfshim.dll
        2009-06-19 15:15 . 2008-07-27 18:03 282112 ----a-w- c:\windows\system32\mscoree.dll
        2009-06-19 15:15 . 2008-07-27 18:03 41984 ----a-w- c:\windows\system32\netfxperf.dll
        2009-06-19 15:15 . 2008-07-27 18:03 158720 ----a-w- c:\windows\system32\mscorier.dll
        2009-06-19 15:14 . 2008-07-27 18:03 83968 ----a-w- c:\windows\system32\mscories.dll
        2009-06-11 10:20 . 2009-04-21 11:55 2033152 ----a-w- c:\windows\system32\win32k.sys
        2009-06-11 10:20 . 2009-04-23 12:42 636928 ----a-w- c:\windows\system32\localspl.dll
        2009-06-11 10:20 . 2009-04-23 12:43 784896 ----a-w- c:\windows\system32\rpcrt4.dll
        2009-06-11 10:20 . 2009-04-24 16:05 827904 ----a-w- c:\windows\system32\wininet.dll
        2009-06-11 10:19 . 2009-04-24 13:44 26624 ----a-w- c:\windows\system32\ieUnatt.exe
        2009-06-11 10:19 . 2009-04-24 16:02 78336 ----a-w- c:\windows\system32\ieencode.dll
        2009-06-09 07:38 . 2009-06-09 07:38 456304 ----a-w- c:\programdata\Google\Google Toolbar\Update\gtb65F6.tmp.exe

        .
        (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
        .
        2009-06-24 06:54 . 2008-12-25 14:15 -------- d-----w- c:\users\Olive\AppData\Roaming\skypePM
        2009-06-23 14:26 . 2009-01-25 20:33 -------- d-----w- c:\programdata\Google Updater
        2009-06-19 16:21 . 2008-03-07 05:14 676592 ----a-w- c:\windows\system32\perfh00C.dat
        2009-06-19 16:21 . 2008-03-07 05:14 126880 ----a-w- c:\windows\system32\perfc00C.dat
        2009-06-19 16:20 . 2008-12-22 15:37 108248 ----a-w- c:\users\Olive\AppData\Local\GDIPFONTCACHEV1.DAT
        2009-06-19 15:41 . 2008-03-06 21:39 -------- d-----w- c:\programdata\Microsoft Help
        2009-06-14 17:05 . 2008-12-25 10:29 -------- d-----w- c:\users\Olive\AppData\Roaming\LimeWire
        2009-06-11 22:28 . 2008-03-06 21:17 -------- d-----w- c:\program files\Microsoft Works
        2009-06-11 06:12 . 2008-12-24 21:58 1915520 ----a-w- c:\users\Olive\AppData\Roaming\Macromedia\Flash Player\www.macromedia.com\bin\fpupdateax\fpupdateax.exe
        2009-06-03 22:21 . 2009-02-17 18:05 -------- d-----w- c:\users\Olive\AppData\Roaming\dvdcss
        2009-05-16 16:35 . 2009-05-10 13:14 -------- d-----w- c:\program files\RaybanMirror
        2009-05-10 16:42 . 2009-05-10 16:42 -------- d-----w- c:\users\Olive\AppData\Roaming\Fit3DLive
        2009-05-06 16:17 . 2008-12-25 14:13 -------- d-----w- c:\users\Olive\AppData\Roaming\Skype
        2009-04-26 10:43 . 2009-04-26 10:43 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdMtpDr_01_00_00.Wdf
        2009-04-26 10:29 . 2008-12-22 15:31 -------- d-----w- c:\users\Olive\AppData\Roaming\Hewlett-Packard
        2009-04-26 10:27 . 2009-04-26 10:27 -------- d-----w- c:\program files\Samsung
        2009-04-26 10:27 . 2008-03-06 20:36 -------- d--h--w- c:\program files\InstallShield Installation Information
        2009-04-26 10:27 . 2008-03-06 20:32 -------- d-----w- c:\program files\Hewlett-Packard
        .

        ((((((((((((((((((((((((((((( SnapShot@2009-06-23_15.51.44 )))))))))))))))))))))))))))))))))))))))))
        .
        + 2008-01-21 01:58 . 2009-06-24 06:54 52050 c:\windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
        + 2006-11-02 13:05 . 2009-06-24 06:54 81658 c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
        + 2008-12-22 15:21 . 2009-06-24 06:57 16384 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
        - 2008-12-22 15:21 . 2009-06-23 15:45 16384 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
        + 2008-12-22 15:21 . 2009-06-24 06:57 32768 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
        - 2008-12-22 15:21 . 2009-06-23 15:45 32768 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
        + 2008-12-22 15:21 . 2009-06-24 06:57 16384 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
        - 2008-12-22 15:21 . 2009-06-23 15:45 16384 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
        - 2008-12-22 15:25 . 2009-06-23 14:26 7580 c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-2953666331-2871950449-2251577109-1000_UserData.bin
        + 2008-12-22 15:25 . 2009-06-24 06:54 7580 c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-2953666331-2871950449-2251577109-1000_UserData.bin
        + 2009-06-24 06:52 . 2009-06-24 06:52 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
        - 2009-06-23 14:24 . 2009-06-23 14:24 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
        - 2009-06-23 14:24 . 2009-06-23 14:24 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
        + 2009-06-24 06:52 . 2009-06-24 06:52 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
        + 2008-12-22 15:47 . 2009-06-23 21:43 291694 c:\windows\System32\WDI\SuspendPerformanceDiagnostics_SystemData_S3.bin
        + 2008-12-22 15:55 . 2009-06-23 22:28 124120 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache3.0.0.0.dat
        .
        ((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
        .
        .
        *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
        REGEDIT4

        [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
        "Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-21 1233920]
        "LightScribe Control Panel"="c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe" [2007-08-23 455968]
        "HPAdvisor"="c:\program files\Hewlett-Packard\HP Advisor\HPAdvisor.exe" [2007-10-01 1783136]
        "msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-02-06 3885408]
        "Skype"="c:\program files\Skype\Phone\Skype.exe" [2008-11-18 21633320]
        "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-01-25 39408]
        "ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952]
        "WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240]

        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
        "NvSvc"="c:\windows\system32\nvsvc.dll" [2007-09-19 86016]
        "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-09-19 8497696]
        "NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-09-19 81920]
        "Apoint"="c:\program files\Apoint2K\Apoint.exe" [2007-03-11 159744]
        "IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2007-07-25 174616]
        "QPService"="c:\program files\HP\QuickPlay\QPService.exe" [2007-12-19 468264]
        "QlbCtrl"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2007-09-19 202032]
        "OnScreenDisplay"="c:\program files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exe" [2007-09-04 554320]
        "UCam_Menu"="c:\program files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" [2007-08-16 218408]
        "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 40048]
        "HP Software Update"="c:\program files\Hp\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
        "hpWirelessAssistant"="c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2007-09-13 480560]
        "WAWifiMessage"="c:\program files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe" [2007-01-08 311296]
        "SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_02\bin\jusched.exe" [2007-07-12 132496]
        "F-Secure Manager"="c:\program files\Orange\AntivirusFirewall\Common\FSM32.EXE" [2008-04-23 182936]
        "F-Secure TNB"="c:\program files\Orange\AntivirusFirewall\FSGUI\TNBUtil.exe" [2008-04-23 744032]
        "ORAHSSSessionManager"="c:\program files\OrangeHSS\SessionManager\SessionManager.exe" [2007-12-12 107248]
        "fssui"="c:\program files\Windows Live\Family Safety\fsui.exe" [2009-02-06 454000]

        c:\users\Olive\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
        Outil de notification Live Search.lnk - c:\users\Olive\AppData\Roaming\Microsoft\Live Search\Notification-LiveSearch.exe [2008-12-26 143360]

        c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
        BTTray.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2007-9-5 727592]

        [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
        "EnableLUA"= 0 (0x0)
        "EnableUIADesktopToggle"= 0 (0x0)

        [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
        "aux"=wdmaud.drv

        [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
        @="Service"

        [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
        "DisableMonitoring"=dword:00000001

        [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
        "DisableMonitoring"=dword:00000001

        [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
        "DisableMonitoring"=dword:00000001

        [HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
        "EnableFirewall"= 0 (0x0)

        [HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
        "{F986AD45-3D68-4EB9-BD40-DC5B96B86266}"= UDP:c:\program files\Common Files\AOL\Loader\aolload.exe:AOL Loader
        "{CC97F759-633E-4B96-99BA-F2BACDCC0198}"= TCP:c:\program files\Common Files\AOL\Loader\aolload.exe:AOL Loader
        "{6320805D-B0B6-4E2D-A635-BBB1EF5FE9B3}"= c:\program files\Cyberlink\PowerDirector\PDR.EXE:CyberLink PowerDirector
        "{2648016C-1312-4404-BDE4-786B2B6E4468}"= c:\program files\HP\QuickPlay\QP.exe:Quick Play
        "{A73EB178-FD4A-4406-9387-FC99093F7CE1}"= c:\program files\HP\QuickPlay\QPService.exe:Quick Play Resident Program
        "{4D2CBDDB-9E8C-4686-B628-E91E2CBB931F}"= c:\program files\Skype\Phone\Skype.exe:Skype
        "{85097506-13B2-47F9-8C38-03CEF85087A3}"= TCP:6004|c:\program files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook
        "{868E96A5-C673-4BD8-A750-F6ED88B230F2}"= c:\program files\Windows Live\Sync\WindowsLiveSync.exe:Windows Live Sync

        [HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
        "EnableFirewall"= 0 (0x0)

        [HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
        "EnableFirewall"= 0 (0x0)

        [HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List]
        "c:\\Program Files\\OrangeHSS\\Connectivity\\ConnectivityManager.exe"= c:\program files\OrangeHSS\Connectivity\ConnectivityManager.exe:*:enabled:CSS

        R1 F-Secure HIPS;F-Secure HIPS;c:\program files\Orange\AntivirusFirewall\HIPS\fshs.sys [23/12/2008 15:42 41184]
        R1 FSES;F-Secure Email Scanning Driver;c:\windows\System32\drivers\fses.sys [23/12/2008 15:42 34752]
        R1 FSFW;F-Secure Firewall Driver;c:\windows\System32\drivers\fsdfw.sys [23/12/2008 15:42 60064]
        R1 fsvista;F-Secure Vista Support Driver;c:\program files\Orange\AntivirusFirewall\Anti-Virus\minifilter\fsvista.sys [23/12/2008 15:41 12896]
        R2 fssfltr;FssFltr;c:\windows\System32\drivers\fssfltr.sys [26/12/2008 21:22 55264]
        R2 fsssvc;Windows Live Contrôle parental;c:\program files\Windows Live\Family Safety\fsssvc.exe [06/02/2009 19:08 533360]
        R3 F-Secure Gatekeeper;F-Secure Gatekeeper;c:\program files\Orange\AntivirusFirewall\Anti-Virus\minifilter\fsgk.sys [23/12/2008 15:41 62048]
        S3 PCAMp50;PCAMp50 NDIS Protocol Driver;c:\windows\System32\drivers\PCAMp50.sys [17/02/2009 14:41 28224]
        S4 F-Secure Filter;F-Secure File System Filter;c:\program files\Orange\AntivirusFirewall\Anti-Virus\win2k\fsfilter.sys [23/12/2008 15:41 39776]
        S4 F-Secure Recognizer;F-Secure File System Recognizer;c:\program files\Orange\AntivirusFirewall\Anti-Virus\win2k\fsrec.sys [23/12/2008 15:41 25184]

        [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
        bthsvcs REG_MULTI_SZ BthServ

        [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
        "c:\program files\Common Files\LightScribe\LSRunOnce.exe"
        .
        Contenu du dossier 'Tâches planifiées'

        2009-06-24 c:\windows\Tasks\Google Software Updater.job
        - c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-12-25 17:53]

        2009-06-24 c:\windows\Tasks\Scheduled scanning task.job
        - c:\progra~1\Orange\ANTIVI~1\ANTI-V~1\fsav.exe [2008-12-23 16:11]

        2009-06-23 c:\windows\Tasks\User_Feed_Synchronization-{EACA1F9D-7DA9-463A-A478-B21C79F75452}.job
        - c:\windows\system32\msfeedssync.exe [2008-01-21 02:24]
        .
        - - - - ORPHELINS SUPPRIMES - - - -

        HKLM-RunOnce-SoftwareHelper - c:\users\Olive\AppData\Roaming\eoRezo\SoftwareUpdate\SoftwareUpdateHP.exe

        .
        ------- Examen supplémentaire -------
        .
        uStart Page = hxxp://y.lo.st
        mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=fr_fr&c=81&bd=Pavilion&pf=laptop
        IE: &Recherche AOL Toolbar - c:\program files\aol\aol toolbar 5.0\resources\fr-fr\local\search.html
        IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
        IE: Envoyer au périphérique &Bluetooth... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
        IE: Envoyer l'&image au périphérique Bluetooth... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
        LSP: c:\program files\Orange\AntivirusFirewall\FSPS\program\FSLSP.DLL
        .

        **************************************************************************

        catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
        Rootkit scan 2009-06-24 09:06
        Windows 6.0.6001 Service Pack 1 NTFS

        Recherche de processus cachés ...

        Recherche d'éléments en démarrage automatique cachés ...

        Recherche de fichiers cachés ...

        Scan terminé avec succès
        Fichiers cachés: 0

        **************************************************************************
        .
        --------------------- CLES DE REGISTRE BLOQUEES ---------------------

        [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
        @Denied: (A) (Users)
        @Denied: (A) (Everyone)
        @Allowed: (B 1 2 3 4 5) (S-1-5-20)
        "BlindDial"=dword:00000000
        .
        --------------------- DLLs chargées dans les processus actifs ---------------------

        - - - - - - - > 'winlogon.exe'(844)
        c:\program files\Orange\AntivirusFirewall\FWES\Program\fsdc.dll

        - - - - - - - > 'lsass.exe'(728)
        c:\program files\Orange\AntivirusFirewall\FWES\Program\fsdc.dll

        - - - - - - - > 'csrss.exe'(616)
        c:\program files\Orange\AntivirusFirewall\FWES\Program\fsdc.dll

        - - - - - - - > 'csrss.exe'(680)
        c:\program files\Orange\AntivirusFirewall\FWES\Program\fsdc.dll
        .
        Heure de fin: 2009-06-24 9:08
        ComboFix-quarantined-files.txt 2009-06-24 07:08
        ComboFix2.txt 2009-06-23 16:46
        ComboFix3.txt 2009-06-23 15:53

        Avant-CF: 213 500 362 752 octets libres
        Après-CF: 213 524 508 672 octets libres

        236 --- E O F --- 2009-06-23 14:30
        0
        1. Contributeur sécurité
          Slt,

          On a bien avancés ...

          Dans l ordre: ^^^^

          Folder::
          c:\users\Olive\AppData\Roaming\EoRezo

          File::
          c:\users\Olive\AppData\Local\d3d9caps.dat

          - Ouvre le Bloc-Notes puis colle le texte copié.
          (Démarrer\Tous les programmes\Accessoires\Bloc notes.)

          - Sauvegarde ce fichier sous le nom de CFScript.txt

          - Glisse maintenant le fichier CFScript.txt dans Combofix.exe

          Cela va relancer Combofix,

          Une fenêtre bleue va apparaître: au message qui apparaît ( Type 1 to continue, or 2 to abort) , tape 1 puis valide.

          Patiente le temps du scan.Le bureau va disparaître à plusieurs reprises: c'est normal!

          Ne touche à rien tant que le scan n'est pas terminé.

          Après redémarrage, poste le contenu du rapport Combofix.txt

          Ensuite:

          ▶ Télécharge Toolscleaner sur ton Bureau

          ▶ Sous XP : Double-clique sur ToolsCleaner2.exe
          ▶ Sous Vista : Fais un clic droit sur ToolsCleaner2.exe et sélectionne "Exécuter en tant qu'administrateur"
          ▶ Clique sur Recherche et laisse le scan se terminer.
          ▶ Clique sur Suppression pour finaliser.
          ▶ Tu peux, si tu le souhaites, te servir des Options facultatives.
          ▶ Clique sur Quitter, pour que le rapport puisse se créer.
          ▶ Le rapport (TCleaner.txt) se trouve à la racine de votre disque dur (C:\)...colle le dans ta réponse

          Ensuite:

          **********************************************************
          ********************* Option S (Recherche) *********************
          **********************************************************

          Télécharge AD-Remover ( de C_XX ) sur ton bureau :

          ! Déconnecte toi et ferme toutes applications en cours !

          • Double clique sur "AD-R.exe" pour lancer l'installation et laisse les paramètres d'installation par défaut .

          • Double-clique sur le raccourci Ad-remover qui est sur ton bureau pour lancer l'outil .

          • Au menu principal choisis l'option "S" et tape sur [entrée] .

          • Laisse travailler l'outil et ne touche à rien ...

          --> Poste le rapport qui apparait à la fin , sur le forum ... <--

          Notes:

          1- Le rapport est sauvegardé aussi sous C:\Ad-report-scan.log
          2- "Process.exe", une composante de l'outil, est détecté par certains antivirus :
          (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool.
          Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.
          Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall...) d'où l'alerte émise par ces antivirus.


          Aide (Installation)
          Aide (Recherche)

          **********************************************************
          ********************* Option L (Nettoyage) *********************
          **********************************************************

          ! Déconnecte toi et ferme toutes applications en cours !

          • Double-clique sur le raccourci Ad-remover qui est sur ton bureau pour lancer l'outil .

          • Au menu principal choisis l'option "L" et tape sur [entrée] .

          • Laisse travailler l'outil et ne touche à rien ...

          --> Poste le rapport qui apparait à la fin , sur le forum ... <--

          Notes:

          1- Le rapport est sauvegardé aussi sous C:\Ad-report-clean.log
          2- "Process.exe", une composante de l'outil, est détecté par certains antivirus :
          (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool.
          Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.
          Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall...) d'où l'alerte émise par ces antivirus.


          Aide en images (Nettoyage)

          ...

          ++
          0
          1. Ils ne me demandent pas de taper un ni de redemarrer l'ordinateur mais cela à l'air de fonctionner, voici le rapport:

            ComboFix 09-06-22.0D - Olive 23/06/2009 18:42.2 - NTFSx86
            Microsoft® Windows Vista™ Édition Familiale Premium 6.0.6001.1.1252.33.1036.18.3070.1438 [GMT 2:00]
            Lancé depuis: c:\users\Olive\Documents\Desktop\C-FIX.exe
            Commutateurs utilisés :: c:\users\Olive\Documents\Desktop\CFScript.txt
            AV: AntiVirus Firewall 7.03 *On-access scanning disabled* (Updated) {E7512ED5-4245-4B4D-AF3A-382D3F313F15}
            FW: AntiVirus Firewall 7.03 *enabled* {D4747503-0346-49EB-9262-997542F79BF4}
            SP: AntiVirus Firewall 7.03 *disabled* (Updated) {0651C4B0-1D7E-4682-B965-2E9523C483A5}
            SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}

            FILE ::
            "c:\windows\bf23567.dat"
            "c:\windows\bf5087.dat"
            "c:\windows\bthservsdp.dat"
            "c:\windows\dk39fi4fe.dat"
            "c:\windows\system32\ezsidmv.dat"
            .

            (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
            .

            c:\program files\EoRezo
            c:\programdata\13268674
            c:\programdata\19462744
            c:\program files\EoRezo\ConfMedia.cyp
            c:\program files\EoRezo\EoAdv\atl90.dll
            c:\program files\EoRezo\EoAdv\EoAdv.dll
            c:\program files\EoRezo\EoAdv\EoRezoBHO.dll
            c:\program files\EoRezo\EoAdv\mfc90.dll
            c:\program files\EoRezo\EoAdv\Microsoft.VC90.ATL.manifest
            c:\program files\EoRezo\EoAdv\Microsoft.VC90.CRT.manifest
            c:\program files\EoRezo\EoAdv\Microsoft.VC90.MFC.manifest
            c:\program files\EoRezo\EoAdv\msvcr90.dll
            c:\program files\EoRezo\EoEngine.exe
            c:\program files\EoRezo\eoEngine.url
            c:\program files\EoRezo\EoMultiLanguage.dll
            c:\program files\EoRezo\EoRezoComm.dll
            c:\program files\EoRezo\EoRezoImg_17.dll
            c:\program files\EoRezo\EoRezoImg_19.dll
            c:\program files\EoRezo\EoRezoImg_20.dll
            c:\program files\EoRezo\EoRezoImg_21.dll
            c:\program files\EoRezo\EoRezoImg_22.dll
            c:\program files\EoRezo\EoRezoImg_23.dll
            c:\program files\EoRezo\EoRezoTools_16.dll
            c:\program files\EoRezo\EoRezoTools_17.dll
            c:\program files\EoRezo\EoRezoTools_18.dll
            c:\program files\EoRezo\EoRezoTools_20.dll
            c:\program files\EoRezo\EoRezoTools_21.dll
            c:\program files\EoRezo\EoRezoTools_26.dll
            c:\program files\EoRezo\EoRezoTools_27.dll
            c:\program files\EoRezo\EoRezoTools_28.dll
            c:\program files\EoRezo\EoRezoTools_29.dll
            c:\program files\EoRezo\EoRezoTools_30.dll
            c:\program files\EoRezo\FreeImage.dll
            c:\program files\EoRezo\Host.cyp
            c:\program files\EoRezo\lang\ihm_eoclock.xml
            c:\program files\EoRezo\lang\ihm_eoengine.xml
            c:\program files\EoRezo\lang\ihm_eonet.xml
            c:\program files\EoRezo\lang\ihm_eorezotools.xml
            c:\program files\EoRezo\lang\ihm_eosudoku.xml
            c:\program files\EoRezo\lang\ihm_eoweather.xml
            c:\program files\EoRezo\lang\lang_en.xml
            c:\program files\EoRezo\lang\lang_es.xml
            c:\program files\EoRezo\lang\lang_fr.xml
            c:\program files\EoRezo\lang\lang_it.xml
            c:\program files\EoRezo\MngInstaller.dll
            c:\program files\EoRezo\unins000.dat
            c:\program files\EoRezo\unins000.exe
            c:\program files\EoRezo\user.cyp
            c:\programdata\13268674\pc13268674ins
            c:\programdata\19462744\19462744.glu
            c:\windows\bf23567.dat
            c:\windows\bf5087.dat
            c:\windows\bthservsdp.dat
            c:\windows\dk39fi4fe.dat
            c:\windows\system32\ezsidmv.dat

            .
            ((((((((((((((((((((((((((((( Fichiers créés du 2009-05-23 au 2009-06-23 ))))))))))))))))))))))))))))))))))))
            .

            2009-06-21 09:44 . 2009-06-21 09:45 -------- d-----w- c:\program files\Ad-remover
            2009-06-21 09:18 . 2009-06-21 09:20 -------- d-----w- C:\GenProc
            2009-06-20 14:41 . 2009-06-20 14:42 -------- d-----w- c:\program files\trend micro
            2009-06-20 14:41 . 2009-06-20 14:42 -------- d-----w- C:\rsit
            2009-06-19 15:23 . 2008-06-20 01:14 97800 ----a-w- c:\windows\system32\infocardapi.dll
            2009-06-19 15:22 . 2008-06-20 01:14 105016 ----a-w- c:\windows\system32\PresentationCFFRasterizerNative_v0300.dll
            2009-06-19 15:22 . 2008-06-20 01:14 622080 ----a-w- c:\windows\system32\icardagt.exe
            2009-06-19 15:22 . 2008-06-20 01:14 43544 ----a-w- c:\windows\system32\PresentationHostProxy.dll
            2009-06-19 15:22 . 2008-06-20 01:14 11264 ----a-w- c:\windows\system32\icardres.dll
            2009-06-19 15:22 . 2008-06-20 01:14 781344 ----a-w- c:\windows\system32\PresentationNative_v0300.dll
            2009-06-19 15:22 . 2008-06-20 01:14 326160 ----a-w- c:\windows\system32\PresentationHost.exe
            2009-06-19 15:15 . 2008-07-27 18:03 96760 ----a-w- c:\windows\system32\dfshim.dll
            2009-06-19 15:15 . 2008-07-27 18:03 282112 ----a-w- c:\windows\system32\mscoree.dll
            2009-06-19 15:15 . 2008-07-27 18:03 41984 ----a-w- c:\windows\system32\netfxperf.dll
            2009-06-19 15:15 . 2008-07-27 18:03 158720 ----a-w- c:\windows\system32\mscorier.dll
            2009-06-19 15:14 . 2008-07-27 18:03 83968 ----a-w- c:\windows\system32\mscories.dll
            2009-06-11 10:20 . 2009-04-21 11:55 2033152 ----a-w- c:\windows\system32\win32k.sys
            2009-06-11 10:20 . 2009-04-23 12:42 636928 ----a-w- c:\windows\system32\localspl.dll
            2009-06-11 10:20 . 2009-04-23 12:43 784896 ----a-w- c:\windows\system32\rpcrt4.dll
            2009-06-11 10:20 . 2009-04-24 16:05 827904 ----a-w- c:\windows\system32\wininet.dll
            2009-06-11 10:19 . 2009-04-24 13:44 26624 ----a-w- c:\windows\system32\ieUnatt.exe
            2009-06-11 10:19 . 2009-04-24 16:02 78336 ----a-w- c:\windows\system32\ieencode.dll
            2009-06-09 07:38 . 2009-06-09 07:38 456304 ----a-w- c:\programdata\Google\Google Toolbar\Update\gtb65F6.tmp.exe

            .
            (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
            .
            2009-06-23 14:26 . 2009-01-25 20:33 -------- d-----w- c:\programdata\Google Updater
            2009-06-23 14:25 . 2008-12-25 14:15 -------- d-----w- c:\users\Olive\AppData\Roaming\skypePM
            2009-06-23 14:25 . 2008-12-27 15:56 -------- d-----w- c:\users\Olive\AppData\Roaming\EoRezo
            2009-06-20 14:41 . 2009-02-09 23:04 7592 ----a-w- c:\users\Olive\AppData\Local\d3d9caps.dat
            2009-06-19 16:21 . 2008-03-07 05:14 676592 ----a-w- c:\windows\system32\perfh00C.dat
            2009-06-19 16:21 . 2008-03-07 05:14 126880 ----a-w- c:\windows\system32\perfc00C.dat
            2009-06-19 16:20 . 2008-12-22 15:37 108248 ----a-w- c:\users\Olive\AppData\Local\GDIPFONTCACHEV1.DAT
            2009-06-19 15:41 . 2008-03-06 21:39 -------- d-----w- c:\programdata\Microsoft Help
            2009-06-14 17:05 . 2008-12-25 10:29 -------- d-----w- c:\users\Olive\AppData\Roaming\LimeWire
            2009-06-11 22:28 . 2008-03-06 21:17 -------- d-----w- c:\program files\Microsoft Works
            2009-06-11 06:12 . 2008-12-24 21:58 1915520 ----a-w- c:\users\Olive\AppData\Roaming\Macromedia\Flash Player\www.macromedia.com\bin\fpupdateax\fpupdateax.exe
            2009-06-03 22:21 . 2009-02-17 18:05 -------- d-----w- c:\users\Olive\AppData\Roaming\dvdcss
            2009-05-16 16:35 . 2009-05-10 13:14 -------- d-----w- c:\program files\RaybanMirror
            2009-05-10 16:42 . 2009-05-10 16:42 -------- d-----w- c:\users\Olive\AppData\Roaming\Fit3DLive
            2009-05-06 16:17 . 2008-12-25 14:13 -------- d-----w- c:\users\Olive\AppData\Roaming\Skype
            2009-04-26 10:43 . 2009-04-26 10:43 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdMtpDr_01_00_00.Wdf
            2009-04-26 10:29 . 2008-12-22 15:31 -------- d-----w- c:\users\Olive\AppData\Roaming\Hewlett-Packard
            2009-04-26 10:27 . 2009-04-26 10:27 -------- d-----w- c:\program files\Samsung
            2009-04-26 10:27 . 2008-03-06 20:36 -------- d--h--w- c:\program files\InstallShield Installation Information
            2009-04-26 10:27 . 2008-03-06 20:32 -------- d-----w- c:\program files\Hewlett-Packard
            .

            ((((((((((((((((((((((((((((( SnapShot@2009-06-23_15.51.44 )))))))))))))))))))))))))))))))))))))))))
            .
            - 2008-12-22 15:21 . 2009-06-23 15:45 16384 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
            + 2008-12-22 15:21 . 2009-06-23 16:34 16384 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
            + 2008-12-22 15:21 . 2009-06-23 16:34 32768 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
            - 2008-12-22 15:21 . 2009-06-23 15:45 32768 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
            + 2008-12-22 15:21 . 2009-06-23 16:34 16384 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
            - 2008-12-22 15:21 . 2009-06-23 15:45 16384 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
            .
            ((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
            .
            .
            *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
            REGEDIT4

            [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
            "Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-21 1233920]
            "LightScribe Control Panel"="c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe" [2007-08-23 455968]
            "HPAdvisor"="c:\program files\Hewlett-Packard\HP Advisor\HPAdvisor.exe" [2007-10-01 1783136]
            "msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-02-06 3885408]
            "Skype"="c:\program files\Skype\Phone\Skype.exe" [2008-11-18 21633320]
            "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-01-25 39408]
            "ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952]
            "WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240]

            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
            "NvSvc"="c:\windows\system32\nvsvc.dll" [2007-09-19 86016]
            "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-09-19 8497696]
            "NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-09-19 81920]
            "Apoint"="c:\program files\Apoint2K\Apoint.exe" [2007-03-11 159744]
            "IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2007-07-25 174616]
            "QPService"="c:\program files\HP\QuickPlay\QPService.exe" [2007-12-19 468264]
            "QlbCtrl"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2007-09-19 202032]
            "OnScreenDisplay"="c:\program files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exe" [2007-09-04 554320]
            "UCam_Menu"="c:\program files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" [2007-08-16 218408]
            "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 40048]
            "HP Software Update"="c:\program files\Hp\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
            "hpWirelessAssistant"="c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2007-09-13 480560]
            "WAWifiMessage"="c:\program files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe" [2007-01-08 311296]
            "SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_02\bin\jusched.exe" [2007-07-12 132496]
            "F-Secure Manager"="c:\program files\Orange\AntivirusFirewall\Common\FSM32.EXE" [2008-04-23 182936]
            "F-Secure TNB"="c:\program files\Orange\AntivirusFirewall\FSGUI\TNBUtil.exe" [2008-04-23 744032]
            "ORAHSSSessionManager"="c:\program files\OrangeHSS\SessionManager\SessionManager.exe" [2007-12-12 107248]
            "fssui"="c:\program files\Windows Live\Family Safety\fsui.exe" [2009-02-06 454000]

            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
            "SoftwareHelper"="c:\users\Olive\AppData\Roaming\eoRezo\SoftwareUpdate\SoftwareUpdateHP.exe" [2008-12-09 368224]

            c:\users\Olive\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
            Outil de notification Live Search.lnk - c:\users\Olive\AppData\Roaming\Microsoft\Live Search\Notification-LiveSearch.exe [2008-12-26 143360]

            c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
            BTTray.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2007-9-5 727592]

            [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
            "EnableLUA"= 0 (0x0)
            "EnableUIADesktopToggle"= 0 (0x0)

            [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
            "aux"=wdmaud.drv

            [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
            @="Service"

            [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
            "DisableMonitoring"=dword:00000001

            [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
            "DisableMonitoring"=dword:00000001

            [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
            "DisableMonitoring"=dword:00000001

            [HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
            "EnableFirewall"= 0 (0x0)

            [HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
            "{F986AD45-3D68-4EB9-BD40-DC5B96B86266}"= UDP:c:\program files\Common Files\AOL\Loader\aolload.exe:AOL Loader
            "{CC97F759-633E-4B96-99BA-F2BACDCC0198}"= TCP:c:\program files\Common Files\AOL\Loader\aolload.exe:AOL Loader
            "{6320805D-B0B6-4E2D-A635-BBB1EF5FE9B3}"= c:\program files\Cyberlink\PowerDirector\PDR.EXE:CyberLink PowerDirector
            "{2648016C-1312-4404-BDE4-786B2B6E4468}"= c:\program files\HP\QuickPlay\QP.exe:Quick Play
            "{A73EB178-FD4A-4406-9387-FC99093F7CE1}"= c:\program files\HP\QuickPlay\QPService.exe:Quick Play Resident Program
            "{4D2CBDDB-9E8C-4686-B628-E91E2CBB931F}"= c:\program files\Skype\Phone\Skype.exe:Skype
            "{85097506-13B2-47F9-8C38-03CEF85087A3}"= TCP:6004|c:\program files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook
            "{868E96A5-C673-4BD8-A750-F6ED88B230F2}"= c:\program files\Windows Live\Sync\WindowsLiveSync.exe:Windows Live Sync

            [HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
            "EnableFirewall"= 0 (0x0)

            [HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
            "EnableFirewall"= 0 (0x0)

            [HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List]
            "c:\\Program Files\\OrangeHSS\\Connectivity\\ConnectivityManager.exe"= c:\program files\OrangeHSS\Connectivity\ConnectivityManager.exe:*:enabled:CSS

            R1 F-Secure HIPS;F-Secure HIPS;c:\program files\Orange\AntivirusFirewall\HIPS\fshs.sys [23/12/2008 15:42 41184]
            R1 FSES;F-Secure Email Scanning Driver;c:\windows\System32\drivers\fses.sys [23/12/2008 15:42 34752]
            R1 FSFW;F-Secure Firewall Driver;c:\windows\System32\drivers\fsdfw.sys [23/12/2008 15:42 60064]
            R1 fsvista;F-Secure Vista Support Driver;c:\program files\Orange\AntivirusFirewall\Anti-Virus\minifilter\fsvista.sys [23/12/2008 15:41 12896]
            R2 fssfltr;FssFltr;c:\windows\System32\drivers\fssfltr.sys [26/12/2008 21:22 55264]
            R2 fsssvc;Windows Live Contrôle parental;c:\program files\Windows Live\Family Safety\fsssvc.exe [06/02/2009 19:08 533360]
            R3 F-Secure Gatekeeper;F-Secure Gatekeeper;c:\program files\Orange\AntivirusFirewall\Anti-Virus\minifilter\fsgk.sys [23/12/2008 15:41 62048]
            S3 PCAMp50;PCAMp50 NDIS Protocol Driver;c:\windows\System32\drivers\PCAMp50.sys [17/02/2009 14:41 28224]
            S4 F-Secure Filter;F-Secure File System Filter;c:\program files\Orange\AntivirusFirewall\Anti-Virus\win2k\fsfilter.sys [23/12/2008 15:41 39776]
            S4 F-Secure Recognizer;F-Secure File System Recognizer;c:\program files\Orange\AntivirusFirewall\Anti-Virus\win2k\fsrec.sys [23/12/2008 15:41 25184]

            [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
            bthsvcs REG_MULTI_SZ BthServ

            [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
            "c:\program files\Common Files\LightScribe\LSRunOnce.exe"
            .
            Contenu du dossier 'Tâches planifiées'

            2009-06-23 c:\windows\Tasks\Google Software Updater.job
            - c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-12-25 17:53]

            2009-06-23 c:\windows\Tasks\Scheduled scanning task.job
            - c:\progra~1\Orange\ANTIVI~1\ANTI-V~1\fsav.exe [2008-12-23 16:11]

            2009-06-23 c:\windows\Tasks\User_Feed_Synchronization-{EACA1F9D-7DA9-463A-A478-B21C79F75452}.job
            - c:\windows\system32\msfeedssync.exe [2008-01-21 02:24]
            .
            - - - - ORPHELINS SUPPRIMES - - - -

            HKLM-Run-EoEngine - c:\program files\EoRezo\EoEngine.exe

            .
            ------- Examen supplémentaire -------
            .
            uStart Page = hxxp://y.lo.st
            mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=fr_fr&c=81&bd=Pavilion&pf=laptop
            IE: &Recherche AOL Toolbar - c:\program files\aol\aol toolbar 5.0\resources\fr-fr\local\search.html
            IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
            IE: Envoyer au périphérique &Bluetooth... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
            IE: Envoyer l'&image au périphérique Bluetooth... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
            LSP: c:\program files\Orange\AntivirusFirewall\FSPS\program\FSLSP.DLL
            .

            **************************************************************************

            catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
            Rootkit scan 2009-06-23 18:44
            Windows 6.0.6001 Service Pack 1 NTFS

            Recherche de processus cachés ...

            Recherche d'éléments en démarrage automatique cachés ...

            Recherche de fichiers cachés ...

            Scan terminé avec succès
            Fichiers cachés: 0

            **************************************************************************
            .
            --------------------- CLES DE REGISTRE BLOQUEES ---------------------

            [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
            @Denied: (A) (Users)
            @Denied: (A) (Everyone)
            @Allowed: (B 1 2 3 4 5) (S-1-5-20)
            "BlindDial"=dword:00000000
            .
            --------------------- DLLs chargées dans les processus actifs ---------------------

            - - - - - - - > 'winlogon.exe'(912)
            c:\program files\Orange\AntivirusFirewall\FWES\Program\fsdc.dll

            - - - - - - - > 'lsass.exe'(728)
            c:\program files\Orange\AntivirusFirewall\FWES\Program\fsdc.dll

            - - - - - - - > 'csrss.exe'(616)
            c:\program files\Orange\AntivirusFirewall\FWES\Program\fsdc.dll

            - - - - - - - > 'csrss.exe'(680)
            c:\program files\Orange\AntivirusFirewall\FWES\Program\fsdc.dll
            .
            Heure de fin: 2009-06-23 18:46
            ComboFix-quarantined-files.txt 2009-06-23 16:46
            ComboFix2.txt 2009-06-23 15:53

            Avant-CF: 212 315 734 016 octets libres
            Après-CF: 212 295 438 336 octets libres

            269 --- E O F --- 2009-06-23 14:30
            0
            1. Contributeur sécurité
              Très bien ...

              **

              Registry::
              [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
              "EoEngine"=-

              File::
              c:\windows\bthservsdp.dat
              c:\windows\system32\ezsidmv.dat
              c:\windows\bf5087.dat
              c:\windows\dk39fi4fe.dat
              c:\windows\bf23567.dat

              Folder::
              c:\programdata\13268674
              c:\programdata\19462744
              c:\users\Olive\AppData\Roaming\EoRez­o
              c:\program files\EoRezo

              - Ouvre le Bloc-Notes puis colle le texte copié.
              (Démarrer\Tous les programmes\Accessoires\Bloc notes.)

              - Sauvegarde ce fichier sous le nom de CFScript.txt

              - Glisse maintenant le fichier CFScript.txt dans Combofix.exe comme ceci

              Cela va relancer Combofix,

              Une fenêtre bleue va apparaître: au message qui apparaît ( Type 1 to continue, or 2 to abort) , tape 1 puis valide.

              Patiente le temps du scan.Le bureau va disparaître à plusieurs reprises: c'est normal!

              Ne touche à rien tant que le scan n'est pas terminé.

              Après redémarrage, poste le contenu du rapport Combofix.txt

              0
              1. Voici le rapport: (merci merci)

                ComboFix 09-06-22.0D - Olive 23/06/2009 17:47.1 - NTFSx86
                Microsoft® Windows Vista™ Édition Familiale Premium 6.0.6001.1.1252.33.1036.18.3070.1536 [GMT 2:00]
                Lancé depuis: c:\users\Olive\Desktop\maths\C-FIX.exe
                AV: AntiVirus Firewall 7.03 *On-access scanning disabled* (Updated) {E7512ED5-4245-4B4D-AF3A-382D3F313F15}
                FW: AntiVirus Firewall 7.03 *enabled* {D4747503-0346-49EB-9262-997542F79BF4}
                SP: AntiVirus Firewall 7.03 *disabled* (Updated) {0651C4B0-1D7E-4682-B965-2E9523C483A5}
                SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
                .

                (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
                .

                c:\$recycle.bin\S-1-5-21-2953666331-2871950449-2251577109-500
                c:\$recycle.bin\S-1-5-21-3983755986-1279600414-361464282-500
                c:\windows\system32\dAhXa1wYufU3ZRR.vbs
                c:\$recycle.bin\S-1-5-21-2953666331-2871950449-2251577109-500\desktop.ini
                c:\$recycle.bin\S-1-5-21-3983755986-1279600414-361464282-500\desktop.ini
                c:\users\Olive\AppData\Roaming\02000000a8b26d8e579C.manifest
                c:\users\Olive\AppData\Roaming\02000000a8b26d8e579O.manifest
                c:\users\Olive\AppData\Roaming\02000000a8b26d8e579P.manifest
                c:\users\Olive\AppData\Roaming\02000000a8b26d8e579S.manifest
                c:\windows\9g2234wesdf3dfgjf23
                c:\windows\system32\KBL.LOG
                c:\windows\zaponce53198.dat
                c:\windows\zaponce53290.dat
                D:\Desktop.ini

                .
                ((((((((((((((((((((((((((((( Fichiers créés du 2009-05-23 au 2009-06-23 ))))))))))))))))))))))))))))))))))))
                .

                2009-06-23 14:25 . 2009-06-23 14:25 48 ---ha-w- c:\windows\system32\ezsidmv.dat
                2009-06-21 09:44 . 2009-06-21 09:45 -------- d-----w- c:\program files\Ad-remover
                2009-06-21 09:18 . 2009-06-21 09:20 -------- d-----w- C:\GenProc
                2009-06-20 14:41 . 2009-06-20 14:42 -------- d-----w- c:\program files\trend micro
                2009-06-20 14:41 . 2009-06-20 14:42 -------- d-----w- C:\rsit
                2009-06-19 15:23 . 2008-06-20 01:14 97800 ----a-w- c:\windows\system32\infocardapi.dll
                2009-06-19 15:22 . 2008-06-20 01:14 105016 ----a-w- c:\windows\system32\PresentationCFFRasterizerNative_v0300.dll
                2009-06-19 15:22 . 2008-06-20 01:14 622080 ----a-w- c:\windows\system32\icardagt.exe
                2009-06-19 15:22 . 2008-06-20 01:14 43544 ----a-w- c:\windows\system32\PresentationHostProxy.dll
                2009-06-19 15:22 . 2008-06-20 01:14 11264 ----a-w- c:\windows\system32\icardres.dll
                2009-06-19 15:22 . 2008-06-20 01:14 781344 ----a-w- c:\windows\system32\PresentationNative_v0300.dll
                2009-06-19 15:22 . 2008-06-20 01:14 326160 ----a-w- c:\windows\system32\PresentationHost.exe
                2009-06-19 15:15 . 2008-07-27 18:03 96760 ----a-w- c:\windows\system32\dfshim.dll
                2009-06-19 15:15 . 2008-07-27 18:03 282112 ----a-w- c:\windows\system32\mscoree.dll
                2009-06-19 15:15 . 2008-07-27 18:03 41984 ----a-w- c:\windows\system32\netfxperf.dll
                2009-06-19 15:15 . 2008-07-27 18:03 158720 ----a-w- c:\windows\system32\mscorier.dll
                2009-06-19 15:14 . 2008-07-27 18:03 83968 ----a-w- c:\windows\system32\mscories.dll
                2009-06-14 15:52 . 2009-06-23 14:24 -------- d-----w- c:\programdata\13268674
                2009-06-14 15:29 . 2009-06-14 15:29 -------- d-----w- c:\programdata\19462744
                2009-06-14 15:20 . 2009-06-14 15:20 3257 ---h--w- c:\windows\bf5087.dat
                2009-06-14 14:02 . 2009-06-14 14:02 1 ----a-w- c:\windows\dk39fi4fe.dat
                2009-06-14 14:01 . 2009-06-14 14:01 1 ---h--w- c:\windows\bf23567.dat
                2009-06-11 10:20 . 2009-04-21 11:55 2033152 ----a-w- c:\windows\system32\win32k.sys
                2009-06-11 10:20 . 2009-04-23 12:42 636928 ----a-w- c:\windows\system32\localspl.dll
                2009-06-11 10:20 . 2009-04-23 12:43 784896 ----a-w- c:\windows\system32\rpcrt4.dll
                2009-06-11 10:20 . 2009-04-24 16:05 827904 ----a-w- c:\windows\system32\wininet.dll
                2009-06-11 10:19 . 2009-04-24 13:44 26624 ----a-w- c:\windows\system32\ieUnatt.exe
                2009-06-11 10:19 . 2009-04-24 16:02 78336 ----a-w- c:\windows\system32\ieencode.dll
                2009-06-09 07:38 . 2009-06-09 07:38 456304 ----a-w- c:\programdata\Google\Google Toolbar\Update\gtb65F6.tmp.exe

                .
                (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
                .
                2009-06-23 14:26 . 2009-01-25 20:33 -------- d-----w- c:\programdata\Google Updater
                2009-06-23 14:25 . 2008-12-25 14:15 -------- d-----w- c:\users\Olive\AppData\Roaming\skypePM
                2009-06-23 14:25 . 2008-12-27 15:56 -------- d-----w- c:\users\Olive\AppData\Roaming\EoRezo
                2009-06-23 14:24 . 2008-12-27 15:56 -------- d-----w- c:\program files\EoRezo
                2009-06-21 14:38 . 2008-07-24 05:55 12 ----a-w- c:\windows\bthservsdp.dat
                2009-06-20 14:41 . 2009-02-09 23:04 7592 ----a-w- c:\users\Olive\AppData\Local\d3d9caps.dat
                2009-06-19 16:21 . 2008-03-07 05:14 676592 ----a-w- c:\windows\system32\perfh00C.dat
                2009-06-19 16:21 . 2008-03-07 05:14 126880 ----a-w- c:\windows\system32\perfc00C.dat
                2009-06-19 16:20 . 2008-12-22 15:37 108248 ----a-w- c:\users\Olive\AppData\Local\GDIPFONTCACHEV1.DAT
                2009-06-19 15:41 . 2008-03-06 21:39 -------- d-----w- c:\programdata\Microsoft Help
                2009-06-14 17:05 . 2008-12-25 10:29 -------- d-----w- c:\users\Olive\AppData\Roaming\LimeWire
                2009-06-11 22:28 . 2008-03-06 21:17 -------- d-----w- c:\program files\Microsoft Works
                2009-06-11 06:12 . 2008-12-24 21:58 1915520 ----a-w- c:\users\Olive\AppData\Roaming\Macromedia\Flash Player\www.macromedia.com\bin\fpupdateax\fpupdateax.exe
                2009-06-03 22:21 . 2009-02-17 18:05 -------- d-----w- c:\users\Olive\AppData\Roaming\dvdcss
                2009-05-16 16:35 . 2009-05-10 13:14 -------- d-----w- c:\program files\RaybanMirror
                2009-05-10 16:42 . 2009-05-10 16:42 -------- d-----w- c:\users\Olive\AppData\Roaming\Fit3DLive
                2009-05-06 16:17 . 2008-12-25 14:13 -------- d-----w- c:\users\Olive\AppData\Roaming\Skype
                2009-04-26 10:43 . 2009-04-26 10:43 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdMtpDr_01_00_00.Wdf
                2009-04-26 10:29 . 2008-12-22 15:31 -------- d-----w- c:\users\Olive\AppData\Roaming\Hewlett-Packard
                2009-04-26 10:27 . 2009-04-26 10:27 -------- d-----w- c:\program files\Samsung
                2009-04-26 10:27 . 2008-03-06 20:36 -------- d--h--w- c:\program files\InstallShield Installation Information
                2009-04-26 10:27 . 2008-03-06 20:32 -------- d-----w- c:\program files\Hewlett-Packard
                .

                ((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
                .
                .
                *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
                REGEDIT4

                [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                "Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-21 1233920]
                "LightScribe Control Panel"="c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe" [2007-08-23 455968]
                "HPAdvisor"="c:\program files\Hewlett-Packard\HP Advisor\HPAdvisor.exe" [2007-10-01 1783136]
                "msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-02-06 3885408]
                "Skype"="c:\program files\Skype\Phone\Skype.exe" [2008-11-18 21633320]
                "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-01-25 39408]
                "ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952]
                "WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240]

                [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                "NvSvc"="c:\windows\system32\nvsvc.dll" [2007-09-19 86016]
                "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-09-19 8497696]
                "NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-09-19 81920]
                "Apoint"="c:\program files\Apoint2K\Apoint.exe" [2007-03-11 159744]
                "IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2007-07-25 174616]
                "QPService"="c:\program files\HP\QuickPlay\QPService.exe" [2007-12-19 468264]
                "QlbCtrl"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2007-09-19 202032]
                "OnScreenDisplay"="c:\program files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exe" [2007-09-04 554320]
                "UCam_Menu"="c:\program files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" [2007-08-16 218408]
                "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 40048]
                "HP Software Update"="c:\program files\Hp\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
                "hpWirelessAssistant"="c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2007-09-13 480560]
                "WAWifiMessage"="c:\program files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe" [2007-01-08 311296]
                "SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_02\bin\jusched.exe" [2007-07-12 132496]
                "F-Secure Manager"="c:\program files\Orange\AntivirusFirewall\Common\FSM32.EXE" [2008-04-23 182936]
                "F-Secure TNB"="c:\program files\Orange\AntivirusFirewall\FSGUI\TNBUtil.exe" [2008-04-23 744032]
                "EoEngine"="c:\program files\EoRezo\EoEngine.exe" [2009-02-23 472872]
                "ORAHSSSessionManager"="c:\program files\OrangeHSS\SessionManager\SessionManager.exe" [2007-12-12 107248]
                "fssui"="c:\program files\Windows Live\Family Safety\fsui.exe" [2009-02-06 454000]

                [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
                "SoftwareHelper"="c:\users\Olive\AppData\Roaming\eoRezo\SoftwareUpdate\SoftwareUpdateHP.exe" [2008-12-09 368224]

                c:\users\Olive\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
                Outil de notification Live Search.lnk - c:\users\Olive\AppData\Roaming\Microsoft\Live Search\Notification-LiveSearch.exe [2008-12-26 143360]

                c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
                BTTray.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2007-9-5 727592]

                [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
                "EnableLUA"= 0 (0x0)
                "EnableUIADesktopToggle"= 0 (0x0)

                [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
                "aux"=wdmaud.drv

                [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
                @="Service"

                [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
                "DisableMonitoring"=dword:00000001

                [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
                "DisableMonitoring"=dword:00000001

                [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
                "DisableMonitoring"=dword:00000001

                [HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
                "EnableFirewall"= 0 (0x0)

                [HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
                "{F986AD45-3D68-4EB9-BD40-DC5B96B86266}"= UDP:c:\program files\Common Files\AOL\Loader\aolload.exe:AOL Loader
                "{CC97F759-633E-4B96-99BA-F2BACDCC0198}"= TCP:c:\program files\Common Files\AOL\Loader\aolload.exe:AOL Loader
                "{6320805D-B0B6-4E2D-A635-BBB1EF5FE9B3}"= c:\program files\Cyberlink\PowerDirector\PDR.EXE:CyberLink PowerDirector
                "{2648016C-1312-4404-BDE4-786B2B6E4468}"= c:\program files\HP\QuickPlay\QP.exe:Quick Play
                "{A73EB178-FD4A-4406-9387-FC99093F7CE1}"= c:\program files\HP\QuickPlay\QPService.exe:Quick Play Resident Program
                "{4D2CBDDB-9E8C-4686-B628-E91E2CBB931F}"= c:\program files\Skype\Phone\Skype.exe:Skype
                "{85097506-13B2-47F9-8C38-03CEF85087A3}"= TCP:6004|c:\program files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook
                "{868E96A5-C673-4BD8-A750-F6ED88B230F2}"= c:\program files\Windows Live\Sync\WindowsLiveSync.exe:Windows Live Sync

                [HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
                "EnableFirewall"= 0 (0x0)

                [HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
                "EnableFirewall"= 0 (0x0)

                [HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List]
                "c:\\Program Files\\OrangeHSS\\Connectivity\\ConnectivityManager.exe"= c:\program files\OrangeHSS\Connectivity\ConnectivityManager.exe:*:enabled:CSS

                R1 F-Secure HIPS;F-Secure HIPS;c:\program files\Orange\AntivirusFirewall\HIPS\fshs.sys [23/12/2008 15:42 41184]
                R1 FSES;F-Secure Email Scanning Driver;c:\windows\System32\drivers\fses.sys [23/12/2008 15:42 34752]
                R1 FSFW;F-Secure Firewall Driver;c:\windows\System32\drivers\fsdfw.sys [23/12/2008 15:42 60064]
                R1 fsvista;F-Secure Vista Support Driver;c:\program files\Orange\AntivirusFirewall\Anti-Virus\minifilter\fsvista.sys [23/12/2008 15:41 12896]
                R2 fssfltr;FssFltr;c:\windows\System32\drivers\fssfltr.sys [26/12/2008 21:22 55264]
                R2 fsssvc;Windows Live Contrôle parental;c:\program files\Windows Live\Family Safety\fsssvc.exe [06/02/2009 19:08 533360]
                R3 F-Secure Gatekeeper;F-Secure Gatekeeper;c:\program files\Orange\AntivirusFirewall\Anti-Virus\minifilter\fsgk.sys [23/12/2008 15:41 62048]
                S3 PCAMp50;PCAMp50 NDIS Protocol Driver;c:\windows\System32\drivers\PCAMp50.sys [17/02/2009 14:41 28224]
                S4 F-Secure Filter;F-Secure File System Filter;c:\program files\Orange\AntivirusFirewall\Anti-Virus\win2k\fsfilter.sys [23/12/2008 15:41 39776]
                S4 F-Secure Recognizer;F-Secure File System Recognizer;c:\program files\Orange\AntivirusFirewall\Anti-Virus\win2k\fsrec.sys [23/12/2008 15:41 25184]

                [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
                bthsvcs REG_MULTI_SZ BthServ

                [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
                "c:\program files\Common Files\LightScribe\LSRunOnce.exe"
                .
                Contenu du dossier 'Tâches planifiées'

                2009-06-23 c:\windows\Tasks\Google Software Updater.job
                - c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-12-25 17:53]

                2009-06-23 c:\windows\Tasks\User_Feed_Synchronization-{EACA1F9D-7DA9-463A-A478-B21C79F75452}.job
                - c:\windows\system32\msfeedssync.exe [2008-01-21 02:24]
                .
                - - - - ORPHELINS SUPPRIMES - - - -

                HKLM-Run-HP Health Check Scheduler - [ProgramFilesFolder]Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
                HKLM-Run-sysfbtray - c:\windows\freddy46.exe
                HKLM-Run-19462744 - c:\programdata\19462744\19462744.exe
                HKLM-Run-13268674 - c:\programdata\13268674\13268674.exe

                .
                ------- Examen supplémentaire -------
                .
                uStart Page = hxxp://y.lo.st
                mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=fr_fr&c=81&bd=Pavilion&pf=laptop
                IE: &Recherche AOL Toolbar - c:\program files\aol\aol toolbar 5.0\resources\fr-fr\local\search.html
                IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
                IE: Envoyer au périphérique &Bluetooth... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
                IE: Envoyer l'&image au périphérique Bluetooth... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
                LSP: c:\program files\Orange\AntivirusFirewall\FSPS\program\FSLSP.DLL
                .

                **************************************************************************

                catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
                Rootkit scan 2009-06-23 17:51
                Windows 6.0.6001 Service Pack 1 NTFS

                Recherche de processus cachés ...

                Recherche d'éléments en démarrage automatique cachés ...

                Recherche de fichiers cachés ...

                Scan terminé avec succès
                Fichiers cachés: 0

                **************************************************************************
                .
                --------------------- CLES DE REGISTRE BLOQUEES ---------------------

                [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
                @Denied: (A) (Users)
                @Denied: (A) (Everyone)
                @Allowed: (B 1 2 3 4 5) (S-1-5-20)
                "BlindDial"=dword:00000000
                .
                Heure de fin: 2009-06-23 17:53
                ComboFix-quarantined-files.txt 2009-06-23 15:53

                Avant-CF: 211 412 193 280 octets libres
                Après-CF: 212 312 358 912 octets libres

                211 --- E O F --- 2009-06-23 14:30
                0
                1. Bonjour,
                  Je viens de rallumer mon ordinateur et les programmes peuvent enfin s'ouvrire, je decouvre vos nouveaux messages et vous remercies; en revanche rien ne me prouve que le virus n'est plus sur l'ordinateur (il ne s'est surement pas envolé) donc je suis un peu perdue avec vos nombreuses reponses et ne sais laquelle dois je suivre. Merci d'avance
                  0
                  1. Contributeur sécurité
                    Re,

                    le post 32 ne mènera à rien.

                    faire supprimer des données issues de gmer sans les avoir examinées est hallucinant.

                    Il faut renommer les outils au moment de l'ouverture de la fenêtre qui demande de fournir les paramètres du téléchargement. Les renommer après ne fonctionne pas. Les canned speech sont très imprécis sur ce point.
                    0
                    1. Contributeur sécurité
                      Salut lyonnais,

                      Merci pour ta réactivité , on va essayer de renommer comme tu dis ;)

                      Fais un clic droit sur ce lien http://download.bleepingcomputer.com/sUBs/ComboFix.exe

                      Choisis enregistrer la cible du lien sous:

                      Dans nom de fichier, tu choisis le nom suivant: C-FIX.exe

                      Ensuite clique sur "enregistrer".

                      /!\ Outil très puissant,sachez qu'une mauvaise utilisation du programme pourrait entraîner des problèmes dans le fonctionnement normal de votre ordinateur /!\


                      ============> A lire, Impératif <============

                      AVANT d'utiliser ComboFix :

                      ▶ /!\ Déconnecte ton PC d'Internet et referme les fenêtres de tous les programmes en cours. /!\
                      ▶ (!) Désactive provisoirement (et seulement le temps de l'utilisation de ComboFix), la protection en temps réel de ton Antivirus et de tes Antispywares et de TOUT tes logiciels de protection (!).


                      ▶ Double clique sur C-Fix.exe afin de le lancer (Sous Vista: Clique droit et choisir exécuter en tant qu'administrateur")

                      ▶ Appuies sur la touche 1, pour que le programme commence à s'exécuter et suit les instructions à l'écran

                      ▶ Si il te demande d'installer la console de récupération, Accepte. En cas de problémes d'installation: tuto

                      */!\ Ne touche a rien pendant le scan /!\

                      ▶ Si il te demande de redémarrer , accepte

                      ▶ Après le redémarrage du PC, un rapport s'ouvrira dans le Bloc notes en fin d'analyse, copie et colle le dans ton a ta prochaine réponse


                      (Le fichier rapport Combofix.txt , est ensuite automatiquement sauvegardé dans C:\Combofix.txt)

                      A+ et merci a lyonnais pour la remarque :)

                      ++
                      0
                  2. bonjour
                    je ne suis pas du tout une experte mais j'ai eu le même probleme il ya qq jours et je devais demarrer en mode sans echec avec prise en charge reseau, c'est le seul moyen de pouvoir faire qq chose car en effet le virus bloque tout le pc
                    ensuite j'ai suivi les instruction d'un helpeur et maintenant tout est rentré ds l'ordre

                    bon courage
                    0
                    1. J'abandonne pour aujourd'hui, je vous dis un grand merci pour votre aide et votre patience; je me replonge dans le problème dans la semaine.
                      0
                      1. Contributeur sécurité
                        OK, j'attends,

                        Essaye ceci:

                        Télécharge SDFix de andymanchesta

                        Laisse le te guider...

                        • Après l'installation ,redémarre en mode sans échec

                        • Sous XP: fais un double clique sur: C:\SDFix\RunThis.bat
                        Sous Vista: fais un clic droit sur C:\SDFix\RunThis.bat et choisis "exécuter en tant qu'administrateur"

                        • Appuye sur la touche Y pour commencer le processus de nettoyage.

                        Il va supprimer les services et les entrées du Registre de certains trojans trouvés puis te demandera d'appuyer sur une touche pour redémarrer.

                        • Appuie sur une touche pour redémarrer le PC.

                        • Ton système sera plus long pour redémarrer qu'à l'accoutumée car l'outil va continuer à s'exécuter et supprimer des fichiers.

                        • Après le chargement du Bureau, l'outil terminera son travail et affichera Finished.

                        • Appuie sur une touche pour finir l'exécution du script et charger les icônes de ton Bureau.

                        • Les icônes du Bureau affichées, le rapport SDFix s'ouvrira à l'écran et s'enregistrera aussi dans le dossier SDFix sous le nom Report.txt.

                        • Enfin, copie/colle le contenu du fichier Report.txt dans ta prochaine réponse sur le forum

                        Si SDfix ne se lance pas (ça arrive)
                        * Démarrer->Exécuter
                        * Copie/colle ceci dans la fenêtre :

                        %systemroot%\system32\cmd.exe /K %systemdrive%\SDFix\apps\FixPath.exe

                        * patiente le temps du scan...

                        tutoriel SDFix

                        A+ , et bon courage
                        0
                    2. Toujours le même problème, le virus empêche son ouverture.
                      0
                      1. Contributeur sécurité
                        Tu double clique sur "Gmer.exe"

                        Je pense qu'il ya des rootkit, suis exactement les instructions.

                        0
                        1. Ne pas se moquer même si je l'accorde je ne suis pas douée.. enfin j'ai extrais et on me presente toujour un dossier gmer (le signe n'est plus une pochette avec un zip :) ) mais je ne voi pas de rootkit.
                          0
                          1. Contributeur sécurité
                            Comment on dezipe??? et ou est rootkit?

                            La, je vois que tu n'est vraiment pas doué(e) ...

                            Clic droit >> Extraire tout >> laisse le te guider. ...
                            0
                            1. Comment on dezipe??? et ou est rootkit?
                              0
                              1. Contributeur sécurité
                                Voir en haut:

                                Dézippes gmer ,cliques sur l'onglet rootkit,lances le scan,des lignes rouges vont apparaitre.

                                Les lignes rouges indiquent la présence d'un rootkit.Postes moi le rapport gmer (cliques sur copy,puis vas dans démarrer ,puis ouvres le bloc note,vas dans édition et cliques sur coller,le rapport gmer va apparaitre,postes moi le)

                                Ensuite

                                sur les lignes rouge:

                                Services:cliques droit delete service
                                Process:cliques droit kill process
                                Adl ,file:cliques droit delete files

                                ensuite reposte un nouveau log RSIT pour le contrôle ...

                                ++
                                0
                                1. Gmer s'ouvre !!!! Je dois en faire quoi vu que je n'ai pas ouvert OTM ?
                                  0
                                  1. Contributeur sécurité
                                    Essaye Gmer .

                                    :'/
                                    0
                                    • 1
                                    • 2
                                    • 3