Ordinateur infecté??

Bonsoire tout le monde mon pere a un ordinateur portable et il voudrai savoir pourquoi sa se deconne tout seul et des fois quand sa se deconnecte sa se reconnecte plus du tout sa arrive de temps en temps il utilise une clé wifi
est ce qu'il y a des virus ou autre chose il voudrai de l'aide

merci d'avance
Configuration: Windows XP Internet Explorer 7.0

22 réponses

  1. peut-on revenir m'aider s'il vous plais c'urgent lordi ne se connecte plus sa m'enerve
    0
    1. rapport antivir

      Avira AntiVir Personal
      Report file date: dimanche 4 octobre 2009 08:13

      Scanning for 1772828 virus strains and unwanted programs.

      Licensee : Avira AntiVir Personal - FREE Antivirus
      Serial number : 0000149996-ADJIE-0000001
      Platform : Windows XP
      Windows version : (Service Pack 3) [5.1.2600]
      Boot mode : Normally booted
      Username : yoann
      Computer name : YOANN-43400310E

      Version information:
      BUILD.DAT : 9.0.0.407 17961 Bytes 29/07/2009 10:34:00
      AVSCAN.EXE : 9.0.3.7 466689 Bytes 21/07/2009 12:36:14
      AVSCAN.DLL : 9.0.3.0 40705 Bytes 27/02/2009 09:58:24
      LUKE.DLL : 9.0.3.2 209665 Bytes 20/02/2009 10:35:49
      LUKERES.DLL : 9.0.2.0 12033 Bytes 27/02/2009 09:58:52
      ANTIVIR0.VDF : 7.1.0.0 15603712 Bytes 27/10/2008 11:30:36
      ANTIVIR1.VDF : 7.1.4.132 5707264 Bytes 24/06/2009 08:21:42
      ANTIVIR2.VDF : 7.1.6.50 4333568 Bytes 29/09/2009 05:50:13
      ANTIVIR3.VDF : 7.1.6.68 216576 Bytes 02/10/2009 05:50:17
      Engineversion : 8.2.1.33
      AEVDF.DLL : 8.1.1.2 106867 Bytes 04/10/2009 05:51:01
      AESCRIPT.DLL : 8.1.2.35 483707 Bytes 04/10/2009 05:50:59
      AESCN.DLL : 8.1.2.5 127346 Bytes 04/10/2009 05:50:54
      AERDL.DLL : 8.1.3.2 479604 Bytes 04/10/2009 05:50:52
      AEPACK.DLL : 8.2.0.0 422261 Bytes 04/10/2009 05:50:48
      AEOFFICE.DLL : 8.1.0.38 196987 Bytes 23/07/2009 08:59:39
      AEHEUR.DLL : 8.1.0.166 2003319 Bytes 04/10/2009 05:50:43
      AEHELP.DLL : 8.1.7.0 237940 Bytes 04/10/2009 05:50:28
      AEGEN.DLL : 8.1.1.67 364916 Bytes 04/10/2009 05:50:26
      AEEMU.DLL : 8.1.1.0 393587 Bytes 04/10/2009 05:50:21
      AECORE.DLL : 8.1.8.1 184693 Bytes 04/10/2009 05:50:19
      AEBB.DLL : 8.1.0.3 53618 Bytes 09/10/2008 13:32:40
      AVWINLL.DLL : 9.0.0.3 18177 Bytes 12/12/2008 07:47:59
      AVPREF.DLL : 9.0.0.1 43777 Bytes 05/12/2008 09:32:15
      AVREP.DLL : 8.0.0.3 155905 Bytes 20/01/2009 13:34:28
      AVREG.DLL : 9.0.0.0 36609 Bytes 05/12/2008 09:32:09
      AVARKT.DLL : 9.0.0.3 292609 Bytes 24/03/2009 14:05:41
      AVEVTLOG.DLL : 9.0.0.7 167169 Bytes 30/01/2009 09:37:08
      SQLITE3.DLL : 3.6.1.0 326401 Bytes 28/01/2009 14:03:49
      SMTPLIB.DLL : 9.2.0.25 28417 Bytes 02/02/2009 07:21:33
      NETNT.DLL : 9.0.0.0 11521 Bytes 05/12/2008 09:32:10
      RCIMAGE.DLL : 9.0.0.25 2438913 Bytes 15/05/2009 14:39:58
      RCTEXT.DLL : 9.0.37.0 86785 Bytes 17/04/2009 09:19:48

      Configuration settings for the scan:
      Jobname.............................: Complete system scan
      Configuration file..................: c:\program files\avira\antivir desktop\sysscan.avp
      Logging.............................: high
      Primary action......................: interactive
      Secondary action....................: ignore
      Scan master boot sector.............: on
      Scan boot sector....................: on
      Boot sectors........................: C:, D:,
      Process scan........................: on
      Scan registry.......................: on
      Search for rootkits.................: on
      Integrity checking of system files..: off
      Scan all files......................: All files
      Scan archives.......................: on
      Recursion depth.....................: 20
      Smart extensions....................: on
      Macro heuristic.....................: on
      File heuristic......................: medium
      Deviating risk categories...........: +APPL,+GAME,+JOKE,+PCK,+SPR,
      Expanded search settings............: 0x00001000

      Start of the scan: dimanche 4 octobre 2009 08:13

      Starting search for hidden objects.
      The driver could not be initialized.

      The scan of running processes will be started
      Scan process 'java.exe' - '1' Module(s) have been scanned
      Module is OK -> 'C:\Program Files\Java\jre6\bin\java.exe'
      Scan process 'svchost.exe' - '0' Module(s) have been scanned
      Scan process 'avscan.exe' - '1' Module(s) have been scanned
      Module is OK -> 'c:\program files\avira\antivir desktop\avscan.exe'
      Scan process 'avcenter.exe' - '1' Module(s) have been scanned
      Module is OK -> 'c:\program files\avira\antivir desktop\avcenter.exe'
      Scan process 'wlcomm.exe' - '1' Module(s) have been scanned
      Module is OK -> 'C:\Program Files\Windows Live\Contacts\wlcomm.exe'
      Scan process 'WindowsSearch.exe' - '1' Module(s) have been scanned
      Module is OK -> 'C:\Program Files\Windows Desktop Search\WindowsSearch.exe'
      Scan process 'WLANUTL.EXE' - '1' Module(s) have been scanned
      Module is OK -> 'C:\Program Files\SAGEM WiFi manager\WLANUTL.exe'
      Scan process 'Netlog24Notifier.exe' - '1' Module(s) have been scanned
      Module is OK -> 'C:\Program Files\Netlog 24\Notifier\Netlog24Notifier.exe'
      Scan process 'GoogleToolbarNotifier.exe' - '1' Module(s) have been scanned
      Module is OK -> 'C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe'
      Scan process 'SuperCopier2.exe' - '1' Module(s) have been scanned
      Module is OK -> 'C:\Program Files\SuperCopier2\SuperCopier2.exe'
      Scan process 'wmiprvse.exe' - '1' Module(s) have been scanned
      Module is OK -> 'C:\WINDOWS\system32\wbem\wmiprvse.exe'
      Scan process 'msnmsgr.exe' - '1' Module(s) have been scanned
      Module is OK -> 'C:\Program Files\Windows Live\Messenger\msnmsgr.exe'
      Scan process 'ctfmon.exe' - '1' Module(s) have been scanned
      Module is OK -> 'C:\WINDOWS\system32\ctfmon.exe'
      Scan process 'avgnt.exe' - '1' Module(s) have been scanned
      Module is OK -> 'C:\Program Files\Avira\AntiVir Desktop\avgnt.exe'
      Scan process 'jusched.exe' - '1' Module(s) have been scanned
      Module is OK -> 'C:\Program Files\Java\jre6\bin\jusched.exe'
      Scan process 'LVCOMSX.EXE' - '1' Module(s) have been scanned
      Module is OK -> 'C:\WINDOWS\system32\LVCOMSX.EXE'
      Scan process 'wmiapsrv.exe' - '1' Module(s) have been scanned
      Module is OK -> 'C:\WINDOWS\system32\wbem\wmiapsrv.exe'
      Scan process 'alg.exe' - '1' Module(s) have been scanned
      Module is OK -> 'C:\WINDOWS\System32\alg.exe'
      Scan process 'wuauclt.exe' - '1' Module(s) have been scanned
      Module is OK -> 'C:\WINDOWS\system32\wuauclt.exe'
      Scan process 'explorer.exe' - '1' Module(s) have been scanned
      Module is OK -> 'C:\WINDOWS\Explorer.EXE'
      Scan process 'searchindexer.exe' - '1' Module(s) have been scanned
      Module is OK -> 'C:\WINDOWS\system32\SearchIndexer.exe'
      Scan process 'SeaPort.exe' - '1' Module(s) have been scanned
      Module is OK -> 'C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe'
      Scan process 'lxctcoms.exe' - '1' Module(s) have been scanned
      Module is OK -> 'C:\WINDOWS\system32\lxctcoms.exe'
      Scan process 'jqs.exe' - '1' Module(s) have been scanned
      Module is OK -> 'C:\Program Files\Java\jre6\bin\jqs.exe'
      Scan process 'spoolsv.exe' - '1' Module(s) have been scanned
      Module is OK -> 'C:\WINDOWS\system32\spoolsv.exe'
      Scan process 'svchost.exe' - '1' Module(s) have been scanned
      Module is OK -> 'C:\WINDOWS\system32\svchost.exe'
      Scan process 'svchost.exe' - '1' Module(s) have been scanned
      Module is OK -> 'C:\WINDOWS\system32\svchost.exe'
      Scan process 'svchost.exe' - '1' Module(s) have been scanned
      Module is OK -> 'C:\WINDOWS\System32\svchost.exe'
      Scan process 'svchost.exe' - '1' Module(s) have been scanned
      Module is OK -> 'C:\WINDOWS\system32\svchost.exe'
      Scan process 'svchost.exe' - '1' Module(s) have been scanned
      Module is OK -> 'C:\WINDOWS\system32\svchost.exe'
      Scan process 'lsass.exe' - '1' Module(s) have been scanned
      Module is OK -> 'C:\WINDOWS\system32\lsass.exe'
      Scan process 'services.exe' - '1' Module(s) have been scanned
      Module is OK -> 'C:\WINDOWS\system32\services.exe'
      Scan process 'winlogon.exe' - '1' Module(s) have been scanned
      Module is OK -> 'C:\WINDOWS\system32\winlogon.exe'
      Scan process 'csrss.exe' - '1' Module(s) have been scanned
      Module is OK -> 'C:\WINDOWS\system32\csrss.exe'
      Scan process 'smss.exe' - '1' Module(s) have been scanned
      Module is OK -> 'C:\WINDOWS\System32\smss.exe'
      34 processes with 34 modules were scanned

      Starting master boot sector scan:
      Master boot sector HD0
      [INFO] No virus was found!

      Start scanning boot sectors:
      Boot sector 'C:\'
      [INFO] No virus was found!
      Boot sector 'D:\'
      [INFO] No virus was found!

      Starting to scan executable files (registry).
      C:\WINDOWS\system32\
      crypt32.dll
      [INFO] HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain\DllName
      C:\WINDOWS\system32\
      cryptnet.dll
      [INFO] HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet\DllName
      C:\WINDOWS\system32\
      cscdll.dll
      [INFO] HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll\DLLName
      C:\WINDOWS\system32\
      dimsntfy.dll
      [INFO] HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\dimsntfy\DllName
      C:\WINDOWS\system32\
      LMIinit.dll
      [INFO] HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\LMIinit\DllName
      C:\WINDOWS\system32\
      wlnotify.dll
      [INFO] HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp\DLLName
      C:\WINDOWS\system32\
      wlnotify.dll
      [INFO] HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule\DllName
      C:\WINDOWS\system32\
      sclgntfy.dll
      [INFO] HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy\DllName
      C:\WINDOWS\system32\
      ntsd.EXE
      [INFO] HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Your Image File Name Here without a path\Debugger
      C:\WINDOWS\system32\
      LVCOMSX.EXE
      [INFO] HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\LVCOMSX
      C:\Program Files\Logitech\Video\
      ISStart.exe
      [INFO] HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\LogitechVideoRepair
      C:\WINDOWS\system32\
      rundll32.EXE
      [INFO] HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\LXCTCATS
      C:\WINDOWS\system32\spool\drivers\w32x86\3\
      lxcttime.dll
      [INFO] HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\LXCTCATS
      C:\Program Files\Windows Live\Writer\
      WriterBrowserExtension.dll
      [INFO] HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{219C3416-8CB2-491a-A3C7-D9FCDDC9D600}\HotIcon
      C:\Program Files\Windows Live\Writer\
      WriterBrowserExtension.dll
      [INFO] HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{219C3416-8CB2-491a-A3C7-D9FCDDC9D600}\Icon
      C:\Program Files\Microsoft Office\Office12\
      REFBAR.ICO
      [INFO] HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{92780B25-18CC-41C8-B9BE-3C9C571A8263}\Icon
      C:\Program Files\Microsoft Office\Office12\
      REFBARH.ICO
      [INFO] HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{92780B25-18CC-41C8-B9BE-3C9C571A8263}\HotIcon
      C:\Program Files\Messenger\
      msmsgs.exe
      [INFO] HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{FB5F1910-F110-11d2-BB9E-00C04F795683}\Exec
      C:\Program Files\Messenger\
      msmsgs.exe
      [INFO] HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{FB5F1910-F110-11d2-BB9E-00C04F795683}\HotIcon
      C:\WINDOWS\
      Explorer.EXE
      [INFO] HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\<{12d0ed0d-0ee0-4f90-8827-78cefb8f4988}
      C:\WINDOWS\
      Explorer.EXE
      [INFO] HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\<{12d0ed0d-0ee0-4f90-8827-78cefb8f4988}
      C:\WINDOWS\system32\
      IEUDINIT.EXE
      [INFO] HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\<{12d0ed0d-0ee0-4f90-8827-78cefb8f4988}\ComponentID
      C:\WINDOWS\inf\
      unregmp2.exe
      [INFO] HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}\Stubpath
      C:\WINDOWS\system32\
      ie4uinit.exe
      [INFO] HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{26923b43-4d38-484f-9b9e-de460746276c}\StubPath
      C:\WINDOWS\system32\
      iedkcs32.dll
      [INFO] HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}\StubPath
      C:\WINDOWS\system32\
      shmgrate.exe
      [INFO] HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}\StubPath
      C:\WINDOWS\system32\
      Java.EXE
      [INFO] HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{08B0E5C0-4FCB-11CF-AAA5-00401C608500}
      C:\Program Files\Java\jre6\bin\
      regutils.dll
      [INFO] HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{08B0E5C0-4FCB-11CF-AAA5-00401C608500}\KeyFileName
      C:\WINDOWS\system32\
      Graphics.COM
      [INFO] HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{10072CEC-8CC1-11D1-986E-00A0C955B42F}
      C:\WINDOWS\system32\
      Graphics.COM
      [INFO] HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{10072CEC-8CC1-11D1-986E-00A0C955B42F}
      C:\WINDOWS\system32\
      Setup.EXE
      [INFO] HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}
      C:\WINDOWS\system32\
      themeui.dll
      [INFO] HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}\StubPath
      C:\WINDOWS\system32\
      themeui.dll
      [INFO] HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}\StubPath
      C:\WINDOWS\system32\
      user.EXE
      [INFO] HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}\StubPath
      C:\WINDOWS\system32\
      user.EXE
      [INFO] HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}\StubPath
      C:\WINDOWS\inf\
      msnetmtg.inf
      [INFO] HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA842-CC51-11CF-AAFA-00AA00B6015B}\StubPath
      C:\WINDOWS\inf\
      msnetmtg.inf
      [INFO] HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA842-CC51-11CF-AAFA-00AA00B6015B}\StubPath
      C:\WINDOWS\inf\
      msmsgs.inf
      [INFO] HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{5945c046-1e7d-11d1-bc44-00c04fd912be}\StubPath
      C:\WINDOWS\inf\
      msmsgs.inf
      [INFO] HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{5945c046-1e7d-11d1-bc44-00c04fd912be}\StubPath
      C:\WINDOWS\system32\
      msieftp.dll
      [INFO] HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{630b1da0-b465-11d1-9948-00c04f98bbc9}\KeyFileName
      C:\WINDOWS\inf\
      wmp11.inf
      [INFO] HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}\StubPath
      C:\WINDOWS\inf\
      wmp11.inf
      [INFO] HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}\StubPath
      C:\WINDOWS\system32\
      regsvr32.exe
      [INFO] HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4340}\StubPath
      C:\WINDOWS\system32\
      shell32.dll
      [INFO] HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4340}\StubPath
      C:\WINDOWS\system32\
      shell32.dll
      [INFO] HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4340}\StubPath
      C:\WINDOWS\system32\
      mscories.dll
      [INFO] HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89B4C1CD-B018-4511-B0A1-5476DBF70820}\StubPath
      C:\WINDOWS\system32\
      Help.EXE
      [INFO] HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{de5aed00-a4bf-11d1-9948-00c04f98bbc9}
      C:\WINDOWS\system32\
      ctfmon.exe
      [INFO] HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\CTFMON.EXE
      C:\Program Files\SuperCopier2\
      SuperCopier2.exe
      [INFO] HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\SuperCopier2.exe
      C:\WINDOWS\system32\
      logon.scr
      [INFO] HKEY_CURRENT_USER\Control Panel\Desktop\Scrnsave.exe
      C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\
      desktop.ini
      [INFO] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Common Startup
      C:\WINDOWS\system32\
      desktop.ini
      [INFO] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Common Startup
      C:\WINDOWS\system32\
      desktop.ini
      [INFO] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Common Startup
      C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\
      Utilitaire réseau pour SAGEM Wi-Fi 11g USB adapter.lnk
      [INFO] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Common Startup
      C:\Program Files\SAGEM WiFi manager\
      WLANUTL.EXE
      [INFO] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Common Startup
      C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\
      Windows Search.lnk
      [INFO] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Common Startup
      C:\Program Files\Windows Desktop Search\
      WindowsSearch.exe
      [INFO] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Common Startup
      C:\Documents and Settings\yoann\Menu Démarrer\Programmes\Démarrage\
      desktop.ini
      [INFO] HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Startup
      C:\Documents and Settings\yoann\Menu Démarrer\Programmes\Démarrage\
      desktop.ini
      [INFO] HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Startup
      The registry was scanned ( '59' files ).

      Starting the file scan:

      Begin scan in 'C:\'
      C:\
      .rnd
      AUTOEXEC.BAT
      AVSCAN-20090924-235254-33F5B70E.LOG
      boot.ini
      Bootfont.bin
      CONFIG.SYS
      IO.SYS
      lxctscan.log
      MSDOS.SYS
      NTDETECT.COM
      ntldr
      pagefile.sys
      [WARNING] The file could not be opened!
      [NOTE] This file is a Windows system file.
      [NOTE] This file cannot be opened for scanning.
      UsbFix.txt
      C:\autorun.inf\
      lpt3.This folder was created by UsbFix
      C:\Documents and Settings\All Users\Application Data\
      desktop.ini
      C:\Documents and Settings\All Users\Application Data\5400 Series\Coverpgs\
      Cnfdentl.pg
      FAXLOG32.CDX
      FAXLOG32.DBF
      FAXLOG32.FPT
      Simple.pg
      Standard.pg
      Urgent.pg
      C:\Documents and Settings\All Users\Application Data\Adobe\Acrobat\9.0\Replicate\Security\
      directories.acrodata
      C:\Documents and Settings\All Users\Application Data\Adobe\Updater6\
      AdobeESDGlobalApps.xml
      C:\Documents and Settings\All Users\Application Data\Avira\AntiVir Desktop\
      addr_file.html
      C:\Documents and Settings\All Users\Application Data\Avira\AntiVir Desktop\CONFIG\
      AVWIN.INI
      C:\Documents and Settings\All Users\Application Data\Avira\AntiVir Desktop\EVENTDB\
      avevtdb.dbe
      C:\Documents and Settings\All Users\Application Data\Avira\AntiVir Desktop\IDX\
      master.idx
      C:\Documents and Settings\All Users\Application Data\Avira\AntiVir Desktop\JOBS\
      04b93509.avj
      produpd.avj
      scanjob.avj
      startupd.avj
      updjob.avj
      C:\Documents and Settings\All Users\Application Data\Avira\AntiVir Desktop\LOGFILES\
      avguard.log
      AVSCAN-20091004-081317-573009B5.LOG
      sched.log
      setup.log
      Upd-2009-10-04-07-48-17.log
      C:\Documents and Settings\All Users\Application Data\Avira\AntiVir Desktop\PROFILES\
      folder.avp
      rootkit.avp
      C:\Documents and Settings\All Users\Application Data\Avira\AntiVir Desktop\REPORTS\
      dc10c00a.avl
      C:\Documents and Settings\All Users\Application Data\Avira\AntiVir Desktop\TEMP\AVSCAN-20091004-081316-5700E342\
      avscan_ext
      [WARNING] The file could not be opened!
      C:\Documents and Settings\All Users\Application Data\Google\Custom Buttons\
      TOOLBAR.GOOGLE.COM_O8Y91YHB24Z6SR0SGYSK.XML
      C:\Documents and Settings\All Users\Application Data\Google\Toolbar Dictionary\
      googledict_en2fr.dat
      C:\Documents and Settings\All Users\Application Data\LogiShrd\Updater\
      LUpdateGuid.ini
      LuPersist.ini
      LuUpdater.log
      UpdateList.csv
      C:\Documents and Settings\All Users\Application Data\ma-config.com\
      mcbase.db
      C:\Documents and Settings\All Users\Application Data\ma-config.com\Logs\
      activex.txt
      maconfservice.txt
      C:\Documents and Settings\All Users\Application Data\ma-config.com\Temp\
      mc_18A.tmp
      C:\Documents and Settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\
      ignore.dat
      news.txt
      rules.ref
      C:\Documents and Settings\All Users\Application Data\Messenger Plus!\Custom Sounds\
      BuiltIn37.dat
      C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\
      01800be7dc4b7ce3032fa9373b895ffa_76927399-ebce-4170-a32f-b8474a8b0ef4
      c802764057a6f3f4db0e809712eeb45f_76927399-ebce-4170-a32f-b8474a8b0ef4
      C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\S-1-5-18\
      6d14e4b1d8ca773bab785d1be032546e_76927399-ebce-4170-a32f-b8474a8b0ef4
      d42cc0c3858a58db2db37658219e6400_76927399-ebce-4170-a32f-b8474a8b0ef4
      C:\Documents and Settings\All Users\Application Data\Microsoft\Dr Watson\
      drwtsn32.log
      user.dmp
      C:\Documents and Settings\All Users\Application Data\Microsoft\IdentityCRL\production\
      MetaConfig.xml
      ppcrlconfig.dll
      C:\Documents and Settings\All Users\Application Data\Microsoft\Media Player\
      DefaultStore_59R.bin
      UserMigratedStore_59R.bin
      C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Connections\Pbk\
      sharedaccess.ini
      C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\
      qmgr0.dat
      qmgr1.dat
      C:\Documents and Settings\All Users\Application Data\Microsoft\OFFICE\
      DocumentRepository.ico
      MySharePoints.ico
      MySite.ico
      SharePointPortalSite.ico
      SharePointTeamSite.ico
      C:\Documents and Settings\All Users\Application Data\Microsoft\OFFICE\DATA\
      OPA12.BAK
      opa12.dat
      C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\
      MSS.chk
      MSS.log
      [WARNING] The file could not be opened!
      [NOTE] An attempt is being made to scan the file with the aid of the snapshot driver.
      [WARNING] The snapshot could not be created.
      MSS005C2.log
      MSS005C3.log
      res1.log
      res2.log
      tmp.edb
      [WARNING] The file could not be opened!
      [NOTE] An attempt is being made to scan the file with the aid of the snapshot driver.
      [WARNING] The snapshot could not be created.
      Windows.edb
      [WARNING] The file could not be opened!
      [NOTE] An attempt is being made to scan the file with the aid of the snapshot driver.
      [WARNING] The snapshot could not be created.
      C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\GatherLogs\SystemIndex\
      SystemIndex.1.Crwl
      SystemIndex.10.Crwl
      SystemIndex.11.Crwl
      SystemIndex.12.Crwl
      SystemIndex.13.Crwl
      SystemIndex.14.Crwl
      SystemIndex.15.Crwl
      SystemIndex.16.Crwl
      SystemIndex.17.Crwl
      SystemIndex.18.Crwl
      SystemIndex.19.Crwl
      SystemIndex.2.Crwl
      SystemIndex.20.Crwl
      SystemIndex.21.Crwl
      SystemIndex.22.Crwl
      SystemIndex.23.Crwl
      SystemIndex.24.Crwl
      SystemIndex.25.Crwl
      SystemIndex.26.Crwl
      SystemIndex.27.Crwl
      SystemIndex.28.Crwl
      SystemIndex.29.Crwl
      SystemIndex.3.Crwl
      SystemIndex.30.Crwl
      SystemIndex.31.Crwl
      SystemIndex.32.Crwl
      SystemIndex.33.Crwl
      SystemIndex.34.Crwl
      SystemIndex.35.Crwl
      SystemIndex.36.Crwl
      SystemIndex.37.Crwl
      SystemIndex.38.Crwl
      SystemIndex.39.Crwl
      SystemIndex.4.Crwl
      SystemIndex.40.Crwl
      SystemIndex.41.Crwl
      SystemIndex.42.Crwl
      SystemIndex.43.Crwl
      SystemIndex.44.Crwl
      SystemIndex.45.Crwl
      SystemIndex.46.Crwl
      SystemIndex.47.Crwl
      SystemIndex.48.Crwl
      SystemIndex.49.Crwl
      SystemIndex.5.Crwl
      SystemIndex.50.Crwl
      SystemIndex.51.Crwl
      SystemIndex.52.Crwl
      SystemIndex.53.Crwl
      SystemIndex.54.Crwl
      SystemIndex.55.Crwl
      SystemIndex.56.Crwl
      SystemIndex.57.Crwl
      SystemIndex.58.Crwl
      SystemIndex.59.Crwl
      SystemIndex.6.Crwl
      SystemIndex.60.Crwl
      SystemIndex.61.Crwl
      SystemIndex.62.Crwl
      SystemIndex.63.Crwl
      SystemIndex.64.Crwl
      SystemIndex.65.Crwl
      SystemIndex.66.Crwl
      SystemIndex.67.Crwl
      SystemIndex.68.Crwl
      SystemIndex.69.Crwl
      SystemIndex.7.Crwl
      SystemIndex.70.Crwl
      SystemIndex.71.Crwl
      SystemIndex.72.Crwl
      SystemIndex.73.Crwl
      SystemIndex.74.Crwl
      SystemIndex.75.Crwl
      SystemIndex.76.Crwl
      SystemIndex.77.Crwl
      SystemIndex.78.Crwl
      SystemIndex.79.Crwl
      SystemIndex.8.Crwl
      SystemIndex.80.Crwl
      SystemIndex.81.Crwl
      SystemIndex.82.Crwl
      SystemIndex.83.Crwl
      SystemIndex.84.Crwl
      SystemIndex.85.Crwl
      SystemIndex.86.Crwl
      SystemIndex.87.Crwl
      SystemIndex.88.Crwl
      SystemIndex.89.Crwl
      SystemIndex.89.gthr
      SystemIndex.9.Crwl
      SystemIndex.90.Crwl
      SystemIndex.90.gthr
      SystemIndex.91.Crwl
      SystemIndex.91.gthr
      SystemIndex.92.Crwl
      SystemIndex.92.gthr
      SystemIndex.93.Crwl
      SystemIndex.93.gthr
      C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\
      SystemIndex.chk1.gthr
      SystemIndex.chk2.gthr
      SystemIndex.Crwl61.gthr
      SystemIndex.Ntfy102.gthr
      C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\
      00010001.ci
      00010001.dir
      00010001.wid
      00010002.ci
      00010002.dir
      00010002.wid
      00010003.ci
      00010003.dir
      00010003.wid
      00010004.ci
      00010004.dir
      00010004.wid
      00010005.ci
      00010005.dir
      00010005.wid
      00010006.ci
      00010006.dir
      00010006.wid
      00010007.ci
      00010007.dir
      00010007.wid
      00010008.ci
      00010008.dir
      00010008.wid
      00010009.ci
      00010009.dir
      00010009.wid
      0001000A.ci
      0001000A.dir
      0001000A.wid
      0001000B.ci
      0001000B.dir
      0001000B.wid
      0001000C.ci
      0001000C.dir
      0001000C.wid
      00010010.ci
      00010010.dir
      00010010.wid
      00010010.wsb
      00010014.ci
      00010014.dir
      00010014.wid
      00010016.ci
      00010016.dir
      00010016.wid
      0001001E.ci
      0001001E.dir
      0001001E.wid
      CiAB0001.000
      CiAB0001.001
      CiAB0001.002
      CiAB0002.000
      CiAB0002.001
      CiAB0002.002
      CiAD0002.000
      CiAD0002.001
      CiAD0002.002
      INDEX.000
      INDEX.001
      INDEX.002
      SETTINGS.DIA
      C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\PropMap\
      CiPT0000.000
      CiPT0000.001
      CiPT0000.002
      Used0000.000
      Used0000.001
      Used0000.002
      C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\SecStore\
      CiST0000.000
      CiST0000.001
      CiST0000.002
      C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Temp\usgthrsvc\
      Perflib_Perfdata_258.dat
      [WARNING] The file could not be opened!
      [NOTE] An attempt is being made to scan the file with the aid of the snapshot driver.
      [WARNING] The snapshot could not be created.
      C:\Documents and Settings\All Users\Application Data\Microsoft\Search Enhancement Pack\SeaNote\
      SeaNote.xml
      C:\Documents and Settings\All Users\Application Data\Microsoft\Search Enhancement Pack\SeaPort\
      SeaNote.cab
      SeaPort.cab
      SearchBoxExt.cab
      SHelper.cab
      C:\Documents and Settings\All Users\Application Data\Microsoft\Search Enhancement Pack\Search Box Extension\
      hsconfig.xml
      QueryDat.xml
      C:\Documents and Settings\All Users\Application Data\Microsoft\Search Enhancement Pack\Search Helper\
      shelper.xml
      C:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\
      Administrateur.bmp
      bernard.bmp
      guest.bmp
      yoann.bmp
      C:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\
      airplane.bmp
      astronaut.bmp
      ball.bmp
      beach.bmp
      butterfly.bmp
      car.bmp
      cat.bmp
      chess.bmp
      dirt bike.bmp
      dog.bmp
      drip.bmp
      duck.bmp
      fish.bmp
      frog.bmp
      guitar.bmp
      horses.bmp
      kick.bmp
      lift-off.bmp
      palm tree.bmp
      pink flower.bmp
      red flower.bmp
      skater.bmp
      snowflake.bmp
      C:\Documents and Settings\All Users\Application Data\Microsoft\WLSetup\Logs\
      2009-04-12_00-58_a2c-q2xlpq0f.log
      2009-10-03_17-37_a04-vdbpgru6.log
      C:\Documents and Settings\All Users\Application Data\Microsoft Help\
      Hx.hxn
      Hx_1036_MKWD_K.HxW
      Hx_1036_MKWD_NamedURL.HxW
      Hx_1036_MTOC_Hx.HxH
      Hx_1036_MValidator.HxD
      Hx_1036_MValidator.Lck
      MS.EXCEL.12.1036.hxn
      MS.EXCEL.DEV.12.1036.hxn
      MS.GRAPH.12.1036.hxn
      MS.INFOPATH.12.1036.hxn
      MS.INFOPATHEDITOR.12.1036.hxn
      MS.MSACCESS.12.1036.hxn
      MS.MSACCESS.DEV.12.1036.hxn
      MS.MSE.12.1036.hxn
      MS.MSE_LEGACY.12.1036.hxn
      MS.MSPUB.12.1036.hxn
      MS.MSPUB.DEV.12.1036.hxn
      MS.MSTORE.12.1036.hxn
      MS.OIS.12.1036.hxn
      MS.OUTLOOK.12.1036.hxn
      MS.OUTLOOK.DEV.12.1036.hxn
      MS.POWERPNT.12.1036.hxn
      MS.POWERPNT.DEV.12.1036.hxn
      MS.RIBBON.12.1036.hxn
      MS.SETLANG.12.1036.hxn
      MS.VBE.DEV.12.1036.hxn
      MS.WINWORD.12.1036.hxn
      MS.WINWORD.DEV.12.1036.hxn
      nslist.hxl
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\
      Configuration.ini
      ProcCache.sbc
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Logs\
      Checks.090918-2337.log
      Checks.090919-0028.txt
      Checks.090924-2353.log
      Checks.090925-0045.txt
      Checks.091002-2052.log
      Checks.091002-2306.txt
      Fixes.090919-0548.txt
      Fixes.091002-2308.txt
      Resident.log
      Update downloads.log
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\
      CoolWWWSearchCameUp.zip
      [0] Archive type: ZIP
      --> sbRecovery.reg
      [WARNING] The archive is password protected
      [WARNING] The archive is password protected
      CoolWWWSearchToolband.zip
      [0] Archive type: ZIP
      --> sbRecovery.reg
      [WARNING] The archive is password protected
      [WARNING] The archive is password protected
      Overview.ini
      C:\Documents and Settings\All Users\Application Data\TuneUp Software\TuneUp Utilities\Program Statistics\
      ProgramStatistics.tudb
      C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage\data\
      data.dat
      C:\Documents and Settings\All Users\Application Data\Yahoo! Companion\Data\default\
      us_sres.data
      C:\Documents and Settings\All Users\Application Data\{55A29068-F2CE-456C-9148-C869879E2357}\
      {B3F4072D-1B2C-4B5E-B016-E93C4BEA5AEB}.msi
      C:\Documents and Settings\All Users\Bureau\
      Adobe Reader 9.lnk
      Avira AntiVir Control Center.lnk
      Logitech QuickCam.lnk
      Malwarebytes' Anti-Malware.lnk
      Mes photos Logitech.lnk
      Studio d'imagerie Lexmark - 5400 Series.LNK
      VLC media player.lnk
      C:\Documents and Settings\All Users\Documents\
      desktop.ini
      C:\Documents and Settings\All Users\Documents\Ma musique\
      Desktop.ini
      C:\Documents and Settings\All Users\Documents\Ma musique\Sync Playlists\698266\
      01_Music_auto_rated_at_5_stars.wpl
      02_Music_added_in_the_last_month.wpl
      03_Music_rated_at_4_or_5_stars.wpl
      04_Music_played_in_the_last_month.wpl
      05_Pictures_taken_in_the_last_month.wpl
      06_Pictures_rated_4_or_5_stars.wpl
      07_TV_recorded_in_the_last_week.wpl
      08_Video_rated_at_4_or_5_stars.wpl
      09_Music_played_the_most.wpl
      10_All_Music.wpl
      11_All_Pictures.wpl
      12_All_Video.wpl
      C:\Documents and Settings\All Users\Documents\Ma musique\Échantillons de musique\
      AlbumArtSmall.jpg
      AlbumArt_{E201F44C-B9E2-490F-9ED7-0976E9DA2EA5}_Large.jpg
      AlbumArt_{E201F44C-B9E2-490F-9ED7-0976E9DA2EA5}_Small.jpg
      AlbumArt_{EFFDEB51-C913-4EE1-8B2A-C80112057955}_Large.jpg
      AlbumArt_{EFFDEB51-C913-4EE1-8B2A-C80112057955}_Small.jpg
      desktop.ini
      Folder.jpg
      Nouvelles histoires (le blues de l'autoroute).wma
      Symphonie n° 9 de Beethoven (scherzo).wma
      C:\Documents and Settings\All Users\Documents\Mes images\
      Desktop.ini
      C:\Documents and Settings\All Users\Documents\Mes images\Échantillons d'images\
      Collines.jpg
      Coucher de soleil.jpg
      desktop.ini
      Hiver.jpg
      Nénuphars.jpg
      C:\Documents and Settings\All Users\Documents\Mes vidéos\
      Desktop.ini
      C:\Documents and Settings\All Users\DRM\
      drmstore.hds
      DRMv1.bak
      DRMv1.key
      drmv2.lic
      drmv2.sst
      IndivBox.key
      v2ksndv.bla
      v3ks.bla
      v3ks.sec
      C:\Documents and Settings\All Users\DRM\Cache\
      Indiv01.bla
      Indiv01.key
      C:\Documents and Settings\All Users\Menu Démarrer\
      Catalogue Windows.lnk
      Configurer les programmes par défaut.lnk
      desktop.ini
      Microsoft Update.lnk
      Windows Update.lnk
      C:\Documents and Settings\All Users\Menu Démarrer\Programmes\
      Adobe Reader 9.lnk
      desktop.ini
      MSN.lnk
      Windows Messenger.lnk
      Windows Movie Maker.lnk
      Windows Search.lnk
      C:\Documents and Settings\All Users\Menu Démarrer\Programmes\ABBYY FineReader 6.0 Sprint\
      ABBYY FineReader 6.0 Sprint.lnk
      Guide de l'utilisateur.lnk
      C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Accessoires\
      Calculatrice.lnk
      Connexion Bureau à distance.lnk
      desktop.ini
      Paint.lnk
      Scanner and Camera Wizard.lnk
      WordPad.lnk
      C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Accessoires\Accessibilité\
      Assistant Accessibilité.lnk
      desktop.ini
      C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Accessoires\Communications\
      Assistant Configuration du réseau.lnk
      Assistant Nouvelle connexion.lnk
      Assistant Réseau sans fil.lnk
      Connexions réseau.lnk
      desktop.ini
      HyperTerminal.lnk
      C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Accessoires\Divertissement\
      Contrôle du volume.lnk
      desktop.ini
      Magnétophone.lnk
      C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Accessoires\Outils système\
      Activation de Windows.lnk
      Assistant Transfert de fichiers et de paramètres.lnk
      desktop.ini
      Défragmenteur de disque.lnk
      Informations système.lnk
      Nettoyage de disque.lnk
      Restauration du système.lnk
      Table des caractères.lnk
      Tâches planifiées.lnk
      C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Avira\AntiVir Desktop\
      AntiVir Help.lnk
      AntiVir on the Internet.lnk
      Start AntiVir.lnk
      C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\
      desktop.ini
      Utilitaire réseau pour SAGEM Wi-Fi 11g USB adapter.lnk
      Windows Search.lnk
      C:\Documents and Settings\All Users\Menu Démarrer\Programmes\IDEUtil\
      SISIDE.exe
      C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Jeux\
      Atout Pique sur Internet.lnk
      Backgammon sur Internet.lnk
      Dame de pique sur Internet.lnk
      Dame de Pique.lnk
      desktop.ini
      Démineur.lnk
      Freecell.lnk
      Jeu de dames sur Internet.lnk
      Pinball.lnk
      Reversi sur Internet.lnk
      Solitaire.lnk
      Spider Solitaire.lnk
      C:\Documents and Settings\All Users\Menu Démarrer\Programmes\K-Lite Codec Pack\
      Media Player Classic.lnk
      C:\Documents and Settings\All Users\Menu Démarrer\Programmes\K-Lite Codec Pack\Configuration\
      AC3Filter.lnk
      Codec Tweak Tool.lnk
      DirectVobSub.lnk
      ffdshow audio decoder.lnk
      ffdshow VFW interface.lnk
      ffdshow video decoder.lnk
      Haali Media Splitter.lnk
      Reset to recommended settings.lnk
      Xvid Encoder.lnk
      C:\Documents and Settings\All Users\Menu Démarrer\Programmes\K-Lite Codec Pack\Help\
      FAQ.lnk
      C:\Documents and Settings\All Users\Menu Démarrer\Programmes\K-Lite Codec Pack\Tools\
      Codec Tweak Tool.lnk
      GraphEdit.lnk
      GSpot Codec Information.lnk
      Haali Muxer.lnk
      MediaInfo.lnk
      VobSubStrip.lnk
      Xvid StatsReader.lnk
      C:\Documents and Settings\All Users\Menu Démarrer\Programmes\K-Lite Codec Pack\Uninstall\
      Uninstall K-Lite Codec Pack.lnk
      C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Lexmark 5400 Series\
      Centre de solution Lexmark.LNK
      Centre Tout en un.LNK
      Désinstaller le pilote de l'imprimante Lexmark 5400 Series.LNK
      Guide de l'utilisateur.LNK
      Lexmark Solution Center.LNK
      Lisez-moi.LNK
      Programme d'édition de photos Lexmark.LNK
      Readme.LNK
      Solutions de télécopie Lexmark.LNK
      Studio d'imagerie Lexmark.LNK
      Uninstall Lexmark 5400 Series.LNK
      C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Livebox\
      Configuration de la Livebox.lnk
      Installation TV.url
      Manuel de référence.lnk
      Services optionnels.lnk
      C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Livebox\Utilitaires\
      Désinstallation.lnk
      C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Livebox\Utilitaires\WiFi\
      Désinstaller l'utilitaire réseau pour SAGEM Wi-Fi 11g USB adapter.lnk
      Utilitaire réseau pour SAGEM Wi-Fi 11g USB adapter.lnk
      C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Logitech\
      Logitech QuickCam.lnk
      Mes photos Logitech.lnk
      C:\Documents and Settings\All Users\Menu Démarrer\Programmes\ma-config.com\
      Desinstaller.lnk
      Ma-Config.html.lnk
      Preferences.lnk
      C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Malwarebytes' Anti-Malware\
      Désinstaller Malwarebytes' Anti-Malware.lnk
      Malwarebytes' Anti-Malware Help.lnk
      Malwarebytes' Anti-Malware.lnk
      C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Microsoft Office\
      Microsoft Office Access 2007.lnk
      Microsoft Office Excel 2007.lnk
      Microsoft Office InfoPath 2007.lnk
      Microsoft Office Outlook 2007.lnk
      Microsoft Office PowerPoint 2007.lnk
      Microsoft Office Publisher 2007.lnk
      Microsoft Office Word 2007.lnk
      C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Microsoft Office\Outils Microsoft Office\
      Bibliothèque multimédia Microsoft.lnk
      Certificat numérique pour les projets VBA.lnk
      Microsoft Office 2007 Paramètres de langue.lnk
      Microsoft Office Diagnostics.lnk
      Microsoft Office Picture Manager.lnk
      C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Microsoft Office Live Add-in\
      Aide d'Office Live Add-in.lnk
      Office Live Workspace.lnk
      C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Netlog 24\
      Notifier.lnk
      Uninstall.lnk
      C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Outils d'administration\
      Analyseur de performances.lnk
      Assistants Microsoft .NET Framework 1.1.lnk
      Configuration Microsoft .NET Framework 1.1.lnk
      desktop.ini
      Gestion de l'ordinateur.lnk
      Microsoft .NET Framework 1.1 Configuration.lnk
      Microsoft .NET Framework 1.1 Wizards.lnk
      Observateur d'événements.lnk
      Services de composants.lnk
      Services.lnk
      Sources de données (ODBC).lnk
      C:\Documents and Settings\All Users\Menu Démarrer\Programmes\VideoLAN\
      Documentation.lnk
      Release Notes.lnk
      VideoLAN Website.lnk
      VLC media player.lnk
      C:\Documents and Settings\All Users\Menu Démarrer\Programmes\VideoLAN\Quick Settings\
      Reset VLC media player preferences and cache files.lnk
      C:\Documents and Settings\All Users\Menu Démarrer\Programmes\VideoLAN\Quick Settings\Audio\
      Set Audio mode to DirectX (default).lnk
      Set Audio mode to Waveout.lnk
      C:\Documents and Settings\All Users\Menu Démarrer\Programmes\VideoLAN\Quick Settings\Interface\
      Set Main Interface to Qt (default).lnk
      Set Main Interface to Skinnable.lnk
      C:\Documents and Settings\All Users\Menu Démarrer\Programmes\VideoLAN\Quick Settings\Video\
      Set Video mode to Direct3D (no hardware acceleration).lnk
      Set Video mode to Direct3D.lnk
      Set Video mode to DirectX (no hardware acceleration).lnk
      Set Video mode to DirectX (no video overlay).lnk
      Set Video mode to DirectX.lnk
      Set Video mode to OpenGL.lnk
      C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Windows Live\
      Galerie de photos Windows Live.lnk
      Windows Live Call.lnk
      Windows Live Contrôle parental.lnk
      Windows Live Mail.lnk
      Windows Live Messenger .lnk
      Windows Live Writer.lnk
      C:\Documents and Settings\All Users\Menu Démarrer\Programmes\WinRAR\
      Console RAR manual.lnk
      WinRAR help.lnk
      WinRAR.lnk
      C:\Documents and Settings\bernard\
      NTUSER.DAT
      ntuser.dat.LOG
      ntuser.ini
      C:\Documents and Settings\bernard\Application Data\
      desktop.ini
      C:\Documents and Settings\bernard\Application Data\Adobe\Acrobat\9.0\
      AdobeCMapFnt09.lst
      AdobeSysFnt09.lst
      SharedDataEvents
      UserCache.bin
      C:\Documents and Settings\bernard\Application Data\Adobe\Acrobat\9.0\JavaScripts\
      glob.js
      glob.settings.js
      C:\Documents and Settings\bernard\Application Data\dvdcss\
      CACHEDIR.TAG
      C:\Documents and Settings\bernard\Application Data\Google\Local Search History\
      google%2Eweb.w
      C:\Documents and Settings\bernard\Application Data\Macromedia\Flash Player\#SharedObjects\A5BG8FEC\bin.clearspring.com\
      clearspring.sol
      C:\Documents and Settings\bernard\Application Data\Macromedia\Flash Player\#SharedObjects\A5BG8FEC\broadcast.piximedia.fr\
      piximedia.sol
      C:\Documents and Settings\bernard\Application Data\Macromedia\Flash Player\#SharedObjects\A5BG8FEC\files.deezer.com\
      deezer-v3.sol
      C:\Documents and Settings\bernard\Application Data\Macromedia\Flash Player\#SharedObjects\A5BG8FEC\files.deezer.com\swf\naboo-v37.swf\
      deezer_v3_naboo.sol
      C:\Documents and Settings\bernard\Application Data\Macromedia\Flash Player\#SharedObjects\A5BG8FEC\files.deezer.com\swf\naboo-v38.swf\
      deezer_v3_naboo.sol
      C:\Documents and Settings\bernard\Application Data\Macromedia\Flash Player\#SharedObjects\A5BG8FEC\files.deezer.com\swf\naboo-v39.swf\
      deezer_v3_naboo.sol
      C:\Documents and Settings\bernard\Application Data\Macromedia\Flash Player\#SharedObjects\A5BG8FEC\images.video.msn.com\
      s_br.sol
      VideoWindow.sol
      C:\Documents and Settings\bernard\Application Data\Macromedia\Flash Player\#SharedObjects\A5BG8FEC\load.tubemogul.com\
      InPlayCounts.sol
      StreamMinerInfo.sol
      C:\Documents and Settings\bernard\Application Data\Macromedia\Flash Player\#SharedObjects\A5BG8FEC\mail.google.com\
      wakeup.sol
      C:\Documents and Settings\bernard\Application Data\Macromedia\Flash Player\#SharedObjects\A5BG8FEC\s.ytimg.com\
      soundData.sol
      videostats.sol
      C:\Documents and Settings\bernard\Application Data\Macromedia\Flash Player\#SharedObjects\A5BG8FEC\video.flashtalking.com\
      ft4255-1.sol
      ft4617-1.sol
      C:\Documents and Settings\bernard\Application Data\Macromedia\Flash Player\#SharedObjects\A5BG8FEC\www.dailymotion.com\flash\dmplayer\dmplayer.swf\
      dmplayer.sol
      C:\Documents and Settings\bernard\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\
      settings.sol
      C:\Documents and Settings\bernard\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#bin.clearspring.com\
      settings.sol
      C:\Documents and Settings\bernard\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#broadcast.piximedia.fr\
      settings.sol
      C:\Documents and Settings\bernard\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#files.deezer.com\
      settings.sol
      C:\Documents and Settings\bernard\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#images.soapbox.msn.com\
      settings.sol
      C:\Documents and Settings\bernard\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#images.video.msn.com\
      settings.sol
      C:\Documents and Settings\bernard\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#load.tubemogul.com\
      settings.sol
      C:\Documents and Settings\bernard\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#mail.google.com\
      settings.sol
      C:\Documents and Settings\bernard\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#s.ytimg.com\
      settings.sol
      C:\Documents and Settings\bernard\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#video.flashtalking.com\
      settings.sol
      C:\Documents and Settings\bernard\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#www.dailymotion.com\
      settings.sol
      C:\Documents and Settings\bernard\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#www.wat.tv\
      settings.sol
      C:\Documents and Settings\bernard\Application Data\Media Player Classic\
      default.mpcpl
      C:\Documents and Settings\bernard\Application Data\Microsoft\Address Book\
      bernard.wab
      C:\Documents and Settings\bernard\Application Data\Microsoft\Credentials\S-1-5-21-823518204-706699826-839522115-1007\
      Credentials
      C:\Documents and Settings\bernard\Application Data\Microsoft\CryptnetUrlCache\Content\
      07BF4DE53B25BEE2E3CEF7AA93F39E8A
      0897206B35294097C3660E62BCDB227C
      0EBB3788D77094423275558212CCE7B1
      1B9435E949F2B3D267BABDE0C8BC19A6
      23B523C9E7746F715D33C6527C18EB9D
      25DC8EBAAF0977851B37F37B2F6458F4
      2BBA88436E92E1ABCED8E68D74DC5B38
      2BF68F4714092295550497DD56F57004
      3C19F8F5C2A69BEC912EF5B953293907
      3CE50557B2420D353BF80834FC876984
      5553AF14BD4C3B1DE599145FD14950E0
      56BDEAABA957B2AEC25CCE688FEE4362
      5C45AD19E3530EC4218F560AFC04C3F7
      5F74056C561F814B7771CB2993A44DEB
      60E31627FDA0A46932B0E5948949F2A5
      696F3DE637E6DE85B458996D49D759AD
      71644221AC231DBD2359C18EBB2118DC
      74BFD122C0875EC75DBE5C6DB4C59019
      76D7D71DA8921002BBB4B23CBA5D8BFF
      7B2238AACCEDC3F1FFE8E7EB5F575EC9
      8A071F33CCD31F6D564E666B307E3DD9
      930D1D196EE05A60D0FD6680AB99D0D5
      94308059B57B3142E455B38A6EB92015
      B171751C11ECDD4C0C4BC4BBF7B99FBF
      C554DCF706A5AAB8B360FAD227EAB9C7
      C571B417AAF1F617555A0486AB3F5361
      D725F3459E2275E9EA5871B92AD896D0
      E8974A4669383843486E5AFDB09650F5
      F78CAE5D65CB8F387E2E0E15EF7E4AE3
      FB788E090BC1F3AA2FBC9E8FB2859601
      C:\Documents and Settings\bernard\Application Data\Microsoft\CryptnetUrlCache\MetaData\
      07BF4DE53B25BEE2E3CEF7AA93F39E8A
      0897206B35294097C3660E62BCDB227C
      0EBB3788D77094423275558212CCE7B1
      1B9435E949F2B3D267BABDE0C8BC19A6
      23B523C9E7746F715D33C6527C18EB9D
      25DC8EBAAF0977851B37F37B2F6458F4
      2BBA88436E92E1ABCED8E68D74DC5B38
      2BF68F4714092295550497DD56F57004
      3C19F8F5C2A69BEC912EF5B953293907
      3CE50557B2420D353BF80834FC876984
      5553AF14BD4C3B1DE599145FD14950E0
      56BDEAABA957B2AEC25CCE688FEE4362
      5C45AD19E3530EC4218F560AFC04C3F7
      5F74056C561F814B7771CB2993A44DEB
      60E31627FDA0A46932B0E5948949F2A5
      696F3DE637E6DE85B458996D49D759AD
      71644221AC231DBD2359C18EBB2118DC
      74BFD122C0875EC75DBE5C6DB4C59019
      76D7D71DA8921002BBB4B23CBA5D8BFF
      7B2238AACCEDC3F1FFE8E7EB5F575EC9
      8A071F33CCD31F6D564E666B307E3DD9
      930D1D196EE05A60D0FD6680AB99D0D5
      94308059B57B3142E455B38A6EB92015
      B171751C11ECDD4C0C4BC4BBF7B99FBF
      C554DCF706A5AAB8B360FAD227EAB9C7
      C571B417AAF1F617555A0486AB3F5361
      D725F3459E2275E9EA5871B92AD896D0
      E8974A4669383843486E5AFDB09650F5
      F78CAE5D65CB8F387E2E0E15EF7E4AE3
      FB788E090BC1F3AA2FBC9E8FB2859601
      C:\Documents and Settings\bernard\Application Data\Microsoft\Crypto\RSA\S-1-5-21-823518204-706699826-839522115-1007\
      6b29ae44e85efac3c72ff4d1865d73f1_76927399-ebce-4170-a32f-b8474a8b0ef4
      C:\Documents and Settings\bernard\Application Data\Microsoft\Document Building Blocks\1036\
      Building Blocks.dotx
      C:\Documents and Settings\bernard\Application Data\Microsoft\Internet Explorer\
      brndlog.txt
      Desktop.htt
      C:\Documents and Settings\bernard\Application Data\Microsoft\Internet Explorer\Quick Launch\
      Bureau.scf
      desktop.ini
      Démarrer Internet Explorer.lnk
      Windows Media Player.lnk
      C:\Documents and Settings\bernard\Application Data\Microsoft\Internet Explorer\UserData\
      index.dat
      C:\Documents and Settings\bernard\Application Data\Microsoft\Internet Explorer\UserData\I53K9BYY\
      Tdy58[1].xml
      C:\Documents and Settings\bernard\Application Data\Microsoft\MSN Messenger\
      sqmnoopt00.sqm
      sqmnoopt01.sqm
      sqmnoopt02.sqm
      sqmnoopt03.sqm
      sqmnoopt04.sqm
      sqmnoopt05.sqm
      sqmnoopt06.sqm
      sqmnoopt07.sqm
      sqmnoopt08.sqm
      sqmnoopt09.sqm
      sqmnoopt10.sqm
      sqmnoopt11.sqm
      sqmnoopt12.sqm
      sqmnoopt13.sqm
      sqmnoopt14.sqm
      sqmnoopt15.sqm
      sqmnoopt16.sqm
      sqmnoopt17.sqm
      sqmnoopt18.sqm
      sqmnoopt19.sqm
      C:\Documents and Settings\bernard\Application Data\Microsoft\Office\
      MSO1036.acl
      MSOut12.pip
      OIS12.pip
      Word12.pip
      C:\Documents and Settings\bernard\Application Data\Microsoft\Office\Recent\
      index.dat
      Templates.LNK
      C:\Documents and Settings\bernard\Application Data\Microsoft\OIS\
      Toolbars.dat
      C:\Documents and Settings\bernard\Application Data\Microsoft\Protect\
      CREDHIST
      C:\Documents and Settings\bernard\Application Data\Microsoft\Protect\S-1-5-21-823518204-706699826-839522115-1007\
      39f3add4-e9f4-4b9b-ba24-88d7b07f5af9
      Preferred
      C:\Documents and Settings\bernard\Application Data\Microsoft\Templates\
      Normal.dotm
      C:\Documents and Settings\bernard\Application Data\Microsoft\UProof\
      CUSTOM.DIC
      C:\Documents and Settings\bernard\Application Data\Microsoft\Windows Live\Toolbar\
      toolbar.config
      C:\Documents and Settings\bernard\Application Data\Microsoft\Windows Live\Toolbar\Custom Buttons\microsoft.windowslive.news.btn\
      button.xml
      news.bmp
      C:\Documents and Settings\bernard\Application Data\Microsoft\Windows Live\Toolbar\Custom Buttons\microsoft.windowslive.translator.btn\
      button.xml
      translator.png
      C:\Documents and Settings\bernard\Application Data\Microsoft\Windows Live\Toolbar\Feeds\
      index.xml
      C:\Documents and Settings\bernard\Application Data\Microsoft\Windows Messenger\3498694625\
      ListCache.dat
      C:\Documents and Settings\bernard\Application Data\Sun\Java\Deployment\
      deployment.properties
      C:\Documents and Settings\bernard\Application Data\Sun\Java\Deployment\cache\6.0\
      lastAccessed
      C:\Documents and Settings\bernard\Application Data\Sun\Java\Deployment\cache\6.0\11\
      2b98eb8b-44ea02c9
      2b98eb8b-44ea02c9.idx
      C:\Documents and Settings\bernard\Application Data\Sun\Java\Deployment\cache\6.0\15\
      58fb3e0f-1f00b8fe
      58fb3e0f-1f00b8fe.idx
      C:\Documents and Settings\bernard\Application Data\Sun\Java\Deployment\cache\6.0\15\58fb3e0f-1f00b8fe-n\
      decora-d3d.dll
      decora-sse.dll
      jmc.dll
      msvcp71.dll
      msvcr71.dll
      C:\Documents and Settings\bernard\Application Data\Sun\Java\Deployment\cache\6.0\24\
      2a20e358-382049e6
      2a20e358-382049e6.idx
      C:\Documents and Settings\bernard\Application Data\Sun\Java\Deployment\cache\6.0\26\
      2d280e1a-79b5639f-1.1.1a-
      2d280e1a-79b5639f-1.1.1a-.idx
      C:\Documents and Settings\bernard\Application Data\Sun\Java\Deployment\cache\6.0\32\
      6c34baa0-13fa3f7b.idx
      6c34baa0-42292e87
      6c34baa0-42292e87.idx
      C:\Documents and Settings\bernard\Application Data\Sun\Java\Deployment\cache\6.0\44\
      50f3f12c-4bc24cdf
      50f3f12c-4bc24cdf.idx
      C:\Documents and Settings\bernard\Application Data\Sun\Java\Deployment\cache\6.0\45\
      4f710eed-1759ef39
      4f710eed-1759ef39.idx
      C:\Documents and Settings\bernard\Application Data\Sun\Java\Deployment\cache\6.0\45\4f710eed-1759ef39-n\
      gluegen-rt.dll
      C:\Documents and Settings\bernard\Application Data\Sun\Java\Deployment\cache\6.0\48\
      26760070-65075621-1.0b06a-
      26760070-65075621-1.0b06a-.idx
      C:\Documents and Settings\bernard\Application Data\Sun\Java\Deployment\cache\6.0\59\
      1ea183bb-5039e71a
      1ea183bb-5039e71a.idx
      C:\Documents and Settings\bernard\Application Data\Sun\Java\Deployment\cache\6.0\62\
      6baea4fe-552802ac
      6baea4fe-552802ac.idx
      C:\Documents and Settings\bernard\Application Data\Sun\Java\Deployment\cache\6.0\62\6baea4fe-552802ac-n\
      jogl.dll
      jogl_awt.dll
      jogl_cg.dll
      C:\Documents and Settings\bernard\Application Data\Sun\Java\jre1.6.0_15\
      lzma.dll
      C:\Documents and Settings\bernard\Application Data\TuneUp Software\TuneUp Utilities\Backups\
      00000004.rcb
      00000005.rcb
      C:\Documents and Settings\bernard\Application Data\vlc\
      CACHEDIR.TAG
      ml.xspf
      plugins-04041e.dat
      plugins-zxzx04.dat
      vlc-qt-interface.ini
      vlcrc
      C:\Documents and Settings\bernard\Application Data\Windows Desktop Search\
      WindowsDesktopShortcuts.ini
      C:\Documents and Settings\bernard\Bureau\
      6256_121436906057_550601057_2847084_1022666_n.jpg
      Kirghizie juillet 2009.kmz
      Kirghizie juillet 2009.kmz:Zone.Identifier
      s776524668_1993714_5645.jpg
      C:\Documents and Settings\bernard\Cookies\
      bernard@118218[2].txt
      bernard@247realmedia[1].txt
      bernard@3suisses[1].txt
      bernard@a01.gestionpub[2].txt
      bernard@ad.doctissimo[2].txt
      bernard@ad.zanox[1].txt
      bernard@adnext[2].txt
      bernard@adtech[1].txt
      bernard@adtech[2].txt
      bernard@advertstream[2].txt
      bernard@allocine[1].txt
      bernard@apple[2].txt
      bernard@apprentoile.u-bordeaux2[2].txt
      bernard@as.clearspring[1].txt
      bernard@at.atwola[2].txt
      bernard@atdmt[2].txt
      bernard@atdmt[3].txt
      bernard@atraxio[1].txt
      bernard@bidsystem[1].txt
      bernard@bing[2].txt
      bernard@bing[3].txt
      bernard@boards.msn[1].txt
      bernard@bordorun.skyrock[2].txt
      bernard@boursoramabanque.solution.weborama[2].txt
      bernard@boursoramabanque.solution.weborama[3].txt
      bernard@bouyguestelecom.solution.weborama[2].txt
      bernard@bs.serving-sys[2].txt
      bernard@bubblestat[2].txt
      bernard@by112w.bay112.mail.live[2].txt
      bernard@c.fr.msn[2].txt
      bernard@c.live[1].txt
      bernard@c.live[2].txt
      bernard@c.msn[1].txt
      bernard@c.msn[2].txt
      bernard@c.msn[4].txt
      bernard@c.uk.msn[1].txt
      bernard@c.uk.msn[3].txt
      bernard@CADPHIKW.txt
      bernard@CAJC54MO.txt
      bernard@CAQR339T.txt
      bernard@centerblog[2].txt
      bernard@cetelem.solution.weborama[2].txt
      bernard@chinoi.zarab.skyrock[1].txt
      bernard@city974[2].txt
      bernard@click-fr[2].txt
      bernard@criteo[1].txt
      bernard@criteo[2].txt
      bernard@cv.modele-cv-lettre[2].txt
      bernard@cybermonitor[1].txt
      bernard@dailymotion[1].txt
      bernard@deezer[2].txt
      bernard@divertissements.fr.msn[2].txt
      bernard@doctissimo[1].txt
      bernard@ebay[1].txt
      bernard@ebay[2].txt
      bernard@ebay[4].txt
      bernard@esearchvision[2].txt
      bernard@estat[1].txt
      bernard@estat[2].txt
      bernard@eveiletjeux[1].txt
      bernard@facebook[1].txt
      bernard@facebook[3].txt
      bernard@flashtalking[1].txt
      bernard@fnacmagasin.solution.weborama[2].txt
      bernard@fonciabanquepopulaire.solution.weborama[2].txt
      bernard@fr.at.atwola[1].txt
      bernard@fr.at.atwola[2].txt
      bernard@fr.ebayrtm[1].txt
      bernard@fr.msn[2].txt
      bernard@fr.msn[3].txt
      bernard@gaulinvincent.skyrock[1].txt
      bernard@gaulinvincent.skyrock[2].txt
      bernard@google[10].txt
      bernard@google[11].txt
      bernard@google[1].txt
      bernard@google[2].txt
      bernard@google[3].txt
      bernard@google[4].txt
      bernard@google[5].txt
      bernard@google[6].txt
      bernard@google[7].txt
      bernard@google[8].txt
      bernard@google[9].txt
      bernard@h.msn[2].txt
      bernard@h.msn[3].txt
      bernard@home.live[2].txt
      bernard@iapref.orange[1].txt
      bernard@jim.solution.weborama[2].txt
      bernard@kiwee[2].txt
      bernard@lareunion.urssaf[2].txt
      bernard@livefilestore[2].txt
      bernard@livefilestore[3].txt
      bernard@live[1].txt
      bernard@live[3].txt
      bernard@login.live[1].txt
      bernard@login.live[3].txt
      bernard@mail.google[1].txt
      bernard@mail.google[2].txt
      bernard@mediadico[2].txt
      bernard@meetic-partners[2].txt
      bernard@messenger.msn[1].txt
      bernard@messenger.msn[2].txt
      bernard@metaffiliation[1].txt
      bernard@metrixlablw.customers.luna[1].txt
      bernard@microsoftinternetexplorer.112.2o7[1].txt
      bernard@msnportal.112.2o7[1].txt
      bernard@msnportal.112.2o7[2].txt
      bernard@msn[1].txt
      bernard@msn[2].txt
      bernard@msn[3].txt
      bernard@msn[5].txt
      bernard@news.fr.msn[1].txt
      bernard@night974[1].txt
      bernard@notifier.avira[1].txt
      bernard@notifier.avira[2].txt
      bernard@oes.orange[1].txt
      bernard@onlinestores.metaservices.microsoft[1].txt
      bernard@opodo.122.2o7[1].txt
      bernard@opodo.122.2o7[2].txt
      bernard@opodo[1].txt
      bernard@opodo[2].txt
      bernard@orange.inq[2].txt
      bernard@orange[1].txt
      bernard@p.live[1].txt
      bernard@profile.live[2].txt
      bernard@profile.live[3].txt
      bernard@quantserve[1].txt
      bernard@rad.msn[2].txt
      bernard@rad.msn[3].txt
      bernar
      0
      1. Bonjour , oui je te comprend tout a fé sa sert a rien d'aider des gens comme sa je suis vrement désolé donc j'ai supprimer avast et la je suis passer a antivir (je suis entrain de faire une annalyse en se moment + malwarebyte)
        et au moment je te parle jarrive plus a me connecté sur son ordinateur impossible la clé wifi ne veu pas se connecté j'ai beau mettre reparer rien ne marche
        0
        1. Contributeur
          Re,

          Tu as fais ton scan MBAM hier --> mbam-log-2009-10-02 (23-56-39).txt , il avait déjà découvert ce fameux crack infecté, ce qui ne t'a pas empêché de le réinstaller...

          - Donc, permet-moi de douter, je suis d'accord pour aider les gens qui ont des problèmes avec leur machine, mais quand il s'agit de perdre du temps, ça ne me dis rien du tout...

          mais sinon y a toujours des probleme??

          --> La réponse se trouve dans ce que je t'ai dis au-dessus ( il avait déjà découvert ce fameux crack infecté, ce qui ne t'a pas empêché de le réinstaller...)

          Ouroboros, Le serpent qui se mord la queue !
          1
          1. je te comprend craker un logiciel c'pas bien du tout je vais arreter sa tout suite et changer mon antivirus mettre un gratuit comme antivir et puis voila =)

            mais sinon tu pensses que mon ordi et plus infecté??

            Bonne nuit a demain
            0
            1. ok merci je vais le supprimer et passer a antivir de tout fasson je l'aime pas avast mais sinon y a toujours des probleme??
              0
              1. Contributeur
                Cracker un antivirus, c'est de la folie :-(

                Aurais-tu l'idée d'aller confier les clefs de chez toi à un cambrioleur ? ben, c'est la même chose !

                Cracker un logiciel tel que Photoshop ou autre, c'est déjà malsain pour ta machine, mais un logiciel de sécurité, "No comment " !

                Un peu de lecture à ce sujet ne peut te faire que le plus grand bien :
                https://forum.malekal.com/viewtopic.php?t=893&start=
                0
                1. Malwarebytes' Anti-Malware 1.41
                  Version de la base de données: 2895
                  Windows 5.1.2600 Service Pack 3

                  02/10/2009 23:56:39
                  mbam-log-2009-10-02 (23-56-39).txt

                  Type de recherche: Examen complet (A:\|C:\|D:\|E:\|)
                  Eléments examinés: 149318
                  Temps écoulé: 3 hour(s), 9 minute(s), 29 second(s)

                  Processus mémoire infecté(s): 0
                  Module(s) mémoire infecté(s): 0
                  Clé(s) du Registre infectée(s): 0
                  Valeur(s) du Registre infectée(s): 0
                  Elément(s) de données du Registre infecté(s): 0
                  Dossier(s) infecté(s): 0
                  Fichier(s) infecté(s): 3

                  Processus mémoire infecté(s):
                  (Aucun élément nuisible détecté)

                  Module(s) mémoire infecté(s):
                  (Aucun élément nuisible détecté)

                  Clé(s) du Registre infectée(s):
                  (Aucun élément nuisible détecté)

                  Valeur(s) du Registre infectée(s):
                  (Aucun élément nuisible détecté)

                  Elément(s) de données du Registre infecté(s):
                  (Aucun élément nuisible détecté)

                  Dossier(s) infecté(s):
                  (Aucun élément nuisible détecté)

                  Fichier(s) infecté(s):
                  C:\Documents and Settings\yoann\Application Data\Desktopicon\eBayShortcuts.exe (Adware.ADON) -> Quarantined and deleted successfully.
                  C:\Documents and Settings\yoann\Local Settings\Temp\Rar$EX00.836\Avast!.Antivirus.Pro.V.4.8.1282.FR+Keygen\Keygen\keygen.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
                  C:\Documents and Settings\yoann\Local Settings\Temp\Rar$EX25.5729\Avast!.Antivirus.Pro.V.4.8.1282.FR+Keygen\Keygen\keygen.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
                  0
                  1. Contributeur
                    Ok,

                    Mets Malwarebytes à jour ( si tu l'as toujours sur ton pc) et exécutes un examen rapide, puis poste le rapport généré..

                    Sinon,

                    Telecharges Malwarebytes' Anti-Malware :
                    http://www.malwarebytes.org/mbam/program/mbam-setup.exe

                    - Installe le > double-clic sur Mbam-setup.exe, à la fin de l'installation, il se mettra automatiquement à jour
                    - Une fois installé, fermes toutes les applications en cours et lances Malwarebytes
                    - Exécutes un examen rapide du pc ( tu n'auras pas accés à internet pendant l'analyse)
                    - A la fin du scan clic sur " Afficher les résultats ", si Malwarebytes a trouvé des infections >> clic sur " Supprimer la sélection "
                    - Si il a besoin de redémarrer le pc pour finir la désinfection, acceptes
                    - Un rapport s'établira, postes son contenu.
                    0
                    1. le rapport

                      ############################## | UsbFix V6.037 |

                      User : yoann (Administrateurs) # YOANN-43400310E
                      Update on 27/09/2009 by Chiquitine29, C_XX & Chimay8
                      Start at: 22:25:06 | 03/10/2009
                      Website : http://pagesperso-orange.fr/NosTools/index.html

                      mobile AMD Athlon(tm) XP-M 2400+
                      Microsoft Windows XP Édition familiale (5.1.2600 32-bit) # Service Pack 3
                      Internet Explorer 8.0.6001.18702
                      Windows Firewall Status : Enabled
                      AV : avast! antivirus 4.8.1356 [VPS 091003-0] 4.8.1356 [ Enabled | Updated ]

                      A:\ -> Lecteur de disquettes 3 ½ pouces
                      C:\ -> Disque fixe local # 14,65 Go (4,72 Go free) # NTFS
                      D:\ -> Disque fixe local # 22,61 Go (21,67 Go free) [DATA] # NTFS
                      E:\ -> Disque CD-ROM

                      ############################## | Processus actifs |

                      C:\WINDOWS\System32\smss.exe
                      C:\WINDOWS\system32\csrss.exe
                      C:\WINDOWS\system32\winlogon.exe
                      C:\WINDOWS\system32\services.exe
                      C:\WINDOWS\system32\lsass.exe
                      C:\WINDOWS\system32\svchost.exe
                      C:\WINDOWS\system32\svchost.exe
                      C:\WINDOWS\System32\svchost.exe
                      C:\WINDOWS\system32\svchost.exe
                      C:\WINDOWS\system32\svchost.exe
                      C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                      C:\Program Files\Alwil Software\Avast4\ashServ.exe
                      C:\WINDOWS\system32\spoolsv.exe
                      C:\WINDOWS\Explorer.EXE
                      C:\Program Files\Java\jre6\bin\jqs.exe
                      C:\WINDOWS\system32\lxctcoms.exe
                      C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
                      C:\WINDOWS\system32\SearchIndexer.exe
                      C:\WINDOWS\system32\wuauclt.exe
                      C:\WINDOWS\system32\wbem\wmiprvse.exe
                      C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                      C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                      C:\WINDOWS\system32\wbem\wmiapsrv.exe
                      C:\WINDOWS\System32\alg.exe
                      C:\WINDOWS\system32\wbem\wmiprvse.exe

                      ################## | Fichiers # Dossiers infectieux |

                      Supprimé ! D:\desktop.ini

                      ################## | Registre # Clés Run infectieuses |

                      ################## | Registre # Mountpoints2 |

                      Supprimé ! HKCU\...\Explorer\MountPoints2\{40fd80f0-3290-11de-9417-0060b30ef470}\Shell\Auto\Command
                      Supprimé ! HKCU\...\Explorer\MountPoints2\{4e367d80-4d29-11de-9440-000c6ec96d14}\Shell\Auto\Command

                      ################## | Listing des fichiers présent |

                      [19/04/2009 16:18|--a------|1024] C:\.rnd
                      [11/04/2009 01:32|--a------|0] C:\AUTOEXEC.BAT
                      [25/09/2009 07:32|--a------|2332742] C:\AVSCAN-20090924-235254-33F5B70E.LOG
                      [11/04/2009 01:23|---hs----|216] C:\boot.ini
                      [02/03/2006 14:00|-rahs----|4952] C:\Bootfont.bin
                      [11/04/2009 01:32|--a------|0] C:\CONFIG.SYS
                      [11/04/2009 01:32|-rahs----|0] C:\IO.SYS
                      [29/05/2009 21:37|--a------|282] C:\lxctscan.log
                      [11/04/2009 01:32|-rahs----|0] C:\MSDOS.SYS
                      [02/03/2006 14:00|-rahs----|47564] C:\NTDETECT.COM
                      [11/04/2009 22:15|-rahs----|252240] C:\ntldr
                      [?|?|?] C:\pagefile.sys
                      [03/10/2009 22:31|--a------|2759] C:\UsbFix.txt
                      [21/09/2009 00:45|--a------|29331995] D:\Av.A.P.rar
                      [23/06/2009 21:56|--a------|30143928] D:\avira_antivir_personal_fr.exe
                      [16/06/2009 19:55|--a------|110717129] D:\B.O.S.S Opus 3 By MaSteR_.rar
                      [12/08/2009 08:11|--a------|6404] D:\email.jpg
                      [16/06/2009 16:28|--a------|89611748] D:\Fatal_Bazooka-Tas_Vu-byZam.rar
                      [20/09/2009 23:40|--a------|1040846] D:\koxie-vs-cartman.mp3
                      [12/04/2009 23:17|--a------|5168976] D:\MsgPlusLive-481.exe
                      [12/08/2009 08:11|--a------|1679] D:\picasaweblogo-fr.gif
                      [16/06/2009 17:13|--a------|67351396] D:\Rihanna - Good Girl Gone Bad by Nosdeuxo.rar
                      [20/09/2009 23:44|--a------|5988079] D:\telecharger-mp3-site.rar
                      [21/05/2009 19:46|--a------|17417485] D:\TuneUp.Utilities.2009.8.0.3100.31 FR By master-chief486.rar
                      [20/09/2009 23:41|--a------|3035686] D:\unlocker_singe3.rar
                      [29/08/2009 22:28|--a------|18015723] D:\vlc-1.0.1-win32.exe
                      [16/06/2009 15:13|--a------|59059016] D:\Zaho-up_by_thierry.rar
                      [06/09/2009 23:38|--a------|3246080] D:\Zorro_Chang-sa_bon_kalit_sa_baye-depi_longtime.mp3

                      ################## | Vaccination |

                      # C:\autorun.inf -> Folder created by UsbFix.
                      # D:\autorun.inf -> Folder created by UsbFix.

                      ################## | Upload |

                      Veuillez envoyer le fichier : C:\DOCUME~1\yoann\Bureau\UsbFix_Upload_Me_YOANN-43400310E.zip : https://www.androidworld.fr/
                      Merci pour votre contribution .
                      0
                      1. Contributeur
                        Avant d'attaquer l'option2, désactive le Tea-timer de Spybot, si je peux te conseiller, c'est de ne plus le réinstaller, il est gourmand et obsolète...

                        Par contre, si tu décides de le réinstaller, il faudra attendre la fin de la désinfection, mais attention à ce moment là, il te proposera des modifications du registre sous forme de pop-up, il faudra alors toutes les acceptés sans exeptions

                        Pour désactiver le tea-timer, regarde sur ce lien : http://perso.orange.fr/rginformatique/section%20virus/demo%20spybot.htm

                        Puis,

                        Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) sans les ouvrir

                        # Double clique sur le raccourci UsbFix présent sur ton bureau

                        # choisi l'option 2 ( Suppression )

                        # Ton bureau disparaitra et le pc redémarrera .

                        # Au redémarrage , UsbFix scannera ton pc , laisse travailler l'outil.

                        # Ensuite poste le rapport UsbFix.txt qui apparaitra avec le bureau .

                        # Note : Le rapport UsbFix.txt est sauvegardé a la racine du disque.( C:\UsbFix.txt )
                        0
                        1. le rapport

                          ############################## | UsbFix V6.037 |

                          User : yoann (Administrateurs) # YOANN-43400310E
                          Update on 27/09/2009 by Chiquitine29, C_XX & Chimay8
                          Start at: 22:09:05 | 03/10/2009
                          Website : http://pagesperso-orange.fr/NosTools/index.html

                          mobile AMD Athlon(tm) XP-M 2400+
                          Microsoft Windows XP Édition familiale (5.1.2600 32-bit) # Service Pack 3
                          Internet Explorer 8.0.6001.18702
                          Windows Firewall Status : Enabled
                          AV : avast! antivirus 4.8.1356 [VPS 091003-0] 4.8.1356 [ Enabled | Updated ]

                          A:\ -> Lecteur de disquettes 3 ½ pouces
                          C:\ -> Disque fixe local # 14,65 Go (4,7 Go free) # NTFS
                          D:\ -> Disque fixe local # 22,61 Go (21,67 Go free) [DATA] # NTFS
                          E:\ -> Disque CD-ROM

                          ############################## | Processus actifs |

                          C:\WINDOWS\System32\smss.exe
                          C:\WINDOWS\system32\csrss.exe
                          C:\WINDOWS\system32\winlogon.exe
                          C:\WINDOWS\system32\services.exe
                          C:\WINDOWS\system32\lsass.exe
                          C:\WINDOWS\system32\svchost.exe
                          C:\WINDOWS\system32\svchost.exe
                          C:\WINDOWS\System32\svchost.exe
                          C:\WINDOWS\system32\svchost.exe
                          C:\WINDOWS\system32\svchost.exe
                          C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                          C:\Program Files\Alwil Software\Avast4\ashServ.exe
                          C:\WINDOWS\system32\spoolsv.exe
                          C:\Program Files\Java\jre6\bin\jqs.exe
                          C:\WINDOWS\system32\lxctcoms.exe
                          C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
                          C:\WINDOWS\Explorer.EXE
                          C:\WINDOWS\system32\LVCOMSX.EXE
                          C:\Program Files\Java\jre6\bin\jusched.exe
                          C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                          C:\WINDOWS\system32\ctfmon.exe
                          C:\Program Files\SuperCopier2\SuperCopier2.exe
                          C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                          C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                          C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                          C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                          C:\Program Files\SAGEM WiFi manager\WLANUTL.exe
                          C:\WINDOWS\System32\alg.exe
                          C:\Program Files\Windows Desktop Search\WindowsSearch.exe
                          C:\WINDOWS\system32\wbem\wmiapsrv.exe
                          C:\Program Files\Windows Live\Toolbar\wltuser.exe
                          C:\WINDOWS\system32\svchost.exe
                          C:\WINDOWS\system32\SearchIndexer.exe
                          C:\Program Files\Netlog 24\Notifier\Netlog24Notifier.exe
                          C:\Program Files\Alwil Software\Avast4\ashSimpl.exe
                          C:\Program Files\Internet Explorer\iexplore.exe
                          C:\Program Files\Internet Explorer\iexplore.exe
                          C:\Program Files\Internet Explorer\iexplore.exe
                          C:\WINDOWS\system32\wbem\wmiprvse.exe

                          ################## | Fichiers # Dossiers infectieux |

                          D:\desktop.ini

                          ################## | Registre # Clés Run infectieuses |

                          [HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer] "NoResolveSearch"

                          ################## | Registre # Mountpoints2 |

                          HKCU\..\..\Explorer\MountPoints2\{40fd80f0-3290-11de-9417-0060b30ef470}
                          Shell\Auto\command =AdobeR.exe e
                          Shell\AutoRun\command =C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL

                          HKCU\..\..\Explorer\MountPoints2\{4e367d80-4d29-11de-9440-000c6ec96d14}
                          Shell\Auto\command =AdobeR.exe e
                          Shell\AutoRun\command =C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL AdobeR.exe e

                          ################## | ! Fin du rapport # UsbFix V6.037 ! |
                          0
                          1. Contributeur
                            tes disques amovibles sont infectés,

                            Telecharge et installe UsbFix de C_XX, Chiquitine29 & Chimay8

                            Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) sans les ouvrir

                            # Double clic sur le raccourci UsbFix présent sur ton bureau .

                            # Choisi l option 1 ( Recherche )

                            # Laisse travailler l outil.

                            # Ensuite post le rapport UsbFix.txt qui apparaitra.

                            # Note : Le rapport UsbFix.txt est sauvegardé a la racine du disque. ( C:\UsbFix.txt )

                            ( CTRL+A Pour tout selectionner , CTRL+C pour copier et CTRL+V pour coller )

                            # Note : "Process.exe", une composante de l'outil, est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool.
                            Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.
                            Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall...)
                            0
                            1. 2eme rapport

                              info.txt logfile of random's system information tool 1.06 2009-10-03 21:52:56

                              ======Uninstall list======

                              -->C:\PROGRA~1\Yahoo!\Common\UNYT_W~1.EXE
                              -->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
                              ABBYY FineReader 6.0 Sprint-->MsiExec.exe /X{ACF60000-22B9-4CE9-98D6-2CCF359BAC07}
                              Adobe Flash Player 10 ActiveX-->C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
                              Adobe Reader 9.1.3 - Français-->MsiExec.exe /I{AC76BA86-7AD7-1036-7B44-A91000000001}
                              Assistant de connexion Windows Live-->MsiExec.exe /I{DCE8CD14-FBF5-4464-B9A4-E18E473546C7}
                              avast! Antivirus-->C:\Program Files\Alwil Software\Avast4\aswRunDll.exe "C:\Program Files\Alwil Software\Avast4\Setup\setiface.dll",RunSetup
                              CCleaner (remove only)-->"C:\Program Files\CCleaner\uninst.exe"
                              Correctif pour Lecteur Windows Media 11 (KB939683)-->"C:\WINDOWS\$NtUninstallKB939683$\spuninst\spuninst.exe"
                              Correctif pour Windows XP (KB952287)-->"C:\WINDOWS\$NtUninstallKB952287$\spuninst\spuninst.exe"
                              Correctif pour Windows XP (KB961118)-->"C:\WINDOWS\$NtUninstallKB961118$\spuninst\spuninst.exe"
                              Correctif pour Windows XP (KB970653-v3)-->"C:\WINDOWS\$NtUninstallKB970653-v3$\spuninst\spuninst.exe"
                              FileHippo.com Update Checker-->"C:\Program Files\FileHippo.com\uninstall.exe"
                              Galerie de photos Windows Live-->MsiExec.exe /X{B131E59D-202C-43C6-84C9-68F0C37541F1}
                              Google Toolbar for Internet Explorer-->"C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarManager_E582EA556D8DE101.exe" /uninstall
                              Google Toolbar for Internet Explorer-->MsiExec.exe /I{18455581-E099-4BA8-BC6B-F34B2F06600C}
                              Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)-->C:\WINDOWS\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall /qb+ REBOOTPROMPT=""
                              Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)-->C:\WINDOWS\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {A7EEA2F2-BFCD-4A54-A575-7B81A786E658} /qb+ REBOOTPROMPT=""
                              Hotfix for Windows Media Format 11 SDK (KB929399)-->"C:\WINDOWS\$NtUninstallKB929399$\spuninst\spuninst.exe"
                              Hotfix for Windows XP (KB915800-v4)-->"C:\WINDOWS\$NtUninstallKB915800-v4$\spuninst\spuninst.exe"
                              Installation Windows Live-->C:\Program Files\Windows Live\Installer\wlarp.exe
                              Installation Windows Live-->MsiExec.exe /I{46ABBC54-1872-4AA3-95E2-F2C063A63F31}
                              Java(TM) 6 Update 16-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216016FF}
                              Junk Mail filter update-->MsiExec.exe /I{E2DFE069-083E-4631-9B6C-43C48E991DE5}
                              K-Lite Codec Pack 3.9.0 Full-->"C:\Program Files\K-Lite Codec Pack\unins000.exe"
                              Lecteur Windows Media 11-->"C:\Program Files\Windows Media Player\Setup_wm.exe" /Uninstall
                              Lexmark 5400 Series-->C:\Program Files\Lexmark 5400 Series\Install\x86\Uninst.exe
                              Lexmark Barre d'outils-->regsvr32.exe /s /u "C:\Program Files\Lexmark Toolbar\toolband.dll"
                              livebox-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{FC7DDAAE-7F2B-4270-9BFD-5A130B667E9E}\Setup.exe" -l0x40c
                              Logiciel QuickCam de Logitech-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{C43048A9-742C-4DAD-90D2-E3B53C9DB825}\setup.exe" -l0x40c
                              Ma-Config.com-->MsiExec.exe /X{FACFAAB3-1443-427D-A0B0-1B55BB4F7FB2}
                              Malwarebytes' Anti-Malware-->"C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
                              Messenger Plus! Live-->"C:\Program Files\Messenger Plus! Live\Uninstall.exe"
                              Microsoft .NET Framework 1.1 French Language Pack-->MsiExec.exe /X{9A394342-4A68-4EBA-85A6-55B559F4E700}
                              Microsoft .NET Framework 1.1 Hotfix (KB928366)-->"C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\hotfix.exe" "C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\M928366\M928366Uninstall.msp"
                              Microsoft .NET Framework 1.1-->msiexec.exe /X {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
                              Microsoft .NET Framework 1.1-->MsiExec.exe /X{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
                              Microsoft .NET Framework 2.0 Service Pack 2 Language Pack - FRA-->MsiExec.exe /I{72AD53CC-CCC0-3757-8480-9EE176866A7C}
                              Microsoft .NET Framework 2.0 Service Pack 2-->MsiExec.exe /I{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}
                              Microsoft .NET Framework 3.0 Service Pack 2 Language Pack - FRA-->MsiExec.exe /I{0BD83598-C2EF-3343-847B-7D2E84599128}
                              Microsoft .NET Framework 3.0 Service Pack 2-->MsiExec.exe /I{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}
                              Microsoft .NET Framework 3.5 Language Pack SP1 - fra-->MsiExec.exe /I{3E31821C-7917-367E-938E-E65FC413EA31}
                              Microsoft .NET Framework 3.5 SP1-->C:\WINDOWS\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setup.exe
                              Microsoft .NET Framework 3.5 SP1-->MsiExec.exe /I{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}
                              Microsoft Choice Guard-->MsiExec.exe /X{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}
                              Microsoft Compression Client Pack 1.0 for Windows XP-->"C:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe"
                              Microsoft Internationalized Domain Names Mitigation APIs-->"C:\WINDOWS\$NtServicePackUninstallIDNMitigationAPIs$\spuninst\spuninst.exe"
                              Microsoft Kernel-Mode Driver Framework Feature Pack 1.5-->"C:\WINDOWS\$NtUninstallWdf01005$\spuninst\spuninst.exe"
                              Microsoft National Language Support Downlevel APIs-->"C:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$\spuninst\spuninst.exe"
                              Microsoft Office Access MUI (French) 2007-->MsiExec.exe /X{90120000-0015-040C-0000-0000000FF1CE}
                              Microsoft Office Excel MUI (French) 2007-->MsiExec.exe /X{90120000-0016-040C-0000-0000000FF1CE}
                              Microsoft Office InfoPath MUI (French) 2007-->MsiExec.exe /X{90120000-0044-040C-0000-0000000FF1CE}
                              Microsoft Office Live Add-in 1.3-->MsiExec.exe /I{57F0ED40-8F11-41AA-B926-4A66D0D1A9CC}
                              Microsoft Office Outlook Connector-->MsiExec.exe /I{95120000-0122-040C-0000-0000000FF1CE}
                              Microsoft Office Outlook MUI (French) 2007-->MsiExec.exe /X{90120000-001A-040C-0000-0000000FF1CE}
                              Microsoft Office PowerPoint MUI (French) 2007-->MsiExec.exe /X{90120000-0018-040C-0000-0000000FF1CE}
                              Microsoft Office Professional Plus 2007-->"C:\Program Files\Fichiers communs\Microsoft Shared\OFFICE12\Office Setup Controller\setup.exe" /uninstall PROPLUS /dll OSETUP.DLL
                              Microsoft Office Professional Plus 2007-->MsiExec.exe /X{90120000-0011-0000-0000-0000000FF1CE}
                              Microsoft Office Proof (Arabic) 2007-->MsiExec.exe /X{90120000-001F-0401-0000-0000000FF1CE}
                              Microsoft Office Proof (Dutch) 2007-->MsiExec.exe /X{90120000-001F-0413-0000-0000000FF1CE}
                              Microsoft Office Proof (English) 2007-->MsiExec.exe /X{90120000-001F-0409-0000-0000000FF1CE}
                              Microsoft Office Proof (French) 2007-->MsiExec.exe /X{90120000-001F-040C-0000-0000000FF1CE}
                              Microsoft Office Proof (German) 2007-->MsiExec.exe /X{90120000-001F-0407-0000-0000000FF1CE}
                              Microsoft Office Proof (Spanish) 2007-->MsiExec.exe /X{90120000-001F-0C0A-0000-0000000FF1CE}
                              Microsoft Office Proofing (French) 2007-->MsiExec.exe /X{90120000-002C-040C-0000-0000000FF1CE}
                              Microsoft Office Publisher MUI (French) 2007-->MsiExec.exe /X{90120000-0019-040C-0000-0000000FF1CE}
                              Microsoft Office Shared MUI (French) 2007-->MsiExec.exe /X{90120000-006E-040C-0000-0000000FF1CE}
                              Microsoft Office Word MUI (French) 2007-->MsiExec.exe /X{90120000-001B-040C-0000-0000000FF1CE}
                              Microsoft Search Enhancement Pack-->MsiExec.exe /X{4CBA3D4C-8F51-4D60-B27E-F6B641C571E7}
                              Microsoft Silverlight-->MsiExec.exe /X{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
                              Microsoft SQL Server 2005 Compact Edition [ENU]-->MsiExec.exe /I{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}
                              Microsoft Sync Framework Runtime Native v1.0 (x86)-->MsiExec.exe /I{8A74E887-8F0F-4017-AF53-CBA42211AAA5}
                              Microsoft Sync Framework Services Native v1.0 (x86)-->MsiExec.exe /I{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}
                              Microsoft User-Mode Driver Framework Feature Pack 1.0-->"C:\WINDOWS\$NtUninstallWudf01000$\spuninst\spuninst.exe"
                              Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053-->MsiExec.exe /X{770657D0-A123-3C07-8E44-1C83EC895118}
                              Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
                              Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148-->MsiExec.exe /X{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}
                              Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17-->MsiExec.exe /X{9A25302D-30C0-39D9-BD6F-21E6EC160475}
                              Mise à jour critique pour Lecteur Windows Media 11 (KB959772)-->"C:\WINDOWS\$NtUninstallKB959772_WM11$\spuninst\spuninst.exe"
                              Mise à jour de sécurité pour Lecteur Windows Media (KB952069)-->"C:\WINDOWS\$NtUninstallKB952069_WM9$\spuninst\spuninst.exe"
                              Mise à jour de sécurité pour Lecteur Windows Media (KB968816)-->"C:\WINDOWS\$NtUninstallKB968816_WM9$\spuninst\spuninst.exe"
                              Mise à jour de sécurité pour Lecteur Windows Media (KB973540)-->"C:\WINDOWS\$NtUninstallKB973540_WM9$\spuninst\spuninst.exe"
                              Mise à jour de sécurité pour Lecteur Windows Media 11 (KB936782)-->"C:\WINDOWS\$NtUninstallKB936782_WMP11$\spuninst\spuninst.exe"
                              Mise à jour de sécurité pour Lecteur Windows Media 11 (KB954154)-->"C:\WINDOWS\$NtUninstallKB954154_WM11$\spuninst\spuninst.exe"
                              Mise à jour de sécurité pour Windows Internet Explorer 7 (KB938127-v2)-->"C:\WINDOWS\ie7updates\KB938127-v2-IE7\spuninst\spuninst.exe"
                              Mise à jour de sécurité pour Windows Internet Explorer 7 (KB956390)-->"C:\WINDOWS\ie7updates\KB956390-IE7\spuninst\spuninst.exe"
                              Mise à jour de sécurité pour Windows Internet Explorer 7 (KB961260)-->"C:\WINDOWS\ie7updates\KB961260-IE7\spuninst\spuninst.exe"
                              Mise à jour de sécurité pour Windows Internet Explorer 7 (KB963027)-->"C:\WINDOWS\ie7updates\KB963027-IE7\spuninst\spuninst.exe"
                              Mise à jour de sécurité pour Windows Internet Explorer 8 (KB969897)-->"C:\WINDOWS\ie8updates\KB969897-IE8\spuninst\spuninst.exe"
                              Mise à jour de sécurité pour Windows Internet Explorer 8 (KB971961)-->"C:\WINDOWS\ie8updates\KB971961-IE8\spuninst\spuninst.exe"
                              Mise à jour de sécurité pour Windows Internet Explorer 8 (KB972260)-->"C:\WINDOWS\ie8updates\KB972260-IE8\spuninst\spuninst.exe"
                              Mise à jour de sécurité pour Windows XP (KB923561)-->"C:\WINDOWS\$NtUninstallKB923561$\spuninst\spuninst.exe"
                              Mise à jour de sécurité pour Windows XP (KB938464-v2)-->"C:\WINDOWS\$NtUninstallKB938464-v2$\spuninst\spuninst.exe"
                              Mise à jour de sécurité pour Windows XP (KB941569)-->"C:\WINDOWS\$NtUninstallKB941569$\spuninst\spuninst.exe"
                              Mise à jour de sécurité pour Windows XP (KB946648)-->"C:\WINDOWS\$NtUninstallKB946648$\spuninst\spuninst.exe"
                              Mise à jour de sécurité pour Windows XP (KB950760)-->"C:\WINDOWS\$NtUninstallKB950760$\spuninst\spuninst.exe"
                              Mise à jour de sécurité pour Windows XP (KB950762)-->"C:\WINDOWS\$NtUninstallKB950762$\spuninst\spuninst.exe"
                              Mise à jour de sécurité pour Windows XP (KB950974)-->"C:\WINDOWS\$NtUninstallKB950974$\spuninst\spuninst.exe"
                              Mise à jour de sécurité pour Windows XP (KB951066)-->"C:\WINDOWS\$NtUninstallKB951066$\spuninst\spuninst.exe"
                              Mise à jour de sécurité pour Windows XP (KB951376-v2)-->"C:\WINDOWS\$NtUninstallKB951376-v2$\spuninst\spuninst.exe"
                              Mise à jour de sécurité pour Windows XP (KB951698)-->"C:\WINDOWS\$NtUninstallKB951698$\spuninst\spuninst.exe"
                              Mise à jour de sécurité pour Windows XP (KB951748)-->"C:\WINDOWS\$NtUninstallKB951748$\spuninst\spuninst.exe"
                              Mise à jour de sécurité pour Windows XP (KB952004)-->"C:\WINDOWS\$NtUninstallKB952004$\spuninst\spuninst.exe"
                              Mise à jour de sécurité pour Windows XP (KB952954)-->"C:\WINDOWS\$NtUninstallKB952954$\spuninst\spuninst.exe"
                              Mise à jour de sécurité pour Windows XP (KB954459)-->"C:\WINDOWS\$NtUninstallKB954459$\spuninst\spuninst.exe"
                              Mise à jour de sécurité pour Windows XP (KB954600)-->"C:\WINDOWS\$NtUninstallKB954600$\spuninst\spuninst.exe"
                              Mise à jour de sécurité pour Windows XP (KB955069)-->"C:\WINDOWS\$NtUninstallKB955069$\spuninst\spuninst.exe"
                              Mise à jour de sécurité pour Windows XP (KB956572)-->"C:\WINDOWS\$NtUninstallKB956572$\spuninst\spuninst.exe"
                              Mise à jour de sécurité pour Windows XP (KB956744)-->"C:\WINDOWS\$NtUninstallKB956744$\spuninst\spuninst.exe"
                              Mise à jour de sécurité pour Windows XP (KB956802)-->"C:\WINDOWS\$NtUninstallKB956802$\spuninst\spuninst.exe"
                              Mise à jour de sécurité pour Windows XP (KB956803)-->"C:\WINDOWS\$NtUninstallKB956803$\spuninst\spuninst.exe"
                              Mise à jour de sécurité pour Windows XP (KB956841)-->"C:\WINDOWS\$NtUninstallKB956841$\spuninst\spuninst.exe"
                              Mise à jour de sécurité pour Windows XP (KB956844)-->"C:\WINDOWS\$NtUninstallKB956844$\spuninst\spuninst.exe"
                              Mise à jour de sécurité pour Windows XP (KB957097)-->"C:\WINDOWS\$NtUninstallKB957097$\spuninst\spuninst.exe"
                              Mise à jour de sécurité pour Windows XP (KB958215)-->"C:\WINDOWS\$NtUninstallKB958215$\spuninst\spuninst.exe"
                              Mise à jour de sécurité pour Windows XP (KB958644)-->"C:\WINDOWS\$NtUninstallKB958644$\spuninst\spuninst.exe"
                              Mise à jour de sécurité pour Windows XP (KB958687)-->"C:\WINDOWS\$NtUninstallKB958687$\spuninst\spuninst.exe"
                              Mise à jour de sécurité pour Windows XP (KB958690)-->"C:\WINDOWS\$NtUninstallKB958690$\spuninst\spuninst.exe"
                              Mise à jour de sécurité pour Windows XP (KB959426)-->"C:\WINDOWS\$NtUninstallKB959426$\spuninst\spuninst.exe"
                              Mise à jour de sécurité pour Windows XP (KB960225)-->"C:\WINDOWS\$NtUninstallKB960225$\spuninst\spuninst.exe"
                              Mise à jour de sécurité pour Windows XP (KB960714)-->"C:\WINDOWS\$NtUninstallKB960714$\spuninst\spuninst.exe"
                              Mise à jour de sécurité pour Windows XP (KB960715)-->"C:\WINDOWS\$NtUninstallKB960715$\spuninst\spuninst.exe"
                              Mise à jour de sécurité pour Windows XP (KB960803)-->"C:\WINDOWS\$NtUninstallKB960803$\spuninst\spuninst.exe"
                              Mise à jour de sécurité pour Windows XP (KB960859)-->"C:\WINDOWS\$NtUninstallKB960859$\spuninst\spuninst.exe"
                              Mise à jour de sécurité pour Windows XP (KB961371)-->"C:\WINDOWS\$NtUninstallKB961371$\spuninst\spuninst.exe"
                              Mise à jour de sécurité pour Windows XP (KB961373)-->"C:\WINDOWS\$NtUninstallKB961373$\spuninst\spuninst.exe"
                              Mise à jour de sécurité pour Windows XP (KB961501)-->"C:\WINDOWS\$NtUninstallKB961501$\spuninst\spuninst.exe"
                              Mise à jour de sécurité pour Windows XP (KB968537)-->"C:\WINDOWS\$NtUninstallKB968537$\spuninst\spuninst.exe"
                              Mise à jour de sécurité pour Windows XP (KB969898)-->"C:\WINDOWS\$NtUninstallKB969898$\spuninst\spuninst.exe"
                              Mise à jour de sécurité pour Windows XP (KB970238)-->"C:\WINDOWS\$NtUninstallKB970238$\spuninst\spuninst.exe"
                              Mise à jour de sécurité pour Windows XP (KB971557)-->"C:\WINDOWS\$NtUninstallKB971557$\spuninst\spuninst.exe"
                              Mise à jour de sécurité pour Windows XP (KB971633)-->"C:\WINDOWS\$NtUninstallKB971633$\spuninst\spuninst.exe"
                              Mise à jour de sécurité pour Windows XP (KB971657)-->"C:\WINDOWS\$NtUninstallKB971657$\spuninst\spuninst.exe"
                              Mise à jour de sécurité pour Windows XP (KB973346)-->"C:\WINDOWS\$NtUninstallKB973346$\spuninst\spuninst.exe"
                              Mise à jour de sécurité pour Windows XP (KB973354)-->"C:\WINDOWS\$NtUninstallKB973354$\spuninst\spuninst.exe"
                              Mise à jour de sécurité pour Windows XP (KB973507)-->"C:\WINDOWS\$NtUninstallKB973507$\spuninst\spuninst.exe"
                              Mise à jour de sécurité pour Windows XP (KB973869)-->"C:\WINDOWS\$NtUninstallKB973869$\spuninst\spuninst.exe"
                              Mise à jour pour Windows Internet Explorer 8 (KB969497)-->"C:\WINDOWS\ie8updates\KB969497-IE8\spuninst\spuninst.exe"
                              Mise à jour pour Windows XP (KB951978)-->"C:\WINDOWS\$NtUninstallKB951978$\spuninst\spuninst.exe"
                              Mise à jour pour Windows XP (KB955839)-->"C:\WINDOWS\$NtUninstallKB955839$\spuninst\spuninst.exe"
                              Mise à jour pour Windows XP (KB961503)-->"C:\WINDOWS\$NtUninstallKB961503$\spuninst\spuninst.exe"
                              Mise à jour pour Windows XP (KB967715)-->"C:\WINDOWS\$NtUninstallKB967715$\spuninst\spuninst.exe"
                              Mise à jour pour Windows XP (KB968389)-->"C:\WINDOWS\$NtUninstallKB968389$\spuninst\spuninst.exe"
                              Mise à jour pour Windows XP (KB973815)-->"C:\WINDOWS\$NtUninstallKB973815$\spuninst\spuninst.exe"
                              Module linguistique Microsoft .NET Framework 3.5 SP1- fra-->C:\WINDOWS\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 Language Pack SP1 - fra\setup.exe
                              MSVCRT-->MsiExec.exe /I{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}
                              Netlog 24-->C:\WINDOWS\system32\Netlog24Uninstaller.exe
                              Outil de téléchargement Windows Live-->MsiExec.exe /I{205C6BDD-7B73-42DE-8505-9A093F35A238}
                              Package de base Microsoft de service de chiffrement pour cartes à puce-->"C:\WINDOWS\$NtUninstallbasecsp$\spuninst\spuninst.exe"
                              Programme de gestion Camera de Logitech®-->"C:\Program Files\Fichiers communs\Logitech\QCDRV\BIN\SETUP.EXE" UNINSTALL REMOVEPROMPT
                              Sagem Wi-Fi 11g USB adapter (driver)-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{2ED60C17-4568-4CD5-830A-03C4688B09A1}\setup.exe" -l0x40c
                              Sagem Wi-Fi 11g USB adapter (utility)-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{AAFD22B6-A6C7-4134-AF4E-080BCBCD3493}\setup.exe" -l0x40c
                              Security Update for CAPICOM (KB931906)-->MsiExec.exe /I{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
                              Security Update for CAPICOM (KB931906)-->MsiExec.exe /X{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
                              Security Update for Windows Search 4 - KB963093-->"C:\WINDOWS\$NtUninstallKB963093$\spuninst\spuninst.exe"
                              Segoe UI-->MsiExec.exe /I{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}
                              SiS 900 PCI Fast Ethernet Adapter Driver-->C:\WINDOWS\SiS\900\Uninst.exe
                              SiS Audio Driver-->C:\Program Files\SiS7012\Uninst\uninst2k.exe PCI\VEN_1039&DEV_7012
                              SiSAGP driver-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{DC226AC9-0314-496C-BE6A-B6A132628466}\setup.exe" -l0x40c
                              Spelling Dictionaries Support For Adobe Reader 9-->MsiExec.exe /I{AC76BA86-7AD7-5464-3428-900000000004}
                              Spybot - Search & Destroy-->"C:\Program Files\Spybot - Search & Destroy\unins000.exe"
                              SuperCopier2-->"C:\Program Files\SuperCopier2\SC2Uninst.exe"
                              Update for 2007 Microsoft Office System (KB967642)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {C444285D-5E4F-48A4-91DD-47AAAA68E92D}
                              Update for Microsoft .NET Framework 3.5 SP1 (KB963707)-->C:\WINDOWS\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {B2AE9C82-DC7B-3641-BFC8-87275C4F3607} /qb+ REBOOTPROMPT=""
                              Update for Outlook 2007 Junk Email Filter (kb973514)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {03B11C77-336F-43B4-9B43-79890BA84504}
                              VLC media player 1.0.1-->C:\Program Files\VideoLAN\VLC\uninstall.exe
                              Windows Internet Explorer 8-->"C:\WINDOWS\ie8\spuninst\spuninst.exe"
                              Windows Live Call-->MsiExec.exe /I{82C7B308-0BDD-49D8-8EA5-9CD3A3F9DF41}
                              Windows Live Communications Platform-->MsiExec.exe /I{3B4E636E-9D65-4D67-BA61-189800823F52}
                              Windows Live Contrôle parental-->MsiExec.exe /X{D5D81435-B8DE-4CAF-867F-7998F2B92CFC}
                              Windows Live FolderShare-->MsiExec.exe /X{2075CB0A-D26F-4DAA-B424-5079296B43BA}
                              Windows Live Mail-->MsiExec.exe /I{5DD76286-9BE7-4894-A990-E905E91AC818}
                              Windows Live Messenger-->MsiExec.exe /X{770F1BEC-2871-4E70-B837-FB8525FFA3B1}
                              Windows Live OneCare safety scanner-->RunDll32.exe "C:\Program Files\Windows Live Safety Center\wlscCore.dll",UninstallFunction WLSC_SCANNER_PRODUCT
                              Windows Live Toolbar-->MsiExec.exe /X{F7D27C70-90F5-49B9-B188-0A133C0CE353}
                              Windows Live Writer-->MsiExec.exe /X{4634B21A-CC07-4396-890C-2B8168661FEA}
                              Windows Media Format 11 runtime-->"C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll
                              Windows Media Format 11 runtime-->"C:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe"
                              Windows Media Player 11-->"C:\WINDOWS\$NtUninstallwmp11$\spuninst\spuninst.exe"
                              Windows Search 4.0-->"C:\WINDOWS\$NtUninstallKB940157$\spuninst\spuninst.exe"
                              Windows XP Service Pack 3-->"C:\WINDOWS\$NtServicePackUninstall$\spuninst\spuninst.exe"
                              WinRAR archiver-->C:\Program Files\WinRAR\uninstall.exe
                              XML Paper Specification Shared Components Language Pack 1.0-->"C:\WINDOWS\$NtUninstallXPSEPSCLP$\spuninst\spuninst.exe"
                              Yahoo! Toolbar-->C:\PROGRA~1\Yahoo!\Common\UNYT_W~1.EXE

                              ======Hosts File======

                              127.0.0.1
                              127.0.0.1 www.007guard.com
                              127.0.0.1 007guard.com
                              127.0.0.1 008i.com
                              127.0.0.1 www.008k.com
                              127.0.0.1 008k.com
                              127.0.0.1 www.00hq.com
                              127.0.0.1 00hq.com
                              127.0.0.1 010402.com
                              127.0.0.1 www.032439.com

                              ======Security center information======

                              AV: avast! antivirus 4.8.1356 [VPS 091002-0]

                              ======System event log======

                              Computer Name: YOANN-43400310E
                              Event Code: 18
                              Message:
                              Record Number: 7653
                              Source Name: avgntflt
                              Time Written: 20090912220345.000000+120
                              Event Type: Avertissement
                              User:

                              Computer Name: YOANN-43400310E
                              Event Code: 18
                              Message:
                              Record Number: 7652
                              Source Name: avgntflt
                              Time Written: 20090912220317.000000+120
                              Event Type: Avertissement
                              User:

                              Computer Name: YOANN-43400310E
                              Event Code: 18
                              Message:
                              Record Number: 7651
                              Source Name: avgntflt
                              Time Written: 20090912220250.000000+120
                              Event Type: Avertissement
                              User:

                              Computer Name: YOANN-43400310E
                              Event Code: 18
                              Message:
                              Record Number: 7650
                              Source Name: avgntflt
                              Time Written: 20090912220223.000000+120
                              Event Type: Avertissement
                              User:

                              Computer Name: YOANN-43400310E
                              Event Code: 18
                              Message:
                              Record Number: 7649
                              Source Name: avgntflt
                              Time Written: 20090912220156.000000+120
                              Event Type: Avertissement
                              User:

                              =====Application event log=====

                              Computer Name: YOANN-43400310E
                              Event Code: 301
                              Message: Windows (176) Windows: Le moteur de base de données commence la relecture du fichier journal C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\MSS00281.log.

                              Record Number: 1356
                              Source Name: ESENT
                              Time Written: 20090530231524.000000+120
                              Event Type: Informations
                              User:

                              Computer Name: YOANN-43400310E
                              Event Code: 301
                              Message: Windows (176) Windows: Le moteur de base de données commence la relecture du fichier journal C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\MSS00280.log.

                              Record Number: 1355
                              Source Name: ESENT
                              Time Written: 20090530231524.000000+120
                              Event Type: Informations
                              User:

                              Computer Name: YOANN-43400310E
                              Event Code: 301
                              Message: Windows (176) Windows: Le moteur de base de données commence la relecture du fichier journal C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\MSS0027F.log.

                              Record Number: 1354
                              Source Name: ESENT
                              Time Written: 20090530231524.000000+120
                              Event Type: Informations
                              User:

                              Computer Name: YOANN-43400310E
                              Event Code: 301
                              Message: Windows (176) Windows: Le moteur de base de données commence la relecture du fichier journal C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\MSS0027E.log.

                              Record Number: 1353
                              Source Name: ESENT
                              Time Written: 20090530231524.000000+120
                              Event Type: Informations
                              User:

                              Computer Name: YOANN-43400310E
                              Event Code: 301
                              Message: Windows (176) Windows: Le moteur de base de données commence la relecture du fichier journal C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\MSS0027D.log.

                              Record Number: 1352
                              Source Name: ESENT
                              Time Written: 20090530231523.000000+120
                              Event Type: Informations
                              User:

                              =====Security event log=====

                              Computer Name: YOANN-43400310E
                              Event Code: 850
                              Message: Un port générait une erreur d'exception lorsque le Pare-feu Windows a démarré.

                              Origine de la stratégie : Stratégie locale

                              Profil utilisé : Standard

                              Interface : Toutes les interfaces

                              Nom : Service de session NetBIOS

                              Numéro du port : 139

                              Protocole : TCP

                              État : Désactivé

                              Étendue : Sous-réseau local uniquement

                              Record Number: 15876
                              Source Name: Security
                              Time Written: 20090913182713.000000+120
                              Event Type: Succès de l'audit
                              User: AUTORITE NT\SYSTEM

                              Computer Name: YOANN-43400310E
                              Event Code: 850
                              Message: Un port générait une erreur d'exception lorsque le Pare-feu Windows a démarré.

                              Origine de la stratégie : Stratégie locale

                              Profil utilisé : Standard

                              Interface : Toutes les interfaces

                              Nom : Service de datagramme NetBIOS

                              Numéro du port : 138

                              Protocole : UDP

                              État : Désactivé

                              Étendue : Sous-réseau local uniquement

                              Record Number: 15875
                              Source Name: Security
                              Time Written: 20090913182713.000000+120
                              Event Type: Succès de l'audit
                              User: AUTORITE NT\SYSTEM

                              Computer Name: YOANN-43400310E
                              Event Code: 850
                              Message: Un port générait une erreur d'exception lorsque le Pare-feu Windows a démarré.

                              Origine de la stratégie : Stratégie locale

                              Profil utilisé : Standard

                              Interface : Toutes les interfaces

                              Nom : Nom du service NetBIOS

                              Numéro du port : 137

                              Protocole : UDP

                              État : Désactivé

                              Étendue : Sous-réseau local uniquement

                              Record Number: 15874
                              Source Name: Security
                              Time Written: 20090913182713.000000+120
                              Event Type: Succès de l'audit
                              User: AUTORITE NT\SYSTEM

                              Computer Name: YOANN-43400310E
                              Event Code: 849
                              Message: Une application générait une erreur d'exception lorsque le Pare-feu Windows a démarré.

                              Origine de la stratégie : Stratégie locale

                              Profil utilisé : Standard

                              Nom : Assistance à distance

                              Chemin d'accès : %windir%\system32\sessmgr.exe

                              État : Activé

                              Étendue : Tous les sous-réseaux

                              Record Number: 15873
                              Source Name: Security
                              Time Written: 20090913182713.000000+120
                              Event Type: Succès de l'audit
                              User: AUTORITE NT\SYSTEM

                              Computer Name: YOANN-43400310E
                              Event Code: 849
                              Message: Une application générait une erreur d'exception lorsque le Pare-feu Windows a démarré.

                              Origine de la stratégie : Stratégie locale

                              Profil utilisé : Standard

                              Nom : 5400 Series Server

                              Chemin d'accès : C:\WINDOWS\system32\lxctcoms.exe

                              État : Activé

                              Étendue : Tous les sous-réseaux

                              Record Number: 15872
                              Source Name: Security
                              Time Written: 20090913182713.000000+120
                              Event Type: Succès de l'audit
                              User: AUTORITE NT\SYSTEM

                              ======Environment variables======

                              "ComSpec"=%SystemRoot%\system32\cmd.exe
                              "Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem
                              "windir"=%SystemRoot%
                              "FP_NO_HOST_CHECK"=NO
                              "OS"=Windows_NT
                              "PROCESSOR_ARCHITECTURE"=x86
                              "PROCESSOR_LEVEL"=6
                              "PROCESSOR_IDENTIFIER"=x86 Family 6 Model 10 Stepping 0, AuthenticAMD
                              "PROCESSOR_REVISION"=0a00
                              "NUMBER_OF_PROCESSORS"=1
                              "PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
                              "TEMP"=%SystemRoot%\TEMP
                              "TMP"=%SystemRoot%\TEMP

                              -----------------EOF-----------------
                              0
                              1. laissez le sujet à ced c'est pour lui, il faut que surfer fasse un scan rsit pour voir ce que son pc a.
                                0
                                1. Merci de votre aide
                                  voici le rapport

                                  Logfile of random's system information tool 1.06 (written by random/random)
                                  Run by yoann at 2009-10-03 21:49:29
                                  Microsoft Windows XP Édition familiale Service Pack 3
                                  System drive C: has 5 GB (32%) free of 15 GB
                                  Total RAM: 703 MB (12% free)

                                  Logfile of Trend Micro HijackThis v2.0.2
                                  Scan saved at 21:52:17, on 03/10/2009
                                  Platform: Windows XP SP3 (WinNT 5.01.2600)
                                  MSIE: Internet Explorer v8.00 (8.00.6001.18702)
                                  Boot mode: Normal

                                  Running processes:
                                  C:\WINDOWS\System32\smss.exe
                                  C:\WINDOWS\system32\csrss.exe
                                  C:\WINDOWS\system32\winlogon.exe
                                  C:\WINDOWS\system32\services.exe
                                  C:\WINDOWS\system32\lsass.exe
                                  C:\WINDOWS\system32\svchost.exe
                                  C:\WINDOWS\system32\svchost.exe
                                  C:\WINDOWS\System32\svchost.exe
                                  C:\WINDOWS\system32\svchost.exe
                                  C:\WINDOWS\system32\svchost.exe
                                  C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                                  C:\Program Files\Alwil Software\Avast4\ashServ.exe
                                  C:\WINDOWS\system32\spoolsv.exe
                                  C:\Program Files\Java\jre6\bin\jqs.exe
                                  C:\WINDOWS\system32\lxctcoms.exe
                                  C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
                                  C:\WINDOWS\Explorer.EXE
                                  C:\WINDOWS\system32\LVCOMSX.EXE
                                  C:\Program Files\Java\jre6\bin\jusched.exe
                                  C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                                  C:\WINDOWS\system32\ctfmon.exe
                                  C:\Program Files\SuperCopier2\SuperCopier2.exe
                                  C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                                  C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                                  C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                                  C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                                  C:\Program Files\SAGEM WiFi manager\WLANUTL.exe
                                  C:\WINDOWS\System32\alg.exe
                                  C:\Program Files\Windows Desktop Search\WindowsSearch.exe
                                  C:\WINDOWS\system32\wbem\wmiapsrv.exe
                                  C:\Program Files\Windows Live\Toolbar\wltuser.exe
                                  C:\WINDOWS\system32\svchost.exe
                                  C:\WINDOWS\system32\SearchIndexer.exe
                                  C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                                  C:\Program Files\Windows Live\Contacts\wlcomm.exe
                                  C:\Program Files\Netlog 24\Notifier\Netlog24Notifier.exe
                                  C:\Program Files\Alwil Software\Avast4\ashSimpl.exe
                                  C:\Program Files\Internet Explorer\iexplore.exe
                                  C:\Program Files\Internet Explorer\iexplore.exe
                                  C:\Program Files\Internet Explorer\iexplore.exe
                                  C:\Documents and Settings\yoann\Bureau\RSIT.exe
                                  C:\WINDOWS\system32\wuauclt.exe
                                  C:\WINDOWS\system32\wbem\wmiprvse.exe
                                  C:\Program Files\trend micro\yoann.exe
                                  C:\Program Files\Alwil Software\Avast4\setup\avast.setup

                                  R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
                                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                                  R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
                                  R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
                                  R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
                                  R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                                  R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                                  O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                                  O2 - BHO: Lexmark Barre d'outils - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll
                                  O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
                                  O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                                  O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
                                  O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                                  O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
                                  O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll
                                  O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll
                                  O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
                                  O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
                                  O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
                                  O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll
                                  O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
                                  O3 - Toolbar: Lexmark Barre d'outils - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll
                                  O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
                                  O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                                  O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
                                  O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
                                  O4 - HKLM\..\Run: [LXCTCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCTtime.dll,_RunDLLEntry@16
                                  O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
                                  O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                                  O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
                                  O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
                                  O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
                                  O4 - HKCU\..\Run: [SuperCopier2.exe] C:\Program Files\SuperCopier2\SuperCopier2.exe
                                  O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                                  O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
                                  O4 - HKCU\..\Run: [FileHippo.com] "C:\Program Files\FileHippo.com\UpdateChecker.exe" /background
                                  O4 - HKCU\..\Run: [Netlog 24] "C:\Program Files\Netlog 24\Notifier\Netlog24Notifier.exe"
                                  O4 - Global Startup: Utilitaire réseau pour SAGEM Wi-Fi 11g USB adapter.lnk = ?
                                  O4 - Global Startup: Windows Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
                                  O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office12\EXCEL.EXE/3000
                                  O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
                                  O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
                                  O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\Office12\REFIEBAR.DLL
                                  O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                                  O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                                  O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                                  O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                                  O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                                  O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                                  O16 - DPF: {0D41B8C5-2599-4893-8183-00195EC8D5F9} (asusTek_sysctrl Class) - http://support.asus.com/common/asusTek_sys_ctrl.cab
                                  O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase6796.cab
                                  O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/...
                                  O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} (HardwareDetection Control) - http://www.ma-config.com/activex/MaConfig_3_5_0_0.cab
                                  O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} -
                                  O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} (Performance Viewer Activex Control) - https://secure.logmein.com/activex/RACtrl.cab
                                  O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                                  O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                                  O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                                  O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                                  O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                                  O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
                                  O23 - Service: lxct_device - - C:\WINDOWS\system32\lxctcoms.exe
                                  O23 - Service: Ma-Config Service (maconfservice) - CybelSoft - C:\Program Files\ma-config.com\maconfservice.exe
                                  0
                                  1. écoute: télécharge "ad-aware",et si tu peux, l'antivirus mcaffee(il est payant)sinon,prend la version gratuite d'avast.ensuite,installe les,lance les,fais un scann,et voie.
                                    0
                                    1. Jaimerai qu'on me dis comment verifier si il est infecté en me disant des manipulation
                                      jattend un specialiste s'il vous plait
                                      0
                                      • 1
                                      • 2