Hijack.Windowsupdates

Bonjour, après un scan MBAM, je trouve des clés de registre infectées, je décide donc de supprimer sauf qu'une fois une nouvelle analyse lancée, je retrouve encore et toujours les mêmes fichiers infectés. Si quelqu'un a une explication ou une solution... Je tiens aussi à signaler que sans la suppression des clés de registre, certains de mes logiciels ne fonctionnent plus, ainsi je ne peux plus avoir accès au centre de sécurité de Windows, de même pour Hijackthis. Par contre, une fois avoir supprimé les fichiers, j'ai re accès à Hijackthis mais toujours pas au centre de sécurité. A chaque démarrage de mon ordinateur, les fichiers infectés reviennent et je n'ai plus accès à Hijackthis etc.

Scan MBAM:

Malwarebytes' Anti-Malware 1.40
Version de la base de données: 2701
Windows 5.1.2600 Service Pack 3

28/08/2009 15:01:15
mbam-log-2009-08-28 (15-01-15).txt

Type de recherche: Examen rapide
Eléments examinés: 143566
Temps écoulé: 7 minute(s), 51 second(s)

Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 0
Clé(s) du Registre infectée(s): 90
Valeur(s) du Registre infectée(s): 0
Elément(s) de données du Registre infecté(s): 5
Dossier(s) infecté(s): 0
Fichier(s) infecté(s): 0

Processus mémoire infecté(s):
(Aucun élément nuisible détecté)

Module(s) mémoire infecté(s):
(Aucun élément nuisible détecté)

Clé(s) du Registre infectée(s):
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\A2SERVICE.exe (Security.Hijack) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ArcaCheck.exe (Security.Hijack) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\arcavir.exe (Security.Hijack) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashDisp.exe (Security.Hijack) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashEnhcd.exe (Security.Hijack) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashServ.exe (Security.Hijack) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashUpd.exe (Security.Hijack) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\aswUpdSv.exe (Security.Hijack) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\autoruns.exe (Security.Hijack) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avadmin.exe (Security.Hijack) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avcenter.exe (Security.Hijack) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avcls.exe (Security.Hijack) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avconfig.exe (Security.Hijack) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AVCONSOL.exe (Security.Hijack) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AVGNT.exe (Security.Hijack) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgrssvc.exe (Security.Hijack) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AVGUARD.exe (Security.Hijack) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AvMonitor.exe (Security.Hijack) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avp.com (Security.Hijack) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avp.exe (Security.Hijack) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AVP32.exe (Security.Hijack) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AVSCAN.exe (Security.Hijack) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avz.exe (Security.Hijack) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avz_se.exe (Security.Hijack) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avz4.exe (Security.Hijack) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bdAgent.exe (Security.Hijack) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bdinit.exe (Security.Hijack) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\caav.exe (Security.Hijack) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\caavguiscan.exe (Security.Hijack) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\CASecurityCENTER.exe (Security.Hijack) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\CCenter.exe (Security.Hijack) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ccupdate.exe (Security.Hijack) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\cfp.exe (Security.Hijack) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\cfpupdat.exe (Security.Hijack) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\cmdAgent.exe (Security.Hijack) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\drwadins.exe (Security.Hijack) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DRWEB32.exe (Security.Hijack) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\drwebupw.exe (Security.Hijack) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ekrn.exe (Security.Hijack) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\FAMEH32.exe (Security.Hijack) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\filemon.exe (Security.Hijack) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\FPAVSERVER.exe (Security.Hijack) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\fpscan.exe (Security.Hijack) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\FPWIN.exe (Security.Hijack) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\FSAV32.exe (Security.Hijack) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\FSGK32ST.exe (Security.Hijack) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\FSMA32.exe (Security.Hijack) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\GFRing3.exe (Security.Hijack) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\guardgui.exe (Security.Hijack) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\guardxservice.exe (Security.Hijack) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\guardxup.exe (Security.Hijack) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\HijackThis.exe (Security.Hijack) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KASMain.exe (Security.Hijack) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KASTask.exe (Security.Hijack) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KAV32.exe (Security.Hijack) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KAVDX.exe (Security.Hijack) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KAVPF.exe (Security.Hijack) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KAVPFW.exe (Security.Hijack) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KavStart.exe (Security.Hijack) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KPFW32.exe (Security.Hijack) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KPFW32X.exe (Security.Hijack) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Navapsvc.exe (Security.Hijack) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Navapw32.exe (Security.Hijack) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\navigator.exe (Security.Hijack) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\NAVNT.exe (Security.Hijack) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\NAVSTUB.exe (Security.Hijack) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\navw32.exe (Security.Hijack) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\NAVWNT.exe (Security.Hijack) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\niu.exe (Security.Hijack) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\nod32.exe (Security.Hijack) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\nod32krn.exe (Security.Hijack) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Nvcc.exe (Security.Hijack) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\OllyDBG.exe (Security.Hijack) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\outpost.exe (Security.Hijack) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\preupd.exe (Security.Hijack) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\procexp.exe (Security.Hijack) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\pskdr.exe (Security.Hijack) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\regedit.exe (Security.Hijack) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\regmon.exe (Security.Hijack) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\regtool.exe (Security.Hijack) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SCAN32.exe (Security.Hijack) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SfFnUp.exe (Security.Hijack) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Vba32arkit.exe (Security.Hijack) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\vba32ldr.exe (Security.Hijack) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\vsserv.exe (Security.Hijack) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Zanda.exe (Security.Hijack) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\zapro.exe (Security.Hijack) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Zlh.exe (Security.Hijack) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ZONEALARM.exe (Security.Hijack) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\zoneband.dll (Security.Hijack) -> Quarantined and deleted successfully.

Valeur(s) du Registre infectée(s):
(Aucun élément nuisible détecté)

Elément(s) de données du Registre infecté(s):
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\wuauserv\ImagePath (Hijack.WindowsUpdates) -> Bad: (%fystemroot%\system32\svchost.exe -k netsvcs) Good: (%SystemRoot%\System32\svchost.exe -k netsvcs) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\BITS\ImagePath (Hijack.WindowsUpdates) -> Bad: (%fystemRoot%\system32\svchost.exe -k netsvcs) Good: (%SystemRoot%\System32\svchost.exe -k netsvcs) -> Quarantined and deleted successfully.

Dossier(s) infecté(s):
(Aucun élément nuisible détecté)

Fichier(s) infecté(s):
(Aucun élément nuisible détecté)

Hijackthis:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 15:02:12, on 28/08/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTBCM\Binn\sqlservr.exe
C:\Program Files\Sunbelt Software\Personal Firewall\SbPFLnch.exe
C:\Program Files\Sunbelt Software\Personal Firewall\SbPFSvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Sunbelt Software\Personal Firewall\SbPFCl.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe
C:\Program Files\Creative\SBAudigy2ZS\DVDAudio\CTDVDDET.EXE
C:\WINDOWS\system32\CTHELPER.EXE
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\Program Files\Dell\Media Experience\DMXLauncher.exe
C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\Samsung\SmarThru\PORTCTRL.EXE
C:\Program Files\Logitech\Video\LogiTray.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\PROGRA~1\HEWLET~1\HPSHAR~1\hpgs2wnf.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\Program Files\Logitech\Video\FxSvr2.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe
C:\Program Files\SAGEM Wi-Fi USB 802.11g\WLANUTL.exe
C:\Program Files\CASIO\Photo Loader\Plauto.exe
C:\Program Files\OpenOffice.org 2.1\program\soffice.exe
C:\Program Files\OpenOffice.org 2.1\program\soffice.BIN
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\BitComet\BitComet.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Windows Media Player\wmplayer.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\winmine.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.orange.fr/portail
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://www.dell.com/fr-fr
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local;localhost
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (file missing)
O2 - BHO: BitComet ClickCapture - {39f7e362-828a-4b5a-bcaf-5b79bfdfea60} - C:\Program Files\BitComet\tools\BitCometBHO_1.3.3.2.dll
O2 - BHO: (no name) - {4D25F921-B9FE-4682-BF72-8AB8210D6D75} - (no file)
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll
O2 - BHO: (no name) - {C4CE8A0F-DB1C-4993-8D49-C23ABE041418} - (no file)
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Veoh Web Player Video Finder - {0FBB9689-D3D7-4f7a-A2E2-585B10099BFC} - C:\Program Files\Veoh Networks\VeohWebPlayer\VeohIEToolbar.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [IntelMeM] C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe /r
O4 - HKLM\..\Run: [CTDVDDET] "C:\Program Files\Creative\SBAudigy2ZS\DVDAudio\CTDVDDET.EXE"
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\FICHIE~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [GW Port Controller] C:\Program Files\Samsung\SmarThru\PORTCTRL.EXE
O4 - HKLM\..\Run: [LogitechGalleryRepair] C:\Documents and Settings\rémy\Mes documents\Perso\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
O4 - HKLM\..\RunOnce: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Documents and Settings\rémy\Mes documents\Perso\ManifestEngine.exe" boot
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1
O4 - HKCU\..\Run: [VeohPlugin] "C:\Program Files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: OpenOffice.org 2.1.lnk = C:\Program Files\OpenOffice.org 2.1\program\quickstart.exe
O4 - Global Startup: dlbcserv.lnk = C:\Program Files\Dell Photo Printer 720\dlbcserv.exe
O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Sagem - Utilitaire réseau pour Clé USB Wi-Fi 802.11g.lnk = ?
O4 - Global Startup: Supervision de Photo Loader.lnk = C:\Program Files\CASIO\Photo Loader\Plauto.exe
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Tout télécharger avec BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
O8 - Extra context menu item: Télécharger avec BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
O8 - Extra context menu item: Télécharger toutes les vidéos avec BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: BitComet - {d18a0b52-d63c-4ed0-afc6-c1e3dc1af43a} - res://C:\Program Files\BitComet\tools\BitCometBHO_1.3.3.2.dll/206 (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {3EA4FA88-E0BE-419A-A732-9B79B87A6ED0} (CTVUAxCtrl Object) - http://dl.tvunetworks.com/TVUAx.cab
O16 - DPF: {5C051655-FCD5-4969-9182-770EA5AA5565} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab56986.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: vvukvh.dll
O20 - Winlogon Notify: awturSkL - awturSkL.dll (file missing)
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Service de transfert intelligent en arrière-plan (BITS) - Unknown owner - C:\WINDOWS\
O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Explorateur d'ordinateur BrowserNetman (BrowserNetman) - Unknown owner - C:\WINDOWS\system32\12520437n.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMon) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: SbPF.Launcher - Sunbelt Software, Inc. - C:\Program Files\Sunbelt Software\Personal Firewall\SbPFLnch.exe
O23 - Service: SolidWorks Licensing Service - SolidWorks - C:\Program Files\Fichiers communs\SolidWorks Shared\Service\SolidWorksLicensing.exe
O23 - Service: Sunbelt Personal Firewall 4 (SPF4) - Sunbelt Software, Inc. - C:\Program Files\Sunbelt Software\Personal Firewall\SbPFSvc.exe
O23 - Service: Mises à jour automatiques (wuauserv) - Unknown owner - C:\WINDOWS\

--
End of file - 14062 bytes

Merci.

23 réponses

Résumé de la discussion

La description présente une infection persistante après un scan Malwarebytes Anti-Malware, où des clés de registre infectées permettent l'exécution d'applications via Image File Execution Options et perturbent le Centre de sécurité Windows. Les entrées observées dans HijackThis et les modifications de registre montrent des valeurs liées à Image File Execution Options et des paramètres désactivant ou masquant le centre de sécurité et l'antivirus. Pour y répondre, les conseils préconisent une analyse en mode sans échec, la quarantaine et suppression des artefacts détectés, puis le rétablissement des paramètres système afin d'éviter les réinfections. En cas d'échec, certains évoquent une réinstallation propre du système pour garantir l'élimination complète des composants tenaces.

Bobot (l’IA à votre service)
  1. Contributeur sécurité
    Bonsoir,

    désolé mais je suis en plein travaux de déménagement pour le moment...

    refais un nouveau rapport RSIT stp
    1. .
      ======= RAPPORT D'AD-REMOVER 1.1.4.5_R | UNIQUEMENT XP/VISTA/SEVEN =======
      .
      Mit à jour par C_XX le 31/08/2009 à 8:30 PM
      Contact: AdRemover.contact@gmail.com
      Site web: http://pagesperso-orange.fr/NosTools/ad_remover.html
      .
      Lancé à: 12:42:37, 06/09/2009 | Mode Normal | Option: CLEAN
      Exécuté de: C:\Program Files\Ad-remover\
      Système d'exploitation: Microsoft® Windows XP™ v5.1.2600
      Nom du PC: | Utilisateur actuel: r‚my
      .
      .
      ============== ÉLÉMENT(S) NEUTRALISÉ(S) ==============
      .
      .
      .
      C:\Documents and Settings\mankhen\Cookies\mankhen@dellfr.myway[1].txt
      C:\Documents and Settings\mankhen\Cookies\mankhen@myway[1].txt

      (!) -- Fichiers temporaires supprimés.

      .
      ============== Scan additionnel ==============
      .
      .
      * Mozilla FireFox Version 3.5.2 *
      .
      Nom du profil: 59h6pnha.default (r‚my)
      .
      (Prefs.js) user_pref("browser.search.defaultenginename", "Google");
      (Prefs.js) user_pref("browser.search.defaulturl", "hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=");
      (Prefs.js) user_pref("browser.startup.homepage", "hxxp://www.orange.fr/");
      (Prefs.js) user_pref("browser.startup.homepage_override.mstone", "rv:1.9.1.2");
      .
      .
      .
      * Internet Explorer Version 8.0.6001.18702 *
      .
      [HKEY_CURRENT_USER\..\Internet Explorer\Main]
      .
      Start Page: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
      Search Page: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
      Default_search_url: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
      Default_page_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
      Search bar: hxxp://go.microsoft.com/fwlink/?linkid=54896
      .
      [HKEY_LOCAL_MACHINE\..\Internet Explorer\Main]
      .
      Default_Page_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
      Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
      Search Page: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
      Start Page: hxxp://fr.msn.com/
      Search bar: hxxp://search.msn.com/spbasic.htm
      HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\main\Start Page
      .
      [HKEY_LOCAL_MACHINE\..\Internet Explorer\ABOUTURLS]
      .
      Tabs: res://ieframe.dll/tabswelcome.htm
      .
      ============== Suspect (Cracks, Serials ... ) ==============
      .
      C:\Documents and Settings\r‚my\Mes documents\R‚my Jeux\SACRED\keygen.exe
      .
      .
      ===================================
      .
      2409 Octet(s) - C:\Ad-Report-CLEAN.log
      2327 Octet(s) - C:\Ad-Report-SCAN.log
      .
      46 Fichier(s) - C:\DOCUME~1\RMY~1\LOCALS~1\Temp
      2 Fichier(s) - C:\WINDOWS\Temp
      .
      18 Fichier(s) - C:\Program Files\Ad-remover\BACKUP
      2 Fichier(s) - C:\Program Files\Ad-remover\QUARANTINE
      .
      Fin à: 14:08:42 | 06/09/2009
      .
      ============== E.O.F ==============
      .
      1. Contributeur sécurité
        Bonjour,

        désolé pour le retard...

        ! Déconnectes toi et fermes toutes applications en cours !

        ● tutoriel nettoyage

        ● Relances "Ad-remover" : au menu principal choisi l'option "L" .

        ● Laisse travailler l'outil et ne touche plus à rien

        ● Postes le rapport qui apparait à la fin.

        ( le rapport est sauvegardé aussi sous C:\Ad-report(date).log )

        (CTRL+A Pour tout selectionner , CTRL+C pour copier et CTRL+V pour coller )

        /!\ Si le Bureau ne réapparait pas presse Ctrl + Alt + Suppr , Onglet "Fichier" , "Nouvelle tâche" , tapes explorer.exe et valides)
        1. .
          ======= RAPPORT D'AD-REMOVER 1.1.4.5_R | UNIQUEMENT XP/VISTA/SEVEN =======
          .
          Mit à jour par C_XX le 31/08/2009 à 8:30 PM
          Contact: AdRemover.contact@gmail.com
          Site web: http://pagesperso-orange.fr/NosTools/ad_remover.html
          .
          Lancé à: 14:30:27, 01/09/2009 | Mode Normal | Option: SCAN
          Exécuté de: C:\Program Files\Ad-remover\
          Système d'exploitation: Microsoft® Windows XP™ v5.1.2600
          Nom du PC: | Utilisateur actuel: r‚my
          .
          .
          ============== ÉLÉMENT(S) TROUVÉ(S) ==============
          .
          .
          .
          C:\Documents and Settings\mankhen\Cookies\mankhen@dellfr.myway[1].txt
          C:\Documents and Settings\mankhen\Cookies\mankhen@myway[1].txt
          .
          ============== Scan additionnel ==============
          .
          .
          * Mozilla FireFox Version 3.5.2 *
          .
          Nom du profil: 59h6pnha.default (r‚my)
          .
          (Prefs.js) user_pref("browser.search.defaultenginename", "Google");
          (Prefs.js) user_pref("browser.search.defaulturl", "hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=");
          (Prefs.js) user_pref("browser.startup.homepage", "hxxp://www.orange.fr/");
          (Prefs.js) user_pref("browser.startup.homepage_override.mstone", "rv:1.9.1.2");
          .
          .
          .
          * Internet Explorer Version 8.0.6001.18702 *
          .
          [HKEY_CURRENT_USER\..\Internet Explorer\Main]
          .
          Start Page: hxxp://orange.fr/
          Search Page: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
          .
          [HKEY_LOCAL_MACHINE\..\Internet Explorer\Main]
          .
          Default_Page_URL: hxxp://go.microsoft.com/fwlink/?LinkId=69157
          Default_Search_URL: hxxp://go.microsoft.com/fwlink/?LinkId=54896
          Search Page: hxxp://go.microsoft.com/fwlink/?LinkId=54896
          Start Page: hxxp://go.microsoft.com/fwlink/?LinkId=69157
          HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\main\Start Page
          .
          [HKEY_LOCAL_MACHINE\..\Internet Explorer\ABOUTURLS]
          .
          Tabs: res://ieframe.dll/tabswelcome.htm
          .
          ============== Suspect (Cracks, Serials ... ) ==============
          .
          C:\Documents and Settings\r‚my\Mes documents\R‚my Jeux\SACRED\keygen.exe
          .
          .
          ===================================
          .
          2016 Octet(s) - C:\Ad-Report-SCAN.log
          .
          12 Fichier(s) - C:\DOCUME~1\RMY~1\LOCALS~1\Temp
          2 Fichier(s) - C:\WINDOWS\Temp
          .
          0 Fichier(s) - C:\Program Files\Ad-remover\BACKUP
          0 Fichier(s) - C:\Program Files\Ad-remover\QUARANTINE
          .
          Fin à: 15:55:51 | 01/09/2009
          .
          ============== E.O.F ==============
          .
          1. Contributeur sécurité
            Bonjour,

            ok maintenant :

            ▶ Télécharge et enregistre le fichier d installation de AD-Remover sur ton bureau :

            http://sd-1.archive-host.com/membres/up/16506160323759868/AD-R.exe

            ▶ tutoriel installation

            ▶ tutoriel recherche

            /!\ Ne fait pas le nettoyage tout dessuite /!\

            ▶ Double clique sur le programme d'installation , et installe le dans son emplacement par défaut.

            ▶ Ouvre le dossier Ad-remover présent sur ton bureau

            ▶ Double clique sur Ad-remover.bat.

            * Sous Vista : clic droit sur AD-Remover et sélectionner "Exécuter en tant qu'administrateur"

            ▶ Au menu principal choisi l'option "S"

            ▶ Poste le rapport qui apparait à la fin.

            ( le rapport est sauvegardé aussi sous C:\Ad-report.log )

            (CTRL+A Pour tout selectionner , CTRL+C pour copier et CTRL+V pour coller )

            Note :

            Process.exe est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool.
            Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.
            Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall...) d'où l'alerte émise par ces antivirus.
            1. Pendant le lancement de Combofix, je n'ai pas eu accès à l'installation de la console de récupération donc j'ai pas pu l'installer :S

              ComboFix 09-08-31.03 - rémy 01/09/2009 11:11.1.2 - NTFSx86
              Microsoft Windows XP Professionnel 5.1.2600.3.1252.33.1036.18.1022.440 [GMT 2:00]
              Running from: c:\documents and settings\rémy\Bureau\Remy Musique\ComboFix.exe
              AV: AntiVir Desktop *On-access scanning disabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}
              FW: Sunbelt Personal Firewall *enabled* {82B1150E-9B37-49FC-83EB-D52197D900D0}

              WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
              .

              ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
              .

              c:\documents and settings\christophe\Application Data\Dossier de téléchargement Share-to-Web
              c:\documents and settings\Cindy\Application Data\Dossier de téléchargement Share-to-Web
              c:\documents and settings\inteco\Application Data\Dossier de téléchargement Share-to-Web
              c:\documents and settings\LocalService\Application Data\Dossier de téléchargement Share-to-Web
              c:\documents and settings\mankhen\Application Data\Dossier de téléchargement Share-to-Web
              c:\documents and settings\pse-ms\Application Data\Dossier de téléchargement Share-to-Web
              c:\windows\Installer\54442.msi
              c:\windows\system32\_006312_.tmp.dll
              c:\windows\system32\_006313_.tmp.dll
              c:\windows\system32\_006314_.tmp.dll
              c:\windows\system32\_006315_.tmp.dll
              c:\windows\system32\_006322_.tmp.dll
              c:\windows\system32\_006323_.tmp.dll
              c:\windows\system32\_006324_.tmp.dll
              c:\windows\system32\_006325_.tmp.dll
              c:\windows\system32\_006327_.tmp.dll
              c:\windows\system32\_006328_.tmp.dll
              c:\windows\system32\_006331_.tmp.dll
              c:\windows\system32\_006332_.tmp.dll
              c:\windows\system32\_006334_.tmp.dll
              c:\windows\system32\_006335_.tmp.dll
              c:\windows\system32\_006336_.tmp.dll
              c:\windows\system32\_006338_.tmp.dll
              c:\windows\system32\_006341_.tmp.dll
              c:\windows\system32\_006342_.tmp.dll
              c:\windows\system32\_006346_.tmp.dll
              c:\windows\system32\_006347_.tmp.dll
              c:\windows\system32\_006349_.tmp.dll
              c:\windows\system32\_006352_.tmp.dll
              c:\windows\system32\_006354_.tmp.dll
              c:\windows\system32\_006355_.tmp.dll
              c:\windows\system32\_006356_.tmp.dll
              c:\windows\system32\_006357_.tmp.dll
              c:\windows\system32\_006358_.tmp.dll
              c:\windows\system32\_006361_.tmp.dll
              c:\windows\system32\_006362_.tmp.dll
              c:\windows\system32\_006363_.tmp.dll
              c:\windows\system32\_006364_.tmp.dll
              c:\windows\system32\_006365_.tmp.dll
              c:\windows\system32\_006370_.tmp.dll
              c:\windows\system32\_006372_.tmp.dll
              c:\windows\system32\1748657750.dat
              c:\windows\system32\Drivers\vuikkyz.sys

              .
              ((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
              .

              -------\Legacy_ACPI32
              -------\Legacy_BROWSERNETMAN
              -------\Legacy_KSI32SK
              -------\Legacy_PORT135SIK
              -------\Legacy_SECURENTM
              -------\Legacy_TDSSSERV
              -------\Service_BrowserNetman
              -------\Service_TDSSserv

              ((((((((((((((((((((((((( Files Created from 2009-08-01 to 2009-09-01 )))))))))))))))))))))))))))))))
              .

              2009-08-30 20:31 . 2009-08-30 20:35 -------- d-----w- C:\rsit
              2009-08-28 17:40 . 2009-08-28 17:40 -------- d-----r- c:\documents and settings\LocalService\Favoris
              2009-08-28 14:27 . 2009-07-28 14:33 55656 ----a-w- c:\windows\system32\drivers\avgntflt.sys
              2009-08-28 14:27 . 2009-03-30 08:32 96104 ----a-w- c:\windows\system32\drivers\avipbb.sys
              2009-08-28 14:27 . 2009-02-13 10:28 22360 ----a-w- c:\windows\system32\drivers\avgntmgr.sys
              2009-08-28 14:27 . 2009-02-13 10:17 45416 ----a-w- c:\windows\system32\drivers\avgntdd.sys
              2009-08-28 14:27 . 2009-08-28 14:27 -------- d-----w- c:\program files\Avira
              2009-08-28 14:27 . 2009-08-28 14:27 -------- d-----w- c:\documents and settings\All Users\Application Data\Avira
              2009-08-26 20:57 . 2009-08-28 14:09 -------- d-----w- c:\program files\Lavasoft
              2009-08-26 20:57 . 2009-08-28 14:09 -------- d-----w- c:\documents and settings\All Users\Application Data\Lavasoft
              2009-08-16 12:15 . 2007-12-26 15:30 679936 ----a-w- c:\windows\system32\D3DX81ab.dll
              2009-08-16 12:15 . 2007-12-26 15:30 1970176 ----a-w- c:\windows\system32\d3dx9.dll
              2009-08-16 12:15 . 2009-08-22 15:46 -------- d-----w- c:\program files\Cheat Engine

              .
              (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
              .
              2009-09-01 09:27 . 2004-08-19 12:03 91894 ----a-w- c:\windows\system32\perfc00C.dat
              2009-09-01 09:27 . 2004-08-19 12:03 505156 ----a-w- c:\windows\system32\perfh00C.dat
              2009-09-01 09:22 . 2005-10-26 01:14 384 ----a-w- c:\windows\system32\DVCStateBkp-{00000005-00000000-00000004-00001102-00000004-20061102}.dat
              2009-09-01 09:22 . 2005-10-26 01:14 384 ----a-w- c:\windows\system32\DVCState-{00000005-00000000-00000004-00001102-00000004-20061102}.dat
              2009-09-01 09:08 . 2009-06-28 10:55 -------- d-----w- c:\program files\BitComet
              2009-08-22 14:16 . 2009-03-13 15:27 -------- d-----w- c:\program files\Safari
              2009-08-21 21:49 . 2009-06-06 17:00 -------- d-----w- c:\program files\QuickTime
              2009-08-21 21:49 . 2005-10-26 01:13 -------- d-----w- c:\program files\Modem Helper
              2009-08-21 21:48 . 2006-06-28 10:01 -------- d-----w- c:\program files\Messenger Plus! Live
              2009-08-21 21:48 . 2007-02-11 11:14 -------- d-----w- c:\program files\Google
              2009-08-21 21:48 . 2009-01-22 18:43 -------- d-----w- c:\program files\Ghostgum
              2009-08-21 21:48 . 2008-02-27 12:02 -------- dcsh--w- c:\program files\Fichiers communs\WindowsLiveInstaller
              2009-08-21 21:48 . 2007-04-18 12:45 -------- d-----w- c:\program files\Fichiers communs\Vbox
              2009-08-21 21:48 . 2008-09-27 18:47 -------- d-----w- c:\program files\Fichiers communs\BitDefender
              2009-08-21 21:48 . 2005-10-26 01:22 -------- d-----w- c:\program files\Fichiers communs\AOL
              2009-08-21 21:48 . 2007-04-17 18:15 -------- d-----w- c:\program files\DivX
              2009-08-21 21:48 . 2006-10-03 16:52 -------- d-----w- c:\program files\Dictionnaire
              2009-08-21 21:48 . 2007-09-17 20:18 -------- d-----w- c:\program files\CNDP
              2009-08-21 21:48 . 2005-10-29 08:42 -------- d-----w- c:\program files\Fichiers communs\Adobe
              2009-08-17 07:30 . 2008-09-24 10:40 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
              2009-08-16 13:57 . 2009-04-20 09:21 3942048 ----a-w- c:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
              2009-08-16 08:24 . 2005-10-26 01:09 -------- d-----w- c:\program files\Java
              2009-08-03 11:36 . 2008-09-24 10:40 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
              2009-08-03 11:36 . 2008-09-24 10:40 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
              2009-07-25 03:23 . 2009-02-09 20:15 411368 ----a-w- c:\windows\system32\deploytk.dll
              2009-07-18 15:35 . 2009-07-18 15:34 -------- d-----w- c:\program files\iTunes
              2009-07-18 15:34 . 2009-07-18 15:34 -------- d-----w- c:\program files\iPod
              2009-07-18 15:34 . 2008-10-30 10:22 -------- d-----w- c:\program files\Fichiers communs\Apple
              2009-07-18 15:25 . 2009-07-18 15:25 75040 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 8.2.1.6\SetupAdmin.exe
              2009-07-11 11:56 . 2009-07-11 11:56 -------- d-----w- c:\program files\Sunbelt Software
              2009-07-08 22:27 . 2007-08-19 09:55 78192 ----a-w- c:\documents and settings\Cindy\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
              2009-06-23 08:53 . 2009-06-23 08:53 1915520 ----a-w- c:\documents and settings\pse-ms\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\fpupdateax\fpupdateax.exe
              .

              ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
              .
              .
              *Note* empty entries & legit default entries are not shown
              REGEDIT4

              [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
              "MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
              "LogitechSoftwareUpdate"="c:\documents and settings\rémy\Mes documents\Perso\ManifestEngine.exe" [2004-06-01 196608]
              "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-05-29 68856]
              "updateMgr"="c:\program files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 313472]
              "VeohPlugin"="c:\program files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe" [2009-05-19 3561720]

              [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
              "IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2005-04-25 139264]
              "ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-08-05 344064]
              "IntelMeM"="c:\program files\Intel\Modem Event Monitor\IntelMEM.exe" [2003-09-03 221184]
              "CTSysVol"="c:\program files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe" [2003-09-17 57344]
              "CTDVDDET"="c:\program files\Creative\SBAudigy2ZS\DVDAudio\CTDVDDET.EXE" [2003-06-18 45056]
              "UpdReg"="c:\windows\UpdReg.EXE" [2000-05-11 90112]
              "DVDLauncher"="c:\program files\CyberLink\PowerDVD\DVDLauncher.exe" [2005-02-23 53248]
              "DMXLauncher"="c:\program files\Dell\Media Experience\DMXLauncher.exe" [2004-09-15 86016]
              "ISUSPM Startup"="c:\progra~1\FICHIE~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-07-27 221184]
              "ISUSScheduler"="c:\program files\Fichiers communs\InstallShield\UpdateService\issch.exe" [2004-07-27 81920]
              "LVCOMSX"="c:\windows\system32\LVCOMSX.EXE" [2004-05-21 221184]
              "GW Port Controller"="c:\program files\Samsung\SmarThru\PORTCTRL.EXE" [2004-02-09 163840]
              "LogitechGalleryRepair"="c:\documents and settings\rémy\Mes documents\Perso\ISStart.exe" [2004-06-01 458752]
              "LogitechVideoRepair"="c:\program files\Logitech\Video\ISStart.exe" [2004-06-01 458752]
              "LogitechVideoTray"="c:\program files\Logitech\Video\LogiTray.exe" [2004-06-01 217088]
              "dla"="c:\windows\system32\dla\tfswctrl.exe" [2003-09-26 114741]
              "AppleSyncNotifier"="c:\program files\Fichiers communs\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2009-05-13 177472]
              "Share-to-Web Namespace Daemon"="c:\program files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe" [2001-07-03 57344]
              "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-05-26 413696]
              "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-07-13 292128]
              "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-07-25 149280]
              "avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
              "CTHelper"="CTHELPER.EXE" - c:\windows\system32\CTHELPER.EXE [2004-03-11 28672]

              [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
              "CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

              c:\documents and settings\r‚my\Menu D‚marrer\Programmes\D‚marrage\
              OpenOffice.org 2.1.lnk - c:\program files\OpenOffice.org 2.1\program\quickstart.exe [2006-11-27 393216]

              c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
              dlbcserv.lnk - c:\program files\Dell Photo Printer 720\dlbcserv.exe [2005-11-30 315392]
              Lancement rapide d'Adobe Reader.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2008-4-23 29696]
              Sagem - Utilitaire r‚seau pour Cl‚ USB Wi-Fi 802.11g.lnk - c:\program files\SAGEM Wi-Fi USB 802.11g\WLANUTL.exe [2005-11-30 679936]
              Supervision de Photo Loader.lnk - c:\program files\CASIO\Photo Loader\Plauto.exe [2006-8-21 217088]

              [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
              "EnableFirewall"= 0 (0x0)

              [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
              "%windir%\\system32\\sessmgr.exe"=
              "c:\\Program Files\\Electronic Arts\\La Bataille pour la Terre du Milieu II\\game.dat"=
              "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
              "c:\\WINDOWS\\system32\\LEXPPS.EXE"=
              "c:\\Program Files\\LucasArts\\Star Wars Battlefront II\\GameData\\BattlefrontII.exe"=
              "c:\\Program Files\\Messenger\\msmsgs.exe"=
              "c:\\WINDOWS\\system32\\dpvsetup.exe"=
              "c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
              "c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
              "c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
              "c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
              "c:\\Program Files\\Skype\\Phone\\Skype.exe"=
              "c:\\Program Files\\Veoh Networks\\VeohWebPlayer\\veohwebplayer.exe"=
              "c:\\Program Files\\iTunes\\iTunes.exe"=

              [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
              "7207:TCP"= 7207:TCP:BitComet 7207 TCP
              "7207:UDP"= 7207:UDP:BitComet 7207 UDP
              "26592:TCP"= 26592:TCP:BitComet 26592 TCP
              "26592:UDP"= 26592:UDP:BitComet 26592 UDP
              "10267:TCP"= 10267:TCP:BitComet 10267 TCP
              "10267:UDP"= 10267:UDP:BitComet 10267 UDP

              R1 SbFw;SbFw;c:\windows\system32\drivers\SbFw.sys [11/07/2009 13:56 270888]
              R1 sbhips;Sunbelt HIPS Driver;c:\windows\system32\drivers\sbhips.sys [21/06/2008 04:54 66600]
              R2 AntiVirSchedulerService;Avira AntiVir Planificateur;c:\program files\Avira\AntiVir Desktop\sched.exe [28/08/2009 16:27 108289]
              R2 SbPF.Launcher;SbPF.Launcher;c:\program files\Sunbelt Software\Personal Firewall\SbPFLnch.exe [31/10/2008 07:24 95528]
              R2 SPF4;Sunbelt Personal Firewall 4;c:\program files\Sunbelt Software\Personal Firewall\SbPFSvc.exe [31/10/2008 07:24 1365288]
              R3 PhilCam8116_XP;Logitech QuickCam Pro 3000(PID_08B1);c:\windows\system32\drivers\CamDrL20.sys [30/10/2005 15:52 245760]
              R3 SBFWIMCL;Sunbelt Software Firewall NDIS IM Filter Miniport;c:\windows\system32\drivers\SbFwIm.sys [11/07/2009 13:56 65576]
              R3 WlanUIG;Sagem 802.11g Wireless LAN USB Adapter Driver;c:\windows\system32\drivers\WlanUIG.sys [30/11/2005 17:57 379456]
              S0 zhjv;zhjv;c:\windows\system32\drivers\zbxdyhk.sys --> c:\windows\system32\drivers\zbxdyhk.sys [?]
              S0 zxxpged;zxxpged;c:\windows\system32\drivers\xmasmzsk.sys --> c:\windows\system32\drivers\xmasmzsk.sys [?]
              S1 66a0b8a;66a0b8a;c:\windows\system32\drivers\66a0b8a.sys --> c:\windows\system32\drivers\66a0b8a.sys [?]
              S3 fbxusb;Carte réseau virtuelle FreeBox USB;c:\windows\system32\drivers\fbxusb32.sys [20/10/2004 14:23 21344]
              S3 PIXMCV;JVC Communication PIX-MCV Driver;c:\windows\system32\drivers\pixmcvc.sys [15/06/2007 19:51 32000]
              S3 PIXMCVA;JVC PIX-MCV Audio Capture;c:\windows\system32\drivers\pixmcva.sys [15/06/2007 20:06 28057]
              S3 PIXMCVV;JVC PIX-MCV Video Capture;c:\windows\system32\drivers\pixmcvv.sys [15/06/2007 19:47 21081]

              --- Other Services/Drivers In Memory ---

              *NewlyCreated* - PCANDIS5
              .
              Contents of the 'Scheduled Tasks' folder

              2009-08-22 c:\windows\Tasks\AppleSoftwareUpdate.job
              - c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]

              2005-10-29 c:\windows\Tasks\Rappel d'abonnement 1 auprès de l'ISP.job
              - c:\windows\system32\OOBE\oobebaln.exe [2004-08-19 02:34]

              2009-09-01 c:\windows\Tasks\User_Feed_Synchronization-{C8E84DCF-36BD-4C87-BC6E-F6C2C9D287AA}.job
              - c:\windows\system32\msfeedssync.exe [2006-10-17 02:31]
              .
              - - - - ORPHANS REMOVED - - - -

              BHO-{C4CE8A0F-DB1C-4993-8D49-C23ABE041418} - (no file)
              Notify-awturSkL - awturSkL.dll

              .
              ------- Supplementary Scan -------
              .
              uStart Page = hxxp://orange.fr/
              uInternet Connection Wizard,ShellNext = hxxp://www.dell.fr/myway
              uInternet Settings,ProxyOverride = *.local;localhost
              IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
              IE: Tout télécharger avec BitComet - c:\program files\BitComet\BitComet.exe/AddAllLink.htm
              IE: Télécharger avec BitComet - c:\program files\BitComet\BitComet.exe/AddLink.htm
              IE: Télécharger toutes les vidéos avec BitComet - c:\program files\BitComet\BitComet.exe/AddVideo.htm
              Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\program files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
              FF - ProfilePath - c:\documents and settings\rémy\Application Data\Mozilla\Firefox\Profiles\59h6pnha.default\
              FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
              FF - prefs.js: browser.startup.homepage - hxxp://www.orange.fr/
              FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
              FF - plugin: c:\program files\Opera\program\plugins\npdivx32.dll
              FF - plugin: c:\program files\Veoh Networks\VeohWebPlayer\NPVeohTVPlugin.dll
              FF - plugin: c:\program files\Veoh Networks\VeohWebPlayer\npWebPlayerVideoPluginATL.dll
              FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
              FF - plugin: c:\program files\Virtual Earth 3D\npVE3D.dll
              .

              **************************************************************************

              catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
              Rootkit scan 2009-09-01 11:23
              Windows 5.1.2600 Service Pack 3 NTFS

              scanning hidden processes ...

              scanning hidden autostart entries ...

              scanning hidden files ...

              scan completed successfully
              hidden files: 0

              **************************************************************************
              .
              --------------------- LOCKED REGISTRY KEYS ---------------------

              [HKEY_USERS\S-1-5-21-2487303846-1502529327-667039455-1011\Software\SecuROM\License information*]
              "datasecu"=hex:50,81,a4,a0,1a,7f,8c,5f,d5,68,42,02,b7,3b,67,4a,5a,82,0d,7e,7c,
              4a,82,01,d1,9f,e3,e7,8b,27,9d,f8,27,1f,73,9e,7e,b3,26,20,e8,6f,94,77,50,0c,\
              "rkeysecu"=hex:5e,5e,33,a7,22,22,fe,43,98,1d,2f,86,90,36,25,23

              [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\Ø•€|ÿÿÿÿ•€|ù•9~*]
              "C040AC1900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"
              .
              --------------------- DLLs Loaded Under Running Processes ---------------------

              - - - - - - - > 'winlogon.exe'(1396)
              c:\windows\system32\cscui.dll

              - - - - - - - > 'explorer.exe'(1516)
              c:\progra~1\WINDOW~2\wmpband.dll
              c:\windows\system32\ieframe.dll
              c:\windows\system32\eappprxy.dll
              c:\windows\system32\webcheck.dll
              c:\windows\system32\WPDShServiceObj.dll
              c:\windows\system32\PortableDeviceTypes.dll
              c:\windows\system32\PortableDeviceApi.dll
              .
              ------------------------ Other Running Processes ------------------------
              .
              c:\windows\system32\ati2evxx.exe
              c:\windows\system32\LEXBCES.EXE
              c:\windows\system32\LEXPPS.EXE
              c:\program files\Avira\AntiVir Desktop\avguard.exe
              c:\program files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
              c:\program files\Bonjour\mDNSResponder.exe
              c:\windows\system32\CTSVCCDA.EXE
              c:\program files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
              c:\program files\Java\jre6\bin\jqs.exe
              c:\program files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
              c:\program files\Microsoft SQL Server\MSSQL$MICROSOFTBCM\Binn\sqlservr.exe
              c:\program files\Sunbelt Software\Personal Firewall\SbPFCl.exe
              c:\progra~1\HEWLET~1\HPSHAR~1\hpgs2wnf.exe
              c:\program files\Logitech\Video\FxSvr2.exe
              c:\program files\OpenOffice.org 2.1\program\soffice.exe
              c:\program files\OpenOffice.org 2.1\program\soffice.bin
              c:\program files\iPod\bin\iPodService.exe
              .
              **************************************************************************
              .
              Completion time: 2009-09-01 11:32 - machine was rebooted
              ComboFix-quarantined-files.txt 2009-09-01 09:32

              Pre-Run: 266 314 461 184 octets libres
              Post-Run: 270 268 514 304 octets libres

              Current=6 Default=6 Failed=5 LastKnownGood=7 Sets=1,2,3,4,5,6,7
              290 --- E O F --- 2009-05-13 20:11
              1. Contributeur sécurité
                Bonsoir,

                il y a des infections TDSS, MyWebSearch, "Vundo", etc...

                Fais ceci stp :

                ▶ Télécharge Combofix de sUBs

                ▶ et enregistre le sur le Bureau.

                ▶ désactive tes protections et ferme toutes tes applications(antivirus, parefeu, garde en temps réel de l'antispyware)

                Voici le tutoriel officiel de Bleeping Computer pour savoir l utiliser :

                https://www.bleepingcomputer.com/combofix/fr/comment-utiliser-combofix

                ▶ Je te conseille d'installer la console de récupération !!

                ensuite envois le rapport stp
                1. info.txt logfile of random's system information tool 1.06 2009-08-30 22:31:53

                  ======Uninstall list======

                  -->"C:\Program Files\Creative\SBAudigy2ZS\Program\Ctzapxx.EXE" /W /U /S /L:FRN
                  -->C:\Program Files\DivX\DivXConverterUninstall.exe /CONVERTER
                  -->C:\Program Files\Fichiers communs\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
                  -->C:\WINDOWS\IsUn040c.exe -fC:\WINDOWS\orun32.isu
                  -->C:\WINDOWS\system32\\MSIEXEC.EXE /x {075473F5-846A-448B-BCB3-104AA1760205}
                  -->C:\WINDOWS\system32\\MSIEXEC.EXE /x {1206EF92-2E83-4859-ACCB-2048C3CB7DA6}
                  -->C:\WINDOWS\system32\\MSIEXEC.EXE /x {AB708C9B-97C8-4AC9-899B-DBF226AC9382}
                  -->C:\WINDOWS\system32\\MSIEXEC.EXE /x {B12665F4-4E93-4AB4-B7FC-37053B524629}
                  -->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{169F8893-C1C5-4847-972C-EA1E008112AC}\setup.exe" -l0x40c
                  -->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{169F8893-C1C5-4847-972C-EA1E008112AC}\setup.exe" -l0x40c /remove
                  -->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{236FADD8-58FD-11D6-A285-00A0CC51B2FE}\setup.exe" -l0x40c
                  -->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{236FADD8-58FD-11D6-A285-00A0CC51B2FE}\setup.exe" -l0x40c /remove
                  -->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{2547E065-D92D-11D6-8586-006008CA5356}\setup.exe" -l0x40c uninstall
                  -->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{333D93A7-505C-11D6-857A-006008CA5356}\setup.exe" -l0x40c uninstall
                  -->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{435E969D-867E-4364-8E74-3DC8A69C5BDB}\setup.exe" -l0x40c
                  -->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{435E969D-867E-4364-8E74-3DC8A69C5BDB}\setup.exe" -l0x40c /remove
                  -->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{501F5586-5040-11D6-857A-006008CA5356}\setup.exe" -l0x40c uninstall
                  -->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{5210ED6D-52A9-11D6-A285-00A0CC51B2FE}\setup.exe" -l0x40c
                  -->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{5210ED6D-52A9-11D6-A285-00A0CC51B2FE}\setup.exe" -l0x40c /remove
                  -->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{5CDDF96A-BC34-4D72-9ABA-E1FFF0C39977}\setup.exe" -l0x40c
                  -->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{67AEFC4C-69E4-11D7-85F4-00E018013273}\setup.exe" -l0x40c
                  -->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{67AEFC4C-69E4-11D7-85F4-00E018013273}\setup.exe" -l0x40c /remove
                  -->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{7201B853-5833-11D6-A285-00A0CC51B2FE}\setup.exe" -l0x40c
                  -->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{7201B853-5833-11D6-A285-00A0CC51B2FE}\setup.exe" -l0x40c /remove
                  -->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{72A810B1-EE62-455A-A086-E1C9FEDE7F29}\setup.exe" -l0x40c
                  -->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{72A810B1-EE62-455A-A086-E1C9FEDE7F29}\setup.exe" -l0x40c /remove
                  -->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{7A900EAB-DA37-4554-AF19-9C337476D05D}\setup.exe" -l0x40c
                  -->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{7A900EAB-DA37-4554-AF19-9C337476D05D}\setup.exe" -l0x40c /remove
                  -->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{9154ED7C-926E-49CC-B677-0CF3C5267457}\setup.exe" -l0x40c
                  -->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{9154ED7C-926E-49CC-B677-0CF3C5267457}\setup.exe" -l0x40c /remove
                  -->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{9A4D2983-4662-4387-BE3D-4CFC2FA9C100}\setup.exe" -l0x40c
                  -->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{9A4D2983-4662-4387-BE3D-4CFC2FA9C100}\setup.exe" -l0x40c /remove
                  -->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{A1185190-514F-11D6-A285-00A0CC51B2FE}\setup.exe" -l0x40c
                  -->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{A1185190-514F-11D6-A285-00A0CC51B2FE}\setup.exe" -l0x40c /remove
                  -->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{AC157741-3285-4D6A-B934-9174587A3493}\setup.exe" -l0x40c
                  -->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{AC157741-3285-4D6A-B934-9174587A3493}\setup.exe" -l0x40c /remove
                  -->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{B3549608-69D3-11D7-AB2D-0090271A23A2}\setup.exe" -l0x40c
                  -->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{B3549608-69D3-11D7-AB2D-0090271A23A2}\setup.exe" -l0x40c /remove
                  -->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{C6866B7D-ACFD-4C49-B77B-3B2F8CF54B96}\setup.exe" -l0x40c
                  -->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{C6866B7D-ACFD-4C49-B77B-3B2F8CF54B96}\setup.exe" -l0x40c /remove
                  -->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{D94854D4-505E-11D6-857A-006008CA5356}\setup.exe" -l0x40c uninstall
                  -->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{D9485541-505E-11D6-857A-006008CA5356}\setup.exe" -l0x40c uninstall
                  -->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{D94855AD-505E-11D6-857A-006008CA5356}\setup.exe" -l0x40c uninstall
                  -->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{DEBD7BF3-5856-11D6-A285-00A0CC51B2FE}\setup.exe" -l0x40c
                  -->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{DEBD7BF3-5856-11D6-A285-00A0CC51B2FE}\setup.exe" -l0x40c /remove
                  -->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{E226D4BA-4FAD-11D6-857A-006008CA5356}\setup.exe" -l0x40c uninstall
                  -->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{EE6699B3-E5AD-4E59-8F2B-207DF630670C}\setup.exe" -l0x40c
                  -->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{EE6699B3-E5AD-4E59-8F2B-207DF630670C}\setup.exe" -l0x40c /remove
                  -->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{FB2292C6-1F0A-11D7-AB2D-0090271A23A2}\setup.exe" -l0x40c
                  -->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{FB2292C6-1F0A-11D7-AB2D-0090271A23A2}\setup.exe" -l0x40c /remove
                  -->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{FD851F7E-F887-405D-9E1C-488811113EF3}\setup.exe" -l0x40c
                  -->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{FD851F7E-F887-405D-9E1C-488811113EF3}\setup.exe" -l0x40c /remove
                  -->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
                  Adobe Download Manager 2.0 (Supprimer uniquement)-->"C:\Program Files\Fichiers communs\Adobe\ESD\uninst.exe"
                  Adobe Flash Player 10 ActiveX-->C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
                  Adobe Flash Player 10 Plugin-->C:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe
                  Adobe Reader 7.1.0 - Français-->MsiExec.exe /I{AC76BA86-7AD7-1036-7B44-A71000000002}
                  Adobe Reader Chinese Simplified Fonts-->MsiExec.exe /I{AC76BA86-7AD7-2447-0000-705000000001}
                  Adobe Shockwave Player-->C:\WINDOWS\system32\Macromed\SHOCKW~1\UNWISE.EXE C:\WINDOWS\system32\Macromed\SHOCKW~1\Install.log
                  Age of Empires III-->C:\PROGRA~1\FICHIE~1\INSTAL~1\Driver\11\INTEL3~1\IDriver.exe /M{485775E8-AEB8-46BD-922B-242879E03DD5}
                  Apple Mobile Device Support-->MsiExec.exe /I{C337BDAF-CB4E-47E2-BE1A-CB31BB7DD0E3}
                  Apple Software Update-->MsiExec.exe /I{6956856F-B6B3-4BE0-BA0B-8F495BE32033}
                  Archiveur WinRAR-->C:\Program Files\WinRAR\uninstall.exe
                  ARTEuro-->MsiExec.exe /I{1D3C662A-F6C6-4767-A788-7AA43A9A1317}
                  Assistant de connexion Windows Live-->MsiExec.exe /I{D3116CC7-24DC-4CA3-9CE1-23FED836E9F2}
                  ATI Display Driver-->rundll32 C:\WINDOWS\system32\atiiiexx.dll,_InfEngUnInstallINFFile_RunDLL@16 -force_restart -flags:0x2010001 -inf_class:DISPLAY -clean
                  Avira AntiVir Personal - Free Antivirus-->C:\Program Files\Avira\AntiVir Desktop\setup.exe /REMOVE
                  AviSynth 2.5-->"C:\Program Files\AviSynth 2.5\Uninstall.exe"
                  BitComet 1.13-->C:\Program Files\BitComet\uninst.exe
                  Bonjour-->MsiExec.exe /I{07287123-B8AC-41CE-8346-3D777245C35B}
                  CCleaner (remove only)-->"C:\Program Files\CCleaner\uninst.exe"
                  Cheat Engine 5.5-->"C:\Program Files\Cheat Engine\unins000.exe"
                  Combined Community Codec Pack 2008-01-24-->"C:\Documents and Settings\rémy\Mes documents\rémy Travail\Combined Community Codec Pack\unins000.exe"
                  Compatibility Pack for the 2007 Office system-->MsiExec.exe /X{90120000-0020-040C-0000-0000000FF1CE}
                  Correctif pour Lecteur Windows Media 11 (KB939683)-->"C:\WINDOWS\$NtUninstallKB939683$\spuninst\spuninst.exe"
                  Correctif pour Windows Internet Explorer 7 (KB947864)-->"C:\WINDOWS\ie7updates\KB947864-IE7\spuninst\spuninst.exe"
                  Correctif pour Windows XP (KB952287)-->"C:\WINDOWS\$NtUninstallKB952287$\spuninst\spuninst.exe"
                  Creative MediaSource-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{56F3E1FF-54FE-4384-A153-6CCABA097814}\setup.exe" -l0x40c /remove
                  Dell Driver Reset Tool-->MsiExec.exe /I{5905F42D-3F5F-4916-ADA6-94A3646AEE76}
                  Dell Media Experience Update-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{CDE4CC8B-134B-421E-943C-90799E56F664}\setup.exe" -l0x40c -L0x40c /SMAINT
                  Dell Media Experience-->MsiExec.exe /I{AC0EE5B0-A8FB-4D0A-AF03-2EDC518F841B}
                  Dell Photo Printer 720 Logger-->C:\Program Files\Dell Photo Printer 720\dlbcunst.exe
                  Dell Photo Printer 720-->C:\WINDOWS\system32\spool\drivers\w32x86\3\DLBCUN5C.EXE -dDell Photo Printer 720
                  Dell Picture Studio v3.0-->MsiExec.exe /I{AF06CAE4-C134-44B1-B699-14FBDB63BD37}
                  DivX Codec-->C:\Program Files\DivX\DivXCodecUninstall.exe /CODEC
                  DivX Converter-->C:\Program Files\DivX\DivXConverterUninstall.exe /CONVERTER
                  DivX Player-->C:\Program Files\DivX\DivXPlayerUninstall.exe /PLAYER
                  DivX Web Player-->C:\Program Files\DivX\DivXWebPlayerUninstall.exe /PLUGIN
                  ffdshow [rev 2527] [2008-12-19]-->"C:\Program Files\ffdshow\unins000.exe"
                  Free - Kit de connexion-->C:\Program Files\Free.fr\uninstall.exe
                  Gestionnaire de contacts professionnels pour Outlook 2003-->MsiExec.exe /I{66563AD8-637B-407F-BCA7-0233A16891AB}
                  Google Earth-->MsiExec.exe /I{97C0EA4A-1A0B-4C53-ACEB-49984DA79C90}
                  Google Toolbar for Internet Explorer-->"C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarManager_E582EA556D8DE101.exe" /uninstall
                  Google Toolbar for Internet Explorer-->MsiExec.exe /I{18455581-E099-4BA8-BC6B-F34B2F06600C}
                  High Definition Audio Driver Package - KB835221-->C:\WINDOWS\$NtUninstallKB835221WXP$\spuninst\spuninst.exe
                  HijackThis 2.0.2-->"C:\Program Files\Trend Micro\HijackThis\HijackThis.exe" /uninstall
                  Hotfix for Windows Media Format 11 SDK (KB929399)-->"C:\WINDOWS\$NtUninstallKB929399$\spuninst\spuninst.exe"
                  HP DLA-->MsiExec.exe /I{1206EF92-2E83-4859-ACCB-2048C3CB7DA6}
                  HP Precisionscan Pro 3.1-->MsiExec.exe /I{6B36DEBF-27D0-4B1E-858D-D397091C6C7D}
                  HP Share-to-Web-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{748F4870-8350-11D3-B0BF-080009FB4A19}\setup.exe" --MAIN -l1036
                  Intel Matrix Storage Manager-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}\setup.exe" -l040c -INTELUNINST
                  Intel(R) 537EP V9x DF PCI Modem-->rundll32 IntelCci.dll,iSMUninstallation "Intel(R) 537EP V9x DF PCI Modem"
                  Intel(R) PROSafe for Wired Connections-->MsiExec.exe /I{36BD0774-6CD6-4FF9-A148-83CA09AC123E}
                  Intel(R) PROSafe for Wired Connections-->MsiExec.exe /I{403EF592-953B-4794-BCEF-ECAB835C2095}
                  Internet Explorer Default Page-->MsiExec.exe /I{35BDEFF1-A610-4956-A00D-15453C116395}
                  iTunes-->MsiExec.exe /I{99ECF41F-5CCA-42BD-B8B8-A8333E2E2944}
                  Jasc Paint Shop Photo Album 5-->MsiExec.exe /I{4192EAC0-6B36-4723-B216-D0E86E7757AC}
                  Jasc Paint Shop Pro Studio, Dell Editon-->MsiExec.exe /I{78C496B9-5A6B-4692-8C2E-AFFFC34E4961}
                  Java 2 Runtime Environment, SE v1.4.2_03-->MsiExec.exe /I{7148F0A8-6813-11D6-A77B-00B0D0142030}
                  Java(TM) 6 Update 15-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216012FF}
                  JS Star-->MsiExec.exe /I{1BD68BBD-329B-46CC-9DDD-65F2F65DACA1}
                  L&H TTS3000 Français-->RunDll32 advpack.dll,LaunchINFSection C:\WINDOWS\INF\LHTTSFRF.inf, Uninstall
                  La Bataille pour la Terre du Milieu™ II-->C:\Program Files\Electronic Arts\La Bataille pour la Terre du Milieu II\EAUninstall.exe
                  Learn2 Player (Uninstall Only)-->C:\Program Files\Learn2.com\StRunner\stuninst.exe
                  Lecteur Windows Media 11-->"C:\Program Files\Windows Media Player\Setup_wm.exe" /Uninstall
                  livebox-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{AB3F9176-E74A-4F28-9A09-4F22349B145E}\setup.exe" -l0x40c
                  Livebox-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{FC7DDAAE-7F2B-4270-9BFD-5A130B667E9E}\Setup.exe" -l0x40c
                  Logiciel des cartes réseau Intel(R) PRO v9.2.4.11-->C:\Program Files\Intel\DMIX\uninst\DxSetup.exe /x /qr /le C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\PROSetDX\DMIX\\DxUninst.log
                  Logitech Print Service-->C:\PROGRA~1\Logitech\PRINTS~1\UNWISE.EXE C:\PROGRA~1\Logitech\PRINTS~1\INSTALL.LOG
                  Logitech QuickCam-->MsiExec.exe /I{0496D9E9-224B-4AFA-8F37-23B98D52F1EB}
                  Malwarebytes' Anti-Malware-->"C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
                  MathGraph32 Lycee et College V2.5.2-->MsiExec.exe /X{2983B95B-B2FD-4926-8830-60B4D328293C}
                  Matrix Flowcode Demo-->C:\PROGRA~1\MATRIX~1\FLOWCO~1\UNWISE.EXE C:\PROGRA~1\MATRIX~1\FLOWCO~1\INSTALL.LOG
                  Messenger Plus! Live-->"C:\Program Files\Messenger Plus! Live\Uninstall.exe"
                  MicroSim_EVAL_7.1-->C:\WINDOWS\uninst.exe -fC:\msimev71\DeIsL1.isu
                  Microsoft .NET Framework 1.1 French Language Pack-->MsiExec.exe /X{9A394342-4A68-4EBA-85A6-55B559F4E700}
                  Microsoft .NET Framework 1.1 Hotfix (KB928366)-->"C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\hotfix.exe" "C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\M928366\M928366Uninstall.msp"
                  Microsoft .NET Framework 1.1-->msiexec.exe /X {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
                  Microsoft .NET Framework 1.1-->MsiExec.exe /X{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
                  Microsoft .NET Framework 2.0 Service Pack 1-->MsiExec.exe /I{B508B3F1-A24A-32C0-B310-85786919EF28}
                  Microsoft Compression Client Pack 1.0 for Windows XP-->"C:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe"
                  Microsoft Internationalized Domain Names Mitigation APIs-->"C:\WINDOWS\$NtServicePackUninstallIDNMitigationAPIs$\spuninst\spuninst.exe"
                  Microsoft National Language Support Downlevel APIs-->"C:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$\spuninst\spuninst.exe"
                  Microsoft Office 2003 International Character Toolbar-->MsiExec.exe /I{B6828215-1469-43A2-8BEE-F5A970F98161}
                  Microsoft Office Small Business Edition 2003-->MsiExec.exe /I{91CA040C-6000-11D3-8CFE-0150048383C9}
                  Microsoft Silverlight-->MsiExec.exe /X{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
                  Microsoft User-Mode Driver Framework Feature Pack 1.0-->"C:\WINDOWS\$NtUninstallWudf01000$\spuninst\spuninst.exe"
                  Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
                  Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17-->MsiExec.exe /X{9A25302D-30C0-39D9-BD6F-21E6EC160475}
                  MicroStaff WINASPI-->C:\MWASPI\uninst.exe
                  Mise à jour critique pour Lecteur Windows Media 11 (KB959772)-->"C:\WINDOWS\$NtUninstallKB959772_WM11$\spuninst\spuninst.exe"
                  Mise à jour de sécurité pour Lecteur Windows Media (KB952069)-->"C:\WINDOWS\$NtUninstallKB952069_WM9$\spuninst\spuninst.exe"
                  Mise à jour de sécurité pour Lecteur Windows Media 11 (KB936782)-->"C:\WINDOWS\$NtUninstallKB936782_WMP11$\spuninst\spuninst.exe"
                  Mise à jour de sécurité pour Lecteur Windows Media 11 (KB954154)-->"C:\WINDOWS\$NtUninstallKB954154_WM11$\spuninst\spuninst.exe"
                  Mise à jour de sécurité pour Lecteur Windows Media 9 (KB911565)-->"C:\WINDOWS\$NtUninstallKB911565$\spuninst\spuninst.exe"
                  Mise à jour de sécurité pour Lecteur Windows Media 9 (KB917734)-->"C:\WINDOWS\$NtUninstallKB917734_WMP9$\spuninst\spuninst.exe"
                  Mise à jour de sécurité pour Step by Step Interactive Training (KB898458)-->"C:\WINDOWS\$NtUninstallKB898458$\spuninst\spuninst.exe"
                  Mise à jour de sécurité pour Step by Step Interactive Training (KB923723)-->"C:\WINDOWS\$NtUninstallKB923723$\spuninst\spuninst.exe"
                  Mise à jour de sécurité pour Windows Internet Explorer 7 (KB928090)-->"C:\WINDOWS\ie7updates\KB928090-IE7\spuninst\spuninst.exe"
                  Mise à jour de sécurité pour Windows Internet Explorer 7 (KB929969)-->"C:\WINDOWS\ie7updates\KB929969\spuninst\spuninst.exe"
                  Mise à jour de sécurité pour Windows Internet Explorer 7 (KB931768)-->"C:\WINDOWS\ie7updates\KB931768-IE7\spuninst\spuninst.exe"
                  Mise à jour de sécurité pour Windows Internet Explorer 7 (KB933566)-->"C:\WINDOWS\ie7updates\KB933566-IE7\spuninst\spuninst.exe"
                  Mise à jour de sécurité pour Windows Internet Explorer 7 (KB937143)-->"C:\WINDOWS\ie7updates\KB937143-IE7\spuninst\spuninst.exe"
                  Mise à jour de sécurité pour Windows Internet Explorer 7 (KB938127)-->"C:\WINDOWS\ie7updates\KB938127-IE7\spuninst\spuninst.exe"
                  Mise à jour de sécurité pour Windows Internet Explorer 7 (KB939653)-->"C:\WINDOWS\ie7updates\KB939653-IE7\spuninst\spuninst.exe"
                  Mise à jour de sécurité pour Windows Internet Explorer 7 (KB942615)-->"C:\WINDOWS\ie7updates\KB942615-IE7\spuninst\spuninst.exe"
                  Mise à jour de sécurité pour Windows Internet Explorer 7 (KB944533)-->"C:\WINDOWS\ie7updates\KB944533-IE7\spuninst\spuninst.exe"
                  Mise à jour de sécurité pour Windows Internet Explorer 7 (KB950759)-->"C:\WINDOWS\ie7updates\KB950759-IE7\spuninst\spuninst.exe"
                  Mise à jour de sécurité pour Windows Internet Explorer 7 (KB953838)-->"C:\WINDOWS\ie7updates\KB953838-IE7\spuninst\spuninst.exe"
                  Mise à jour de sécurité pour Windows Internet Explorer 7 (KB956390)-->"C:\WINDOWS\ie7updates\KB956390-IE7\spuninst\spuninst.exe"
                  Mise à jour de sécurité pour Windows Internet Explorer 7 (KB958215)-->"C:\WINDOWS\ie7updates\KB958215-IE7\spuninst\spuninst.exe"
                  Mise à jour de sécurité pour Windows Internet Explorer 7 (KB960714)-->"C:\WINDOWS\ie7updates\KB960714-IE7\spuninst\spuninst.exe"
                  Mise à jour de sécurité pour Windows Internet Explorer 7 (KB961260)-->"C:\WINDOWS\ie7updates\KB961260-IE7\spuninst\spuninst.exe"
                  Mise à jour de sécurité pour Windows Internet Explorer 7 (KB963027)-->"C:\WINDOWS\ie7updates\KB963027-IE7\spuninst\spuninst.exe"
                  Mise à jour de sécurité pour Windows XP (KB923561)-->"C:\WINDOWS\$NtUninstallKB923561$\spuninst\spuninst.exe"
                  Mise à jour de sécurité pour Windows XP (KB938464)-->"C:\WINDOWS\$NtUninstallKB938464$\spuninst\spuninst.exe"
                  Mise à jour de sécurité pour Windows XP (KB938464-v2)-->"C:\WINDOWS\$NtUninstallKB938464-v2$\spuninst\spuninst.exe"
                  Mise à jour de sécurité pour Windows XP (KB941569)-->"C:\WINDOWS\$NtUninstallKB941569$\spuninst\spuninst.exe"
                  Mise à jour de sécurité pour Windows XP (KB946648)-->"C:\WINDOWS\$NtUninstallKB946648$\spuninst\spuninst.exe"
                  Mise à jour de sécurité pour Windows XP (KB950760)-->"C:\WINDOWS\$NtUninstallKB950760$\spuninst\spuninst.exe"
                  Mise à jour de sécurité pour Windows XP (KB950762)-->"C:\WINDOWS\$NtUninstallKB950762$\spuninst\spuninst.exe"
                  Mise à jour de sécurité pour Windows XP (KB950974)-->"C:\WINDOWS\$NtUninstallKB950974$\spuninst\spuninst.exe"
                  Mise à jour de sécurité pour Windows XP (KB951066)-->"C:\WINDOWS\$NtUninstallKB951066$\spuninst\spuninst.exe"
                  Mise à jour de sécurité pour Windows XP (KB951376)-->"C:\WINDOWS\$NtUninstallKB951376$\spuninst\spuninst.exe"
                  Mise à jour de sécurité pour Windows XP (KB951376-v2)-->"C:\WINDOWS\$NtUninstallKB951376-v2$\spuninst\spuninst.exe"
                  Mise à jour de sécurité pour Windows XP (KB951698)-->"C:\WINDOWS\$NtUninstallKB951698$\spuninst\spuninst.exe"
                  Mise à jour de sécurité pour Windows XP (KB951748)-->"C:\WINDOWS\$NtUninstallKB951748$\spuninst\spuninst.exe"
                  Mise à jour de sécurité pour Windows XP (KB952004)-->"C:\WINDOWS\$NtUninstallKB952004$\spuninst\spuninst.exe"
                  Mise à jour de sécurité pour Windows XP (KB952954)-->"C:\WINDOWS\$NtUninstallKB952954$\spuninst\spuninst.exe"
                  Mise à jour de sécurité pour Windows XP (KB953839)-->"C:\WINDOWS\$NtUninstallKB953839$\spuninst\spuninst.exe"
                  Mise à jour de sécurité pour Windows XP (KB954211)-->"C:\WINDOWS\$NtUninstallKB954211$\spuninst\spuninst.exe"
                  Mise à jour de sécurité pour Windows XP (KB954459)-->"C:\WINDOWS\$NtUninstallKB954459$\spuninst\spuninst.exe"
                  Mise à jour de sécurité pour Windows XP (KB954600)-->"C:\WINDOWS\$NtUninstallKB954600$\spuninst\spuninst.exe"
                  Mise à jour de sécurité pour Windows XP (KB955069)-->"C:\WINDOWS\$NtUninstallKB955069$\spuninst\spuninst.exe"
                  Mise à jour de sécurité pour Windows XP (KB956391)-->"C:\WINDOWS\$NtUninstallKB956391$\spuninst\spuninst.exe"
                  Mise à jour de sécurité pour Windows XP (KB956572)-->"C:\WINDOWS\$NtUninstallKB956572$\spuninst\spuninst.exe"
                  Mise à jour de sécurité pour Windows XP (KB956802)-->"C:\WINDOWS\$NtUninstallKB956802$\spuninst\spuninst.exe"
                  Mise à jour de sécurité pour Windows XP (KB956803)-->"C:\WINDOWS\$NtUninstallKB956803$\spuninst\spuninst.exe"
                  Mise à jour de sécurité pour Windows XP (KB956841)-->"C:\WINDOWS\$NtUninstallKB956841$\spuninst\spuninst.exe"
                  Mise à jour de sécurité pour Windows XP (KB957095)-->"C:\WINDOWS\$NtUninstallKB957095$\spuninst\spuninst.exe"
                  Mise à jour de sécurité pour Windows XP (KB957097)-->"C:\WINDOWS\$NtUninstallKB957097$\spuninst\spuninst.exe"
                  Mise à jour de sécurité pour Windows XP (KB958644)-->"C:\WINDOWS\$NtUninstallKB958644$\spuninst\spuninst.exe"
                  Mise à jour de sécurité pour Windows XP (KB958687)-->"C:\WINDOWS\$NtUninstallKB958687$\spuninst\spuninst.exe"
                  Mise à jour de sécurité pour Windows XP (KB958690)-->"C:\WINDOWS\$NtUninstallKB958690$\spuninst\spuninst.exe"
                  Mise à jour de sécurité pour Windows XP (KB959426)-->"C:\WINDOWS\$NtUninstallKB959426$\spuninst\spuninst.exe"
                  Mise à jour de sécurité pour Windows XP (KB960225)-->"C:\WINDOWS\$NtUninstallKB960225$\spuninst\spuninst.exe"
                  Mise à jour de sécurité pour Windows XP (KB960715)-->"C:\WINDOWS\$NtUninstallKB960715$\spuninst\spuninst.exe"
                  Mise à jour de sécurité pour Windows XP (KB960803)-->"C:\WINDOWS\$NtUninstallKB960803$\spuninst\spuninst.exe"
                  Mise à jour de sécurité pour Windows XP (KB961373)-->"C:\WINDOWS\$NtUninstallKB961373$\spuninst\spuninst.exe"
                  Mise à jour pour Windows XP (KB951072-v2)-->"C:\WINDOWS\$NtUninstallKB951072-v2$\spuninst\spuninst.exe"
                  Mise à jour pour Windows XP (KB951978)-->"C:\WINDOWS\$NtUninstallKB951978$\spuninst\spuninst.exe"
                  Mise à jour pour Windows XP (KB955839)-->"C:\WINDOWS\$NtUninstallKB955839$\spuninst\spuninst.exe"
                  Mise à jour pour Windows XP (KB967715)-->"C:\WINDOWS\$NtUninstallKB967715$\spuninst\spuninst.exe"
                  MobileMe Control Panel-->MsiExec.exe /I{DDBB28C8-B2AA-45A1-8DCE-059A798509FB}
                  Modem Event Monitor-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{7A0EFAFB-AC4B-4B88-8C6B-6731BE88DB68}\setup.exe" -l0x40c
                  Modem Helper-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{7F142D56-3326-11D5-B229-002078017FBF}\setup.exe" -l0x40c ControlPanel
                  Modem On Hold-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{3F92ABBB-6BBF-11D5-B229-002078017FBF}\setup.exe" -l0x40c ControlPanelAnyText
                  Mozilla Firefox (3.5.2)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
                  MSN-->C:\Program Files\MSN\MsnInstaller\msninst.exe /Action:ARP
                  MSXML 4.0 SP2 (KB927978)-->MsiExec.exe /I{37477865-A3F1-4772-AD43-AAFC6BCFF99F}
                  MSXML 4.0 SP2 (KB936181)-->MsiExec.exe /I{C04E32E0-0416-434D-AFB9-6969D703A9EF}
                  MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
                  MyWay Search Assistant-->MsiExec.exe /X{E7559288-223B-453C-9F06-340E3BE21E39}
                  NJStar Chinese WP-->C:\Program Files\NJStar Chinese WP\uninst.exe
                  OpenOffice.org 2.1-->MsiExec.exe /I{E5430A11-6799-41E0-A9D5-F68BDC67AAD8}
                  Opera 9.52-->MsiExec.exe /X{E1A88DE8-BD36-4DEA-8DD8-E35EF475ADC7}
                  Outil de téléchargement Windows Live-->MsiExec.exe /I{205C6BDD-7B73-42DE-8505-9A093F35A238}
                  Panneau de contrôle ATI-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{0BEDBD4E-2D34-47B5-9973-57E62B29307C}\setup.exe"
                  Panneau de contrôle distant-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{FCA6A663-110C-40C6-B085-9C2469923326}\setup.exe"
                  Photo Loader 3.0F-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{70B45586-B51E-4947-A258-A895596C5CED}\Setup.exe" -uninst
                  Photohands 1.0F-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{544FB392-069D-4BA5-9DC7-FFD47230AEE5}\Setup.exe"
                  PowerDVD 5.5-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}\setup.exe" -uninstall
                  PRELOAD DELL France Installer-->MsiExec.exe /X{B841F3D2-72F4-47F4-AF19-6922C417FC6B}
                  Programme de gestion Camera de Logitech®-->"C:\Program Files\Fichiers communs\Logitech\QCDRV\BIN\SETUP.EXE" UNINSTALL REMOVEPROMPT
                  QuickTime-->MsiExec.exe /I{C78EAC6F-7A73-452E-8134-DBB2165C5A68}
                  RealPlayer-->C:\Program Files\Fichiers communs\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
                  Safari-->MsiExec.exe /I{E56D39F8-2A9F-44B4-B068-A72E45A073E6}
                  Sagem - Utilitaire réseau pour Clé USB Wi-Fi 802.11g-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{0E691604-B328-4B4A-8F17-C9D6395075C5}\Setup.exe" -l0x40c
                  SAMSUNG CDMA Modem Driver Set-->C:\WINDOWS\system32\Samsung_USB_Drivers\3\SSCDUninstall.exe
                  SAMSUNG Mobile USB Modem 1.0 Software-->C:\WINDOWS\system32\Samsung_USB_Drivers\1\SS_Uninstall.exe
                  SAMSUNG Mobile USB Modem Software-->C:\WINDOWS\system32\Samsung_USB_Drivers\2\SSM_Uninstall.exe
                  Samsung PC Studio 3 USB Driver Installer-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\10\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{EBA29752-DDD2-4B62-B2E3-9841F92A3E3A}\setup.exe" -l0x40c -removeonly
                  Samsung PC Studio-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\10\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{C4A4722E-79F9-417C-BD72-8D359A090C97}\setup.exe" -l0x40c -removeonly
                  Samsung SCX-4x16 Series (TWAIN)-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{0D2EDE81-878F-400D-A5C3-3EC445F47750}\setup.exe" -l0x40c
                  Samsung SCX-4x16 Series-->"C:\WINDOWS\Samsung\SCX-4x16\setup.exe" /UNINSTALL /L040c
                  screensaver-800x600-->C:\WINDOWS\screensaver-800x600.scr /u
                  Security Update for CAPICOM (KB931906)-->MsiExec.exe /I{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
                  Security Update for CAPICOM (KB931906)-->MsiExec.exe /X{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
                  Skype™ 3.2-->MsiExec.exe /X{5C82DAE5-6EB0-4374-9254-BE3319BA4E82}
                  SmarThru-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{1CE06390-46D0-11D6-8578-006008CA5356}\SETUP.EXE" -l0x40c uninstall -l040c
                  Sonic MyDVD LE-->MsiExec.exe /I{21657574-BD54-48A2-9450-EB03B2C7FC29}
                  Sonic RecordNow Audio-->MsiExec.exe /I{AB708C9B-97C8-4AC9-899B-DBF226AC9382}
                  Sonic RecordNow Copy-->MsiExec.exe /I{B12665F4-4E93-4AB4-B7FC-37053B524629}
                  Sonic RecordNow Data-->MsiExec.exe /I{075473F5-846A-448B-BCB3-104AA1760205}
                  Sonic Update Manager-->MsiExec.exe /I{30465B6C-B53F-49A1-9EBA-A3F187AD502E}
                  Sound Blaster Audigy 2 ZS-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{9E2514D9-DC24-4634-B348-61F3EF0F1628}\setup.exe" -l0x40c
                  Star Wars Battlefront II-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{3D374523-CFDE-461A-827E-2A102E2AB365}\Setup.exe" -l0x40c -removeonly
                  Sunbelt Personal Firewall-->MsiExec.exe /X{82B1150E-9B37-49FC-83EB-D52197D900D0}
                  UltraStar 0.6.0-->"C:\Program Files\UltraStar\uninstall.exe"
                  Uninstall 1.0.0.0-->"C:\Program Files\Fichiers communs\DVDVideoSoft\unins000.exe"
                  Veoh Web Player-->"C:\Program Files\Veoh Networks\VeohWebPlayer\uninst.exe"
                  Videora iPod Converter 4.04-->C:\Program Files\Red Kawa\Video Converter App\uninstaller.exe
                  Viewpoint Media Player-->C:\Program Files\Viewpoint\Viewpoint Experience Technology\mtsAxInstaller.exe /u
                  Virtual Earth 3D (Bêta)-->MsiExec.exe /I{3CCB26F5-E2A7-4C91-8340-9149D7B7C2BE}
                  Visual C++ 2008 x86 Runtime - (v9.0.30729)-->MsiExec.exe /X{F333A33D-125C-32A2-8DCE-5C5D14231E27}
                  Visual C++ 2008 x86 Runtime - v9.0.30729.01-->C:\WINDOWS\system32\msiexec.exe /x {F333A33D-125C-32A2-8DCE-5C5D14231E27} /qb+ REBOOTPROMPT=""
                  Windows Imaging Component-->"C:\WINDOWS\$NtUninstallWIC$\spuninst\spuninst.exe"
                  Windows Internet Explorer 8-->"C:\WINDOWS\ie8\spuninst\spuninst.exe"
                  Windows Live installer-->MsiExec.exe /X{FD44E544-E7D0-4DBA-9FA0-8AE1A1300390}
                  Windows Live Messenger-->MsiExec.exe /X{BADF6744-3787-48F6-B8C9-4C4995401D65}
                  Windows Media Format 11 runtime-->"C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll
                  Windows Media Format 11 runtime-->"C:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe"
                  Windows Media Player 11-->"C:\WINDOWS\$NtUninstallwmp11$\spuninst\spuninst.exe"
                  Windows Media Player Firefox Plugin-->MsiExec.exe /I{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}
                  Windows XP Service Pack 3-->"C:\WINDOWS\$NtServicePackUninstall$\spuninst\spuninst.exe"
                  Yahoo! Install Manager-->C:\WINDOWS\system32\regsvr32 /u C:\PROGRA~1\Yahoo!\Common\YINSTH~1.DLL

                  ======Security center information======

                  AV: AntiVir Desktop
                  FW: Sunbelt Personal Firewall

                  ======System event log======

                  Computer Name:
                  Event Code: 7036
                  Message: Le service Hôte de périphérique universel Plug-and-Play est entré dans l'état : en cours d'exécution.

                  Record Number: 167295
                  Source Name: Service Control Manager
                  Time Written: 20090823220223.000000+120
                  Event Type: Informations
                  User:

                  Computer Name:
                  Event Code: 7035
                  Message: Un contrôle Démarrer a correctement été envoyé au service Hôte de périphérique universel Plug-and-Play.

                  Record Number: 167294
                  Source Name: Service Control Manager
                  Time Written: 20090823220222.000000+120
                  Event Type: Informations
                  User: AUTORITE NT\SYSTEM

                  Computer Name:
                  Event Code: 4226
                  Message: TCP/IP a atteint la limite de sécurité imposée sur le nombre de tentatives de connexion TCP simultanées.

                  Record Number: 167293
                  Source Name: Tcpip
                  Time Written: 20090823220045.000000+120
                  Event Type: Avertissement
                  User:

                  Computer Name:
                  Event Code: 4226
                  Message: TCP/IP a atteint la limite de sécurité imposée sur le nombre de tentatives de connexion TCP simultanées.

                  Record Number: 167292
                  Source Name: Tcpip
                  Time Written: 20090823214430.000000+120
                  Event Type: Avertissement
                  User:

                  Computer Name:
                  Event Code: 7036
                  Message: Le service Google Software Updater est entré dans l'état : arrêté.

                  Record Number: 167291
                  Source Name: Service Control Manager
                  Time Written: 20090823214241.000000+120
                  Event Type: Informations
                  User:

                  =====Application event log=====

                  Computer Name:
                  Event Code: 301
                  Message: msnmsgr (2904) \\.\C:\Documents and Settings\rémy\Local Settings\Application Data\Microsoft\Messenger\remytran77@hotmail.com\SharingMetadata\Working\database_CE0_ED03_E0EC_F43C\dfsr.db: Le moteur de base de données commence la relecture du fichier journal \\.\C:\Documents and Settings\rémy\Local Settings\Application Data\Microsoft\Messenger\remytran77@hotmail.com\SharingMetadata\Working\database_CE0_ED03_E0EC_F43C\fsr01C4B.log.

                  Record Number: 51037
                  Source Name: ESENT
                  Time Written: 20090606122022.000000+120
                  Event Type: Informations
                  User:

                  Computer Name:
                  Event Code: 301
                  Message: msnmsgr (2904) \\.\C:\Documents and Settings\rémy\Local Settings\Application Data\Microsoft\Messenger\remytran77@hotmail.com\SharingMetadata\Working\database_CE0_ED03_E0EC_F43C\dfsr.db: Le moteur de base de données commence la relecture du fichier journal \\.\C:\Documents and Settings\rémy\Local Settings\Application Data\Microsoft\Messenger\remytran77@hotmail.com\SharingMetadata\Working\database_CE0_ED03_E0EC_F43C\fsr01C4A.log.

                  Record Number: 51036
                  Source Name: ESENT
                  Time Written: 20090606122022.000000+120
                  Event Type: Informations
                  User:

                  Computer Name:
                  Event Code: 301
                  Message: msnmsgr (2904) \\.\C:\Documents and Settings\rémy\Local Settings\Application Data\Microsoft\Messenger\remytran77@hotmail.com\SharingMetadata\Working\database_CE0_ED03_E0EC_F43C\dfsr.db: Le moteur de base de données commence la relecture du fichier journal \\.\C:\Documents and Settings\rémy\Local Settings\Application Data\Microsoft\Messenger\remytran77@hotmail.com\SharingMetadata\Working\database_CE0_ED03_E0EC_F43C\fsr01C49.log.

                  Record Number: 51035
                  Source Name: ESENT
                  Time Written: 20090606122021.000000+120
                  Event Type: Informations
                  User:

                  Computer Name:
                  Event Code: 301
                  Message: msnmsgr (2904) \\.\C:\Documents and Settings\rémy\Local Settings\Application Data\Microsoft\Messenger\remytran77@hotmail.com\SharingMetadata\Working\database_CE0_ED03_E0EC_F43C\dfsr.db: Le moteur de base de données commence la relecture du fichier journal \\.\C:\Documents and Settings\rémy\Local Settings\Application Data\Microsoft\Messenger\remytran77@hotmail.com\SharingMetadata\Working\database_CE0_ED03_E0EC_F43C\fsr01C48.log.

                  Record Number: 51034
                  Source Name: ESENT
                  Time Written: 20090606122020.000000+120
                  Event Type: Informations
                  User:

                  Computer Name:
                  Event Code: 301
                  Message: msnmsgr (2904) \\.\C:\Documents and Settings\rémy\Local Settings\Application Data\Microsoft\Messenger\remytran77@hotmail.com\SharingMetadata\Working\database_CE0_ED03_E0EC_F43C\dfsr.db: Le moteur de base de données commence la relecture du fichier journal \\.\C:\Documents and Settings\rémy\Local Settings\Application Data\Microsoft\Messenger\remytran77@hotmail.com\SharingMetadata\Working\database_CE0_ED03_E0EC_F43C\fsr01C47.log.

                  Record Number: 51033
                  Source Name: ESENT
                  Time Written: 20090606122020.000000+120
                  Event Type: Informations
                  User:

                  ======Environment variables======

                  "ComSpec"=%SystemRoot%\system32\cmd.exe
                  "FP_NO_HOST_CHECK"=NO
                  "NUMBER_OF_PROCESSORS"=2
                  "OS"=Windows_NT
                  "Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;C:\Program Files\Intel\DMIX;C:\Program Files\ATI Technologies\ATI Control Panel;C:\Program Files\Microsoft Office\OFFICE11\Gestionnaire de contacts professionnels\IM;C:\Program Files\Microsoft SQL Server\80\Tools\Binn\;C:\Program Files\Microsoft Office\OFFICE11\Gestionnaire de contacts professionnels\;C:\Program Files\Fichiers communs\Sonic Shared;C:\Program Files\QuickTime\QTSystem\
                  "PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
                  "PROCESSOR_ARCHITECTURE"=x86
                  "PROCESSOR_IDENTIFIER"=x86 Family 15 Model 4 Stepping 4, GenuineIntel
                  "PROCESSOR_LEVEL"=15
                  "PROCESSOR_REVISION"=0404
                  "SonicCentral"=C:\Program Files\Fichiers communs\Sonic Shared\Sonic Central\
                  "TEMP"=%SystemRoot%\TEMP
                  "TMP"=%SystemRoot%\TEMP
                  "windir"=%SystemRoot%
                  "CLASSPATH"=.;C:\Program Files\Java\jre6\lib\ext\QTJava.zip
                  "QTJAVA"=C:\Program Files\Java\jre6\lib\ext\QTJava.zip

                  -----------------EOF-----------------
                  1. Contributeur sécurité
                    Bonjour,

                    ▶ Télécharge Random's System Information Tool (RSIT).

                    ▶ Un tutoriel sera à ta disposition sur mon site web pour l'installer et l'utiliser correctement.

                    ▶ Double clique sur RSIT.exe pour lancer l'outil.

                    ▶ Clique sur 'Continue' à l'écran Disclaimer.

                    ▶ Si l'outil Hijackthis (version à jour) n'est pas présent ou non détecté sur l'ordinateur, RSIT le téléchargera et tu devras accepter la licence.

                    ▶ Une fois le scan fini , 2 rapports vont apparaitre. Poste le contenu des 2 rapports.

                    ( C:\RSIT\log.txt et C:\RSIT\info.txt )

                    CTRL A pour sélectionner tout, CTRL C pour copier et puis CTRL V pour coller

                    Comment héberger les rapports trop longs de RSIT ??
                    1. Les 2 mêmes clés de registre infectées.
                      1. Bonjour, désolée, je ne sais pas
                        j'ai fait appel à quelqu'un pour qu'il vienne voir
                    2. Malwarebytes' Anti-Malware 1.40
                      Version de la base de données: 2701
                      Windows 5.1.2600 Service Pack 3

                      29/08/2009 11:18:14
                      mbam-log-2009-08-29 (11-18-14).txt

                      Type de recherche: Examen rapide
                      Eléments examinés: 143053
                      Temps écoulé: 9 minute(s), 38 second(s)

                      Processus mémoire infecté(s): 0
                      Module(s) mémoire infecté(s): 0
                      Clé(s) du Registre infectée(s): 0
                      Valeur(s) du Registre infectée(s): 0
                      Elément(s) de données du Registre infecté(s): 2
                      Dossier(s) infecté(s): 0
                      Fichier(s) infecté(s): 0

                      Processus mémoire infecté(s):
                      (Aucun élément nuisible détecté)

                      Module(s) mémoire infecté(s):
                      (Aucun élément nuisible détecté)

                      Clé(s) du Registre infectée(s):
                      (Aucun élément nuisible détecté)

                      Valeur(s) du Registre infectée(s):
                      (Aucun élément nuisible détecté)

                      Elément(s) de données du Registre infecté(s):
                      HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\wuauserv\ImagePath (Hijack.WindowsUpdates) -> Bad: (%fystemroot%\system32\svchost.exe -k netsvcs) Good: (%SystemRoot%\System32\svchost.exe -k netsvcs) -> Quarantined and deleted successfully.
                      HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\BITS\ImagePath (Hijack.WindowsUpdates) -> Bad: (%fystemRoot%\system32\svchost.exe -k netsvcs) Good: (%SystemRoot%\System32\svchost.exe -k netsvcs) -> Quarantined and deleted successfully.

                      Dossier(s) infecté(s):
                      (Aucun élément nuisible détecté)

                      Fichier(s) infecté(s):
                      (Aucun élément nuisible détecté)
                      1. bonjour
                        vide la quarantaine de malwarebytes
                    3. Et à propos du Hijack.Windowsupdates? Parce qu' après un nouveau scan MBAM il ne me détecte plus que celui-là :S
                      1. vide la quarantaine d'Antivir
                        va dans administration, puis dans quarantaine, puis clique sur la petite corbeille
                        poste moi le rapport de MBAM
                    4. Avira AntiVir Personal
                      Date de création du fichier de rapport : vendredi 28 août 2009 16:31

                      La recherche porte sur 1667783 souches de virus.

                      Détenteur de la licence : Avira AntiVir Personal - FREE Antivirus
                      Numéro de série : 0000149996-ADJIE-0000001
                      Plateforme : Windows XP
                      Version de Windows : (Service Pack 3) [5.1.2600]
                      Mode Boot : Démarré normalement
                      Identifiant : SYSTEM
                      Nom de l'ordinateur :

                      Informations de version :
                      BUILD.DAT : 9.0.0.67 17958 Bytes 04/08/2009 14:47:00
                      AVSCAN.EXE : 9.0.3.7 466689 Bytes 21/07/2009 12:35:43
                      AVSCAN.DLL : 9.0.3.0 49409 Bytes 03/03/2009 09:21:02
                      LUKE.DLL : 9.0.3.2 209665 Bytes 20/02/2009 10:35:11
                      LUKERES.DLL : 9.0.2.0 13569 Bytes 03/03/2009 09:21:31
                      ANTIVIR0.VDF : 7.1.0.0 15603712 Bytes 27/10/2008 11:30:36
                      ANTIVIR1.VDF : 7.1.4.132 5707264 Bytes 24/06/2009 08:21:42
                      ANTIVIR2.VDF : 7.1.5.146 3087360 Bytes 21/08/2009 14:29:55
                      ANTIVIR3.VDF : 7.1.5.178 224768 Bytes 28/08/2009 14:29:56
                      Version du moteur : 8.2.1.7
                      AEVDF.DLL : 8.1.1.1 106868 Bytes 28/07/2009 12:17:15
                      AESCRIPT.DLL : 8.1.2.26 463227 Bytes 28/08/2009 14:30:02
                      AESCN.DLL : 8.1.2.4 127348 Bytes 23/07/2009 08:59:39
                      AERDL.DLL : 8.1.2.4 430452 Bytes 23/07/2009 08:59:39
                      AEPACK.DLL : 8.1.3.18 401783 Bytes 28/07/2009 12:17:14
                      AEOFFICE.DLL : 8.1.0.38 196987 Bytes 23/07/2009 08:59:39
                      AEHEUR.DLL : 8.1.0.155 1921400 Bytes 28/08/2009 14:30:01
                      AEHELP.DLL : 8.1.6.0 233846 Bytes 28/08/2009 14:29:58
                      AEGEN.DLL : 8.1.1.59 356725 Bytes 28/08/2009 14:29:57
                      AEEMU.DLL : 8.1.0.9 393588 Bytes 09/10/2008 13:32:40
                      AECORE.DLL : 8.1.7.6 184694 Bytes 23/07/2009 08:59:39
                      AEBB.DLL : 8.1.0.3 53618 Bytes 09/10/2008 13:32:40
                      AVWINLL.DLL : 9.0.0.3 18177 Bytes 12/12/2008 07:47:30
                      AVPREF.DLL : 9.0.0.1 43777 Bytes 03/12/2008 10:39:26
                      AVREP.DLL : 8.0.0.3 155905 Bytes 20/01/2009 13:34:28
                      AVREG.DLL : 9.0.0.0 36609 Bytes 07/11/2008 14:24:42
                      AVARKT.DLL : 9.0.0.3 292609 Bytes 24/03/2009 14:05:22
                      AVEVTLOG.DLL : 9.0.0.7 167169 Bytes 30/01/2009 09:36:37
                      SQLITE3.DLL : 3.6.1.0 326401 Bytes 28/01/2009 14:03:49
                      SMTPLIB.DLL : 9.2.0.25 28417 Bytes 02/02/2009 07:20:57
                      NETNT.DLL : 9.0.0.0 11521 Bytes 07/11/2008 14:40:59
                      RCIMAGE.DLL : 9.0.0.25 2438913 Bytes 17/06/2009 12:44:26
                      RCTEXT.DLL : 9.0.37.0 88321 Bytes 15/04/2009 09:07:05

                      Configuration pour la recherche actuelle :
                      Nom de la tâche...............................: Contrôle intégral du système
                      Fichier de configuration......................: c:\program files\avira\antivir desktop\sysscan.avp
                      Documentation.................................: bas
                      Action principale.............................: interactif
                      Action secondaire.............................: ignorer
                      Recherche sur les secteurs d'amorçage maître..: marche
                      Recherche sur les secteurs d'amorçage.........: marche
                      Secteurs d'amorçage...........................: C:,
                      Recherche dans les programmes actifs..........: marche
                      Recherche en cours sur l'enregistrement.......: marche
                      Recherche de Rootkits.........................: marche
                      Contrôle d'intégrité de fichiers système......: arrêt
                      Fichier mode de recherche.....................: Tous les fichiers
                      Recherche sur les archives....................: marche
                      Limiter la profondeur de récursivité..........: 20
                      Archive Smart Extensions......................: marche
                      Heuristique de macrovirus.....................: marche
                      Heuristique fichier...........................: moyen
                      Catégories de dangers divergentes.............: +SPR,

                      Début de la recherche : vendredi 28 août 2009 16:31

                      La recherche d'objets cachés commence.
                      HKEY_LOCAL_MACHINE\System\ControlSet006\Services\TDSSserv\modules
                      [INFO] L'entrée d'enregistrement n'est pas visible.
                      HKEY_LOCAL_MACHINE\System\ControlSet006\Services\TDSSserv\start
                      [INFO] L'entrée d'enregistrement n'est pas visible.
                      HKEY_LOCAL_MACHINE\System\ControlSet006\Services\TDSSserv\type
                      [INFO] L'entrée d'enregistrement n'est pas visible.
                      HKEY_LOCAL_MACHINE\System\ControlSet006\Services\TDSSserv\imagepath
                      [INFO] L'entrée d'enregistrement n'est pas visible.
                      '83699' objets ont été contrôlés, '4' objets cachés ont été trouvés.

                      La recherche sur les processus démarrés commence :
                      Processus de recherche 'avscan.exe' - '1' module(s) sont contrôlés
                      Processus de recherche 'avcenter.exe' - '1' module(s) sont contrôlés
                      Processus de recherche 'avcenter.exe' - '1' module(s) sont contrôlés
                      Processus de recherche 'avgnt.exe' - '1' module(s) sont contrôlés
                      Processus de recherche 'sched.exe' - '1' module(s) sont contrôlés
                      Processus de recherche 'avguard.exe' - '1' module(s) sont contrôlés
                      Processus de recherche 'msiexec.exe' - '1' module(s) sont contrôlés
                      Processus de recherche 'svchost.exe' - '1' module(s) sont contrôlés
                      Processus de recherche 'firefox.exe' - '1' module(s) sont contrôlés
                      Processus de recherche 'wmplayer.exe' - '1' module(s) sont contrôlés
                      Processus de recherche 'BitComet.exe' - '1' module(s) sont contrôlés
                      Processus de recherche 'iPodService.exe' - '1' module(s) sont contrôlés
                      Processus de recherche 'soffice.bin' - '1' module(s) sont contrôlés
                      Processus de recherche 'soffice.exe' - '1' module(s) sont contrôlés
                      Processus de recherche 'Plauto.exe' - '1' module(s) sont contrôlés
                      Processus de recherche 'WLANUTL.exe' - '1' module(s) sont contrôlés
                      Processus de recherche 'veohwebplayer.exe' - '1' module(s) sont contrôlés
                      Processus de recherche 'GoogleToolbarNotifier.exe' - '1' module(s) sont contrôlés
                      Processus de recherche 'msmsgs.exe' - '1' module(s) sont contrôlés
                      Processus de recherche 'hpgs2wnf.exe' - '1' module(s) sont contrôlés
                      Processus de recherche 'FxSvr2.exe' - '1' module(s) sont contrôlés
                      Processus de recherche 'ctfmon.exe' - '1' module(s) sont contrôlés
                      Processus de recherche 'jusched.exe' - '1' module(s) sont contrôlés
                      Processus de recherche 'iTunesHelper.exe' - '1' module(s) sont contrôlés
                      Processus de recherche 'hpgs2wnd.exe' - '1' module(s) sont contrôlés
                      Processus de recherche 'tfswctrl.exe' - '1' module(s) sont contrôlés
                      Processus de recherche 'LogiTray.exe' - '1' module(s) sont contrôlés
                      Processus de recherche 'Portctrl.exe' - '1' module(s) sont contrôlés
                      Processus de recherche 'LVCOMSX.EXE' - '1' module(s) sont contrôlés
                      Processus de recherche 'issch.exe' - '1' module(s) sont contrôlés
                      Processus de recherche 'DMXLauncher.exe' - '1' module(s) sont contrôlés
                      Processus de recherche 'DVDLauncher.exe' - '1' module(s) sont contrôlés
                      Processus de recherche 'CTHELPER.EXE' - '1' module(s) sont contrôlés
                      Processus de recherche 'CTDVDDET.exe' - '1' module(s) sont contrôlés
                      Processus de recherche 'CTSysVol.exe' - '1' module(s) sont contrôlés
                      Processus de recherche 'IntelMEM.exe' - '1' module(s) sont contrôlés
                      Processus de recherche 'IAAnotif.exe' - '1' module(s) sont contrôlés
                      Processus de recherche 'SbPFCl.exe' - '1' module(s) sont contrôlés
                      Processus de recherche 'explorer.exe' - '1' module(s) sont contrôlés
                      Processus de recherche 'alg.exe' - '1' module(s) sont contrôlés
                      Processus de recherche 'svchost.exe' - '1' module(s) sont contrôlés
                      Processus de recherche 'SbPFSvc.exe' - '1' module(s) sont contrôlés
                      Processus de recherche 'SbPFLnch.exe' - '1' module(s) sont contrôlés
                      Processus de recherche 'sqlservr.exe' - '1' module(s) sont contrôlés
                      Processus de recherche 'MDM.EXE' - '1' module(s) sont contrôlés
                      Processus de recherche 'jqs.exe' - '1' module(s) sont contrôlés
                      Processus de recherche 'IAANTMon.exe' - '1' module(s) sont contrôlés
                      Processus de recherche 'CTSVCCDA.EXE' - '1' module(s) sont contrôlés
                      Processus de recherche 'cisvc.exe' - '1' module(s) sont contrôlés
                      Processus de recherche 'svchost.exe' - '1' module(s) sont contrôlés
                      Processus de recherche 'mDNSResponder.exe' - '1' module(s) sont contrôlés
                      Processus de recherche 'AppleMobileDeviceService.exe' - '1' module(s) sont contrôlés
                      Processus de recherche 'svchost.exe' - '1' module(s) sont contrôlés
                      Processus de recherche 'LEXPPS.EXE' - '1' module(s) sont contrôlés
                      Processus de recherche 'spoolsv.exe' - '1' module(s) sont contrôlés
                      Processus de recherche 'LEXBCES.EXE' - '1' module(s) sont contrôlés
                      Processus de recherche 'svchost.exe' - '1' module(s) sont contrôlés
                      Processus de recherche 'svchost.exe' - '1' module(s) sont contrôlés
                      Processus de recherche 'svchost.exe' - '1' module(s) sont contrôlés
                      Processus de recherche 'svchost.exe' - '1' module(s) sont contrôlés
                      Processus de recherche 'svchost.exe' - '1' module(s) sont contrôlés
                      Processus de recherche 'ati2evxx.exe' - '1' module(s) sont contrôlés
                      Processus de recherche 'lsass.exe' - '1' module(s) sont contrôlés
                      Processus de recherche 'services.exe' - '1' module(s) sont contrôlés
                      Processus de recherche 'winlogon.exe' - '1' module(s) sont contrôlés
                      Processus de recherche 'csrss.exe' - '1' module(s) sont contrôlés
                      Processus de recherche 'smss.exe' - '1' module(s) sont contrôlés
                      '67' processus ont été contrôlés avec '67' modules

                      La recherche sur les secteurs d'amorçage maître commence :
                      Secteur d'amorçage maître HD0
                      [INFO] Aucun virus trouvé !
                      Secteur d'amorçage maître HD1
                      [INFO] Aucun virus trouvé !
                      Secteur d'amorçage maître HD2
                      [INFO] Aucun virus trouvé !
                      Secteur d'amorçage maître HD3
                      [INFO] Aucun virus trouvé !
                      Secteur d'amorçage maître HD4
                      [INFO] Aucun virus trouvé !

                      La recherche sur les secteurs d'amorçage commence :
                      Secteur d'amorçage 'C:\'
                      [INFO] Aucun virus trouvé !

                      La recherche sur les renvois aux fichiers exécutables (registre) commence :
                      Le registre a été contrôlé ( '78' fichiers).

                      La recherche sur les fichiers sélectionnés commence :

                      Recherche débutant dans 'C:\'
                      C:\hiberfil.sys
                      [AVERTISSEMENT] Impossible d'ouvrir le fichier !
                      [REMARQUE] Ce fichier est un fichier système Windows.
                      [REMARQUE] Il est correct que ce fichier ne puisse pas être ouvert pour la recherche.
                      C:\pagefile.sys
                      [AVERTISSEMENT] Impossible d'ouvrir le fichier !
                      [REMARQUE] Ce fichier est un fichier système Windows.
                      [REMARQUE] Il est correct que ce fichier ne puisse pas être ouvert pour la recherche.
                      C:\System Volume Information\_restore{340C3340-2EBB-4324-859A-C37E85627171}\RP235\A0060989.dll
                      [RESULTAT] Contient le cheval de Troie TR/Trash.Gen
                      C:\System Volume Information\_restore{340C3340-2EBB-4324-859A-C37E85627171}\RP259\A0063771.sys
                      [RESULTAT] Contient le cheval de Troie TR/Rootkit.Gen
                      C:\WINDOWS\$NtServicePackUninstall$\spuninst\spuninst.inf
                      [RESULTAT] Contient le modèle de détection du virus de script HTML HTML/Malicious.ActiveX.Gen
                      C:\WINDOWS\system32\12520437n.exe
                      [RESULTAT] Contient le modèle de détection du programme backdoor (dangereux) BDS/Agent.agrd
                      [AVERTISSEMENT] Impossible d'ouvrir le fichier !
                      C:\WINDOWS\system32\drivers\sptd.sys
                      [AVERTISSEMENT] Impossible d'ouvrir le fichier !

                      Début de la désinfection :
                      C:\System Volume Information\_restore{340C3340-2EBB-4324-859A-C37E85627171}\RP235\A0060989.dll
                      [RESULTAT] Contient le cheval de Troie TR/Trash.Gen
                      [REMARQUE] Le fichier a été déplacé dans le répertoire de quarantaine sous le nom '4ac815f3.qua' !
                      C:\System Volume Information\_restore{340C3340-2EBB-4324-859A-C37E85627171}\RP259\A0063771.sys
                      [RESULTAT] Contient le cheval de Troie TR/Rootkit.Gen
                      [REMARQUE] Le fichier a été déplacé dans le répertoire de quarantaine sous le nom '4ac815f4.qua' !
                      C:\WINDOWS\$NtServicePackUninstall$\spuninst\spuninst.inf
                      [RESULTAT] Contient le modèle de détection du virus de script HTML HTML/Malicious.ActiveX.Gen
                      [REMARQUE] Le fichier a été déplacé dans le répertoire de quarantaine sous le nom '4b0d1635.qua' !
                      C:\WINDOWS\system32\12520437n.exe
                      [RESULTAT] Contient le modèle de détection du programme backdoor (dangereux) BDS/Agent.agrd
                      [AVERTISSEMENT] Erreur lors de la création d'une copie de sécurité du fichier. Le fichier n'a pas été supprimé. Code d'erreur : 26004
                      [AVERTISSEMENT] Impossible de trouver le fichier source.
                      [REMARQUE] Tentative en cours d'exécuter l'action à l'aide de la bibliothèque ARK.
                      [REMARQUE] Le fichier a été déplacé dans le répertoire de quarantaine sous le nom '4acd15f8.qua' !

                      Fin de la recherche : vendredi 28 août 2009 19:37
                      Temps nécessaire: 1:30:52 Heure(s)

                      La recherche a été effectuée intégralement

                      17554 Les répertoires ont été contrôlés
                      469453 Des fichiers ont été contrôlés
                      4 Des virus ou programmes indésirables ont été trouvés
                      0 Des fichiers ont été classés comme suspects
                      0 Des fichiers ont été supprimés
                      0 Des virus ou programmes indésirables ont été réparés
                      4 Les fichiers ont été déplacés dans la quarantaine
                      0 Les fichiers ont été renommés
                      4 Impossible de contrôler des fichiers
                      469445 Fichiers non infectés
                      11737 Les archives ont été contrôlées
                      4 Avertissements
                      6 Consignes
                      83699 Des objets ont été contrôlés lors du Rootkitscan
                      4 Des objets cachés ont été trouvés
                      • 1
                      • 2