Pbl message KIS avp.exe pas application32

Bonjour,
j'ai un message indiquant que kis 2009 n'est pas une application win32 !!
j'ai essaye d'installer d'autres antivirus mais la aussi meme probleme !!
je n'arive pas à fare un scanne antivirus sur internet, ça se bloque à la mise à jour des virus !
Cela depuis que j'ai essayé d'installer un petit programme alors que kis n'etait pas en fonctionnement
Pourriez vous m'aider svp
D'avance merci

PS : la souris ne fonctionne plus, ainsi que les prises usb ne sont pas reconnues
Configuration: Windows vista Internet Explorer 8.0

34 réponses

Résumé de la discussion

Un problème sur Windows Vista est décrit: un message affirme que KIS 2009 n'est pas une application Win32 et les scans antivirus en ligne se bloquent lors de la mise à jour des virus. Des étapes de nettoyage sont proposées, notamment FindyKill et RSIT avec des rapports à partager, afin d'identifier les infections persistantes et d'éviter les conflits entre outils. Des conseils supplémentaires encouragent l'exécution en mode sans échec, la suppression de composants indésirables et l'utilisation d'un antimalware fiable comme Malwarebytes, tout en désinstallant des programmes problématiques. En dernier lieu, la discussion évoque la question de réinstaller KIS ou privilégier Microsoft Security Essentials, avec une observation finale sur la persistance des symptômes USB et de la souris après nettoyage.

Bobot (l’IA à votre service)
  1. oui j oubliai

    on va enlever boonty games aussi pas tres recommande.
    telecharge cela et fait le fonctionner en option A.colle le rapport.

    http://sd-1.archive-host.com/membres/up/16506160323759868/AD-R.exe

    Déconnectes toi et fermes toutes applications en cours !

    Relances "Ad-remover" : au menu principal choisi l'option "B" .
    ? Ensuite coche: (le numero devant et entree)

    Boonty/Boonty Games
    eorezo
    .......
    Puis "S"

    le programme va travailler ...

    Postes le rapport qui apparait à la fin + un nouvel Hijackthis pour analyse ...

    ( le rapport est sauvegardé aussi sous C:\Ad-report.log )

    /!\ Si le Bureau ne réapparait pas presse Ctrl + Alt + Suppr , Onglet "Fichier" , "Nouvelle tâche" , tapes explorer.exe et valides) /!\
    1. comment se comporte ton pc?

      refais un nouveau rsit et colle le merci.
      je pense que cela doit aller bien mieux.
      1. j'ai effectué un scan, un nettoyage, un rapport qui est ci-dessous

        mon ordi a l'air stabilisé mais il ne lance plus la barre hpadvisor (ou quelque chose du genre), mais c'est pas vital
        il y a quelque temps je pensais faire une sauvegarde de mes fichiers les transferer sur un autre ordi et réinitialiser celui ci. est ce possible maintenant pour les fichiers ? il n'y a pas de probleme d'infester l'autre appareil ? existe il un forum ou autre pour une aide pour executer ces manip sans proleme ?

        je risque beaucoup avec avast ?

        le rapport final :
        Malwarebytes' Anti-Malware 1.41
        Version de la base de données: 3106
        Windows 6.0.6000

        05/11/2009 23:19:41
        mbam-log-2009-11-05 (23-19-41).txt

        Type de recherche: Examen complet (C:\|D:\|E:\|F:\|)
        Eléments examinés: 327154
        Temps écoulé: 1 hour(s), 18 minute(s), 14 second(s)

        Processus mémoire infecté(s): 0
        Module(s) mémoire infecté(s): 0
        Clé(s) du Registre infectée(s): 31
        Valeur(s) du Registre infectée(s): 0
        Elément(s) de données du Registre infecté(s): 0
        Dossier(s) infecté(s): 0
        Fichier(s) infecté(s): 1

        Processus mémoire infecté(s):
        (Aucun élément nuisible détecté)

        Module(s) mémoire infecté(s):
        (Aucun élément nuisible détecté)

        Clé(s) du Registre infectée(s):
        HKEY_CLASSES_ROOT\smart-shopper.hbax (Adware.SmartShopper) -> Quarantined and deleted successfully.
        HKEY_CLASSES_ROOT\smart-shopper.hbax.1 (Adware.SmartShopper) -> Quarantined and deleted successfully.
        HKEY_CLASSES_ROOT\smart-shopper.hbinfoband (Adware.SmartShopper) -> Quarantined and deleted successfully.
        HKEY_CLASSES_ROOT\smart-shopper.hbinfoband.1 (Adware.SmartShopper) -> Quarantined and deleted successfully.
        HKEY_CLASSES_ROOT\smart-shopper.iebutton (Adware.SmartShopper) -> Quarantined and deleted successfully.
        HKEY_CLASSES_ROOT\smart-shopper.iebutton.1 (Adware.SmartShopper) -> Quarantined and deleted successfully.
        HKEY_CLASSES_ROOT\smart-shopper.iebuttona (Adware.SmartShopper) -> Quarantined and deleted successfully.
        HKEY_CLASSES_ROOT\smart-shopper.iebuttona.1 (Adware.SmartShopper) -> Quarantined and deleted successfully.
        HKEY_CLASSES_ROOT\smart-shopper.iebuttonb (Adware.SmartShopper) -> Quarantined and deleted successfully.
        HKEY_CLASSES_ROOT\smart-shopper.iebuttonb.1 (Adware.SmartShopper) -> Quarantined and deleted successfully.
        HKEY_CLASSES_ROOT\smart-shopper.smrt-shprctrl (Adware.SmartShopper) -> Quarantined and deleted successfully.
        HKEY_CLASSES_ROOT\smart-shopper.smrt-shprctrl.1 (Adware.SmartShopper) -> Quarantined and deleted successfully.
        HKEY_CLASSES_ROOT\Interface\{90f62ef7-58d1-4e8e-bb3e-cfb10ba9e47b} (Adware.SmartShopper) -> Quarantined and deleted successfully.
        HKEY_CLASSES_ROOT\Interface\{b2b92bc9-e149-4ee8-a93e-0b8cfb329808} (Adware.SmartShopper) -> Quarantined and deleted successfully.
        HKEY_CLASSES_ROOT\Interface\{e79b1445-dfea-4bef-a786-e0c0f33c863b} (Adware.SmartShopper) -> Quarantined and deleted successfully.
        HKEY_CLASSES_ROOT\CLSID\{4a7c84e2-e95c-43c6-8dd3-03abcd0eb60e} (Adware.SmartShopper) -> Quarantined and deleted successfully.
        HKEY_CLASSES_ROOT\CLSID\{4cf088bd-be95-40a5-be9b-677f8683edea} (Adware.SmartShopper) -> Quarantined and deleted successfully.
        HKEY_CLASSES_ROOT\CLSID\{6fac4823-815e-4361-836e-46d65ed2550b} (Adware.SmartShopper) -> Quarantined and deleted successfully.
        HKEY_CLASSES_ROOT\CLSID\{8bcb5337-ec01-4e38-840c-a964f174255b} (Adware.SmartShopper) -> Quarantined and deleted successfully.
        HKEY_CLASSES_ROOT\CLSID\{911f251e-34fd-465e-b6ce-df00ff49a6be} (Adware.SmartShopper) -> Quarantined and deleted successfully.
        HKEY_CLASSES_ROOT\CLSID\{fe4f1649-8909-49c0-87ba-24d65120db46} (Adware.SmartShopper) -> Quarantined and deleted successfully.
        HKEY_CLASSES_ROOT\Typelib\{022c671f-6cba-4a03-a8f9-3b3a361b235a} (Adware.SmartShopper) -> Quarantined and deleted successfully.
        HKEY_CLASSES_ROOT\Typelib\{305c6cb1-9d31-4489-881d-5a8e2dc3fe14} (Adware.SmartShopper) -> Quarantined and deleted successfully.
        HKEY_CLASSES_ROOT\Typelib\{8ad815fc-607b-419f-8b70-d345a507a54e} (Adware.SmartShopper) -> Quarantined and deleted successfully.
        HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\{8bcb5337-ec01-4e38-840c-a964f174255b} (Adware.SmartShopper) -> Quarantined and deleted successfully.
        HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{4a7c84e2-e95c-43c6-8dd3-03abcd0eb60e} (Adware.SmartShopper) -> Quarantined and deleted successfully.
        HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{8bcb5337-ec01-4e38-840c-a964f174255b} (Adware.SmartShopper) -> Quarantined and deleted successfully.
        HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{3cc3d8fe-f0e0-4dd1-a69a-8c56bcc7bebf} (Adware.SmartShopper) -> Quarantined and deleted successfully.
        HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{3cc3d8fe-f0e0-4dd1-a69a-8c56bcc7bec0} (Adware.SmartShopper) -> Quarantined and deleted successfully.
        HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4a7c84e2-e95c-43c6-8dd3-03abcd0eb60e} (Adware.SmartShopper) -> Quarantined and deleted successfully.
        HKEY_CURRENT_USER\SOFTWARE\fcn (Rogue.Residue) -> Quarantined and deleted successfully.

        Valeur(s) du Registre infectée(s):
        (Aucun élément nuisible détecté)

        Elément(s) de données du Registre infecté(s):
        (Aucun élément nuisible détecté)

        Dossier(s) infecté(s):
        (Aucun élément nuisible détecté)

        Fichier(s) infecté(s):
        C:\Users\ghesquiere\AppData\Local\Temp\vista\Vista.exe (Trojan.Agent) -> Quarantined and deleted successfully.
        1. cela parait donc pas mal.

          garde cet antimalware.
          passe cet antimalware, fait comme indique
          Telecharges malwaresbytes antimalwares(MBAM) : egalement tres util sur pb de pub mais pas tous malheureusement

          Malwarebytes Anti-Malware: http://www.malwarebytes.org/mbam/program/mbam-setup.exe

          Tutoriel Malwarebytes Anti-Malware: https://forum.pcastuces.com/malwarebytes_antimalwares___tutoriel-f31s3.htm
          fais comme indique,mise a jour , scan complet en mode sans echec et les rapports.
          COLLE LE RAPPORT APRES SUPPRESSION MERCI.

          garde le et lance un scan tout les mois comme indique.

          si tu as ad aware tu peux desinstalle car il ne reconnait plus grand chose.

          1. a part kaspersky que je ne sais réinstaller, donc j'ai mis avast pour ne pas rester sans rien
            avast a fait un scan et trouvé dans appdata/local/temp/bis de2e.exe un trojan win32:swizbased-gen et aussi dans fleshinstaller.ese un win32:adware-gen - j'ai demandé la mise en quarantaine
            J'ai aussi un programme qui se mettais en marche au demarrage et qui ne sais plus du genre advistor, un programme qui recherche sur internet des mises à jour commerciales ou autres de chez hp

            je crois que le reste fonctionne correctement, je n'ai pas encore tous testé !
            vous en pensez quoi ?
            Merci
            1. voir post 26 et 27 avant, puis j'ai refait option1 et à voir il n'y a plus de virus ?

              Je reessai l'installation de kespersky ?
              merci

              rapport 1

              ############################## | FindyKill V5.017 |

              # User : ghesquiere (Administrateurs) # PC-DE-GHESQUIER
              # Update on 01/11/2009 by Chiquitine29
              # Start at: 22:11:00 | 04/11/2009
              # Website : http://pagesperso-orange.fr/NosTools/index.html
              # Contact : FindyKill.Contact@gmail.com

              # Intel(R) Pentium(R) Dual CPU T2370 @ 1.73GHz
              # Microsoft® Windows Vista™ Édition Familiale Premium (6.0.6000 32-bit) #
              # Internet Explorer 8.0.6001.18828
              # Windows Firewall Status : Enabled
              # AV : Kaspersky Internet Security 8.0.0.357 [ (!) Disabled | Updated ]
              # AV : avast! antivirus 4.8.1356 [VPS 091103-1] 4.8.1356 [ Enabled | Updated ]

              # C:\ # Disque fixe local # 221,29 Go (137,55 Go free) # NTFS
              # D:\ # Disque fixe local # 11,6 Go (2,13 Go free) [PRESARIO_RP] # NTFS
              # E:\ # Disque CD-ROM

              ############################## | Processus actifs |

              C:\Windows\System32\smss.exe
              C:\Windows\system32\csrss.exe
              C:\Windows\system32\wininit.exe
              C:\Windows\system32\csrss.exe
              C:\Windows\system32\services.exe
              C:\Windows\system32\lsass.exe
              C:\Windows\system32\lsm.exe
              C:\Windows\system32\winlogon.exe
              C:\Windows\system32\svchost.exe
              C:\Windows\system32\svchost.exe
              C:\Windows\System32\svchost.exe
              C:\Windows\System32\svchost.exe
              C:\Windows\System32\svchost.exe
              C:\Windows\system32\svchost.exe
              C:\Windows\system32\svchost.exe
              C:\Windows\system32\SLsvc.exe
              C:\Windows\system32\svchost.exe
              C:\Windows\system32\svchost.exe
              C:\Windows\System32\spoolsv.exe
              C:\Windows\system32\svchost.exe
              C:\Windows\system32\Dwm.exe
              C:\Windows\Explorer.EXE
              C:\PVSW\Bin\WGE_SRV.exe
              C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
              C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
              C:\PVSW\BIN\W3dbsmgr.EXE
              C:\Windows\system32\svchost.exe
              C:\Program Files\CyberLink\Shared Files\RichVideo.exe
              C:\Windows\Installer\MSIDFCC.tmp
              C:\Windows\system32\svchost.exe
              C:\Windows\System32\svchost.exe
              C:\Windows\system32\SearchIndexer.exe
              C:\Windows\system32\DRIVERS\xaudio.exe
              C:\Program Files\Hewlett-Packard\Shared\hpqWmiEx.exe
              C:\Windows\system32\taskeng.exe
              C:\Windows\System32\alg.exe
              C:\Windows\system32\taskeng.exe
              C:\Windows\system32\conime.exe
              c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
              C:\Windows\system32\svchost.exe
              C:\Program Files\Hp\QuickPlay\QPService.exe
              C:\Windows\System32\igfxpers.exe
              C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
              C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
              C:\Program Files\Apoint2K\Apoint.exe
              C:\Windows\system32\igfxsrvc.exe
              C:\Windows\WindowsMobile\wmdSync.exe
              C:\Program Files\Java\jre6\bin\jusched.exe
              C:\Program Files\Hp\HP Software Update\hpwuSchd2.exe
              C:\Windows\System32\wpcumi.exe
              C:\Program Files\Windows Sidebar\sidebar.exe
              C:\Program Files\Registry Mechanic\RMTray.exe
              C:\Windows\ehome\ehtray.exe
              C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
              C:\Program Files\Free Download Manager\fdm.exe
              C:\Program Files\Micro Application\LauncherMA.exe
              C:\Windows\system32\wbem\wmiprvse.exe
              C:\Program Files\Internet Explorer\iexplore.exe
              C:\Windows\ehome\ehmsas.exe
              C:\Windows\system32\wuauclt.exe
              C:\Program Files\Hewlett-Packard\HP wireless Assistant\WiFiMsg.EXE
              C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe
              C:\Program Files\Internet Explorer\iexplore.exe
              C:\Program Files\Apoint2K\ApMsgFwd.exe
              C:\Program Files\Apoint2K\Apntex.exe
              C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
              C:\Program Files\uTorrent\uTorrent.exe
              C:\Program Files\Internet Explorer\iexplore.exe
              C:\Windows\System32\mobsync.exe
              C:\Program Files\Hp\HP Software Update\HPWUCli.exe
              C:\Windows\system32\Macromed\Flash\FlashUtil10b.exe
              C:\Windows\system32\wbem\wmiprvse.exe
              C:\Windows\system32\msiexec.exe

              ################## | C: |

              ################## | C:\Windows |

              ################## | C:\Windows\system32 |

              ################## | C:\Windows\system32\drivers |

              ################## | C:\Users\ghesquiere\AppData\Roaming |

              ################## | Autres detections ... |

              ################## | Temporary Internet Files |

              ################## | Registre / Clés infectieuses |

              Présent ! [HKLM\software\microsoft\security center\Svc] "AntiVirusOverride"
              Présent ! [HKLM\software\microsoft\security center\Svc] "FirewallOverride"

              ################## | Etat / Services / Informations |

              # Affichage des fichiers cachés : OK

              # Mode sans echec : OK

              # Uac : OK

              # Ndisuio -> Start = 3 ( Good = 3 | Bad = 4 )
              # EapHost -> Start = 2 ( Good = 2 | Bad = 4 )
              # Wlansvc -> Start = 2 ( Good = 2 | Bad = 4 )
              # SharedAccess -> Start = 2 ( Good = 2 | Bad = 4 )
              # windefend -> Start = 2 ( Good = 2 | Bad = 4 )
              # wuauserv -> Start = 2 ( Good = 2 | Bad = 4 )
              # wscsvc -> Start = 2 ( Good = 2 | Bad = 4 )

              ################## | Cracks / Keygens / Serials |

              ################## | ! Fin du rapport # FindyKill V5.017 ! |
              1. voici le rapport pour findykill option 2

                ############################## | FindyKill V5.017 |

                # User : ghesquiere (Administrateurs) # PC-DE-GHESQUIER
                # Update on 01/11/2009 by Chiquitine29
                # Start at: 20:39:20 | 04/11/2009
                # Website : http://pagesperso-orange.fr/NosTools/index.html
                # Contact : FindyKill.Contact@gmail.com

                # Intel(R) Pentium(R) Dual CPU T2370 @ 1.73GHz
                # Microsoft® Windows Vista™ Édition Familiale Premium (6.0.6000 32-bit) #
                # Internet Explorer 8.0.6001.18828
                # Windows Firewall Status : Enabled
                # AV : Kaspersky Internet Security 8.0.0.357 [ (!) Disabled | Updated ]
                # AV : avast! antivirus 4.8.1356 [VPS 091103-1] 4.8.1356 [ Enabled | Updated ]

                # C:\ # Disque fixe local # 221,29 Go (137,53 Go free) # NTFS
                # D:\ # Disque fixe local # 11,6 Go (2,13 Go free) [PRESARIO_RP] # NTFS
                # E:\ # Disque CD-ROM

                ############################## | Processus actifs |

                C:\Windows\System32\smss.exe
                C:\Windows\system32\csrss.exe
                C:\Windows\system32\wininit.exe
                C:\Windows\system32\csrss.exe
                C:\Windows\system32\services.exe
                C:\Windows\system32\lsass.exe
                C:\Windows\system32\lsm.exe
                C:\Windows\system32\winlogon.exe
                C:\Windows\system32\svchost.exe
                C:\Windows\system32\svchost.exe
                C:\Windows\System32\svchost.exe
                C:\Windows\System32\svchost.exe
                C:\Windows\System32\svchost.exe
                C:\Windows\system32\svchost.exe
                C:\Windows\system32\svchost.exe
                C:\Windows\system32\SLsvc.exe
                C:\Windows\system32\svchost.exe
                C:\Windows\system32\svchost.exe
                C:\Windows\System32\spoolsv.exe
                C:\Windows\system32\svchost.exe
                C:\Windows\system32\Dwm.exe
                C:\Windows\Explorer.EXE
                C:\PVSW\Bin\WGE_SRV.exe
                C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
                C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
                C:\PVSW\BIN\W3dbsmgr.EXE
                C:\Windows\system32\svchost.exe
                C:\Program Files\CyberLink\Shared Files\RichVideo.exe
                C:\Windows\Installer\MSIDFCC.tmp
                C:\Windows\system32\svchost.exe
                C:\Windows\System32\svchost.exe
                C:\Windows\system32\SearchIndexer.exe
                C:\Windows\system32\DRIVERS\xaudio.exe
                C:\Program Files\Hewlett-Packard\Shared\hpqWmiEx.exe
                C:\Windows\system32\SearchProtocolHost.exe
                C:\Windows\system32\SearchFilterHost.exe
                C:\Windows\system32\taskeng.exe
                C:\Windows\System32\alg.exe
                C:\Windows\system32\taskeng.exe
                C:\Windows\system32\runonce.exe
                C:\Windows\system32\conime.exe
                C:\Windows\system32\PresentationSettings.exe
                C:\Windows\system32\wbem\wmiprvse.exe

                ################## | C: |

                ################## | C:\Windows |

                Supprimé ! C:\Windows\Prefetch\WINUPGRO.EXE-CCC1740C.pf

                ################## | C:\Windows\system32 |

                ################## | C:\Windows\system32\drivers |

                ################## | C:\Users\ghesquiere\AppData\Roaming |

                ################## | Autres suppressions ... |

                ################## | Temporary Internet Files |

                ################## | Registre / Clés infectieuses |

                ################## | Etat / Services / Informations |

                # Mode sans echec : OK

                # Affichage des fichiers cachés : OK

                # Uac : OK

                # Ndisuio -> Start = 3 ( Good = 3 | Bad = 4 )
                # EapHost -> Start = 2 ( Good = 2 | Bad = 4 )
                # Wlansvc -> Start = 2 ( Good = 2 | Bad = 4 )
                # SharedAccess -> Start = 2 ( Good = 2 | Bad = 4 )
                # windefend -> Start = 2 ( Good = 2 | Bad = 4 )
                # wuauserv -> Start = 2 ( Good = 2 | Bad = 4 )
                # wscsvc -> Start = 2 ( Good = 2 | Bad = 4 )

                ################## | PEH ... |

                Corrompu : C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe
                [Offset = 000000FC - Valeur = 0x0001]

                ################## | Cracks / Keygens / Serials |

                ################## | ! Fin du rapport # FindyKill V5.017 ! |

                Pourriez vous me dire ce que je fais à présent ?
                et pour kaspersky ?
                un grand merci
                1. bonsoir
                  J'ai envoyé le fichier !!
                  J'ai supprimé tous les programmes à crack
                  j'ai supprimé kaspersky
                  j'ai fais le prog findykill option 1

                  Le rapport :

                  ############################## | FindyKill V5.017 |

                  # User : ghesquiere (Administrateurs) # PC-DE-GHESQUIER
                  # Update on 01/11/2009 by Chiquitine29
                  # Start at: 18:53:29 | 04/11/2009
                  # Website : http://pagesperso-orange.fr/NosTools/index.html
                  # Contact : FindyKill.Contact@gmail.com

                  # Intel(R) Pentium(R) Dual CPU T2370 @ 1.73GHz
                  # Microsoft® Windows Vista™ Édition Familiale Premium (6.0.6000 32-bit) #
                  # Internet Explorer 8.0.6001.18828
                  # Windows Firewall Status : Enabled
                  # AV : Kaspersky Internet Security 8.0.0.357 [ (!) Disabled | Updated ]
                  # AV : avast! antivirus 4.8.1356 [VPS 091103-1] 4.8.1356 [ Enabled | Updated ]

                  # C:\ # Disque fixe local # 221,29 Go (137,66 Go free) # NTFS
                  # D:\ # Disque fixe local # 11,6 Go (2,13 Go free) [PRESARIO_RP] # NTFS
                  # E:\ # Disque CD-ROM

                  ############################## | Processus actifs |

                  C:\Windows\System32\smss.exe
                  C:\Windows\system32\csrss.exe
                  C:\Windows\system32\wininit.exe
                  C:\Windows\system32\csrss.exe
                  C:\Windows\system32\services.exe
                  C:\Windows\system32\lsass.exe
                  C:\Windows\system32\lsm.exe
                  C:\Windows\system32\winlogon.exe
                  C:\Windows\system32\svchost.exe
                  C:\Windows\system32\svchost.exe
                  C:\Windows\System32\svchost.exe
                  C:\Windows\System32\svchost.exe
                  C:\Windows\System32\svchost.exe
                  C:\Windows\system32\svchost.exe
                  C:\Windows\system32\svchost.exe
                  C:\Windows\system32\SLsvc.exe
                  C:\Windows\system32\svchost.exe
                  C:\Windows\system32\svchost.exe
                  C:\Windows\System32\spoolsv.exe
                  C:\Windows\system32\svchost.exe
                  C:\Windows\system32\Dwm.exe
                  C:\Windows\Explorer.EXE
                  C:\Program Files\Hp\QuickPlay\QPService.exe
                  C:\Windows\System32\igfxpers.exe
                  C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
                  C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
                  C:\Program Files\Apoint2K\Apoint.exe
                  C:\Windows\WindowsMobile\wmdSync.exe
                  C:\Program Files\Java\jre6\bin\jusched.exe
                  C:\Program Files\Hp\HP Software Update\hpwuSchd2.exe
                  C:\Windows\System32\wpcumi.exe
                  C:\Program Files\Windows Sidebar\sidebar.exe
                  C:\Program Files\Registry Mechanic\RMTray.exe
                  C:\Windows\ehome\ehtray.exe
                  C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
                  C:\Program Files\Free Download Manager\fdm.exe
                  C:\Program Files\Micro Application\LauncherMA.exe
                  C:\Windows\system32\igfxsrvc.exe
                  C:\Windows\ehome\ehmsas.exe
                  C:\PVSW\Bin\WGE_SRV.exe
                  C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
                  C:\PVSW\BIN\W3dbsmgr.EXE
                  C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
                  C:\Windows\system32\svchost.exe
                  C:\Program Files\CyberLink\Shared Files\RichVideo.exe
                  C:\Windows\Installer\MSIDFCC.tmp
                  C:\Windows\system32\svchost.exe
                  C:\Windows\System32\svchost.exe
                  C:\Windows\system32\SearchIndexer.exe
                  C:\Windows\system32\DRIVERS\xaudio.exe
                  C:\Program Files\Hewlett-Packard\Shared\hpqWmiEx.exe
                  C:\Windows\system32\taskeng.exe
                  C:\Windows\system32\msiexec.exe
                  C:\Windows\system32\wbem\wmiprvse.exe
                  C:\Windows\system32\svchost.exe
                  C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
                  C:\Windows\System32\alg.exe
                  C:\Program Files\Hewlett-Packard\HP wireless Assistant\WiFiMsg.EXE
                  C:\Windows\system32\MsiExec.exe
                  C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
                  C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe
                  C:\Program Files\Apoint2K\ApMsgFwd.exe
                  C:\Program Files\Apoint2K\Apntex.exe
                  C:\Windows\system32\conime.exe
                  C:\Users\GHESQU~1\AppData\Local\Temp\{e9513610-f218-4dda-b954-2c7e6ba7cabb}\IDriver.NonElevated.exe
                  C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
                  c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
                  C:\Windows\system32\SearchProtocolHost.exe
                  C:\Windows\system32\SearchFilterHost.exe
                  C:\Windows\system32\wbem\wmiprvse.exe

                  ################## | C: |

                  ################## | C:\Windows |

                  ################## | C:\Windows\system32 |

                  ################## | C:\Windows\system32\drivers |

                  ################## | C:\Users\ghesquiere\AppData\Roaming |

                  ################## | Autres detections ... |

                  ################## | Temporary Internet Files |

                  ################## | Registre / Clés infectieuses |

                  Présent ! [HKLM\software\microsoft\security center\Svc] "AntiVirusOverride"
                  Présent ! [HKLM\software\microsoft\security center\Svc] "FirewallOverride"

                  ################## | Etat / Services / Informations |

                  # Affichage des fichiers cachés : OK

                  # Mode sans echec : OK

                  # Uac : OK

                  # Ndisuio -> Start = 3 ( Good = 3 | Bad = 4 )
                  # EapHost -> Start = 2 ( Good = 2 | Bad = 4 )
                  # Wlansvc -> Start = 2 ( Good = 2 | Bad = 4 )
                  # SharedAccess -> Start = 2 ( Good = 2 | Bad = 4 )
                  # windefend -> Start = 2 ( Good = 2 | Bad = 4 )
                  # wuauserv -> Start = 2 ( Good = 2 | Bad = 4 )
                  # wscsvc -> Start = 2 ( Good = 2 | Bad = 4 )

                  ################## | Cracks / Keygens / Serials |

                  ################## | ! Fin du rapport # FindyKill V5.017 ! |

                  Merci de votre aide
                  je fais une option 2 de findykill !!
                  1. envoie le fichier demande par usb fix , c est pour celui qui met a jour findykill suivant les nouvelles versions de l infection.

                    siwindows te dit que kaspersky n est pas une application win 32 valide c est que tu as toujours bagle.
                    desinstalle tout les programmes ou tu avais un crack , desinstalle kaspersky.

                    repasse findykill en option 1.
                    1. ma souris c'est remise en fonction
                      ma clé usb est accessible

                      le programme usbfix demande l'envoi d'un fichier , ok ?
                      le programme kaspersky ne fonctionne tjs pas

                      le rapport 2 :

                      ############################## | UsbFix V6.047 |

                      User : ghesquiere (Administrateurs) # PC-DE-GHESQUIER
                      Update on 02/11/2009 by Chiquitine29, C_XX & Chimay8
                      Start at: 20:17:38 | 03/11/2009
                      Website : http://pagesperso-orange.fr/NosTools/index.html
                      Contact : FindyKill.Contact@gmail.com

                      Intel(R) Pentium(R) Dual CPU T2370 @ 1.73GHz
                      Microsoft® Windows Vista™ Édition Familiale Premium (6.0.6000 32-bit) #
                      Internet Explorer 8.0.6001.18828
                      Windows Firewall Status : Disabled
                      AV : Kaspersky Internet Security 8.0.0.357 [ (!) Disabled | Updated ]

                      C:\ -> Disque fixe local # 221,29 Go (130,24 Go free) # NTFS
                      D:\ -> Disque fixe local # 11,6 Go (2,13 Go free) [PRESARIO_RP] # NTFS
                      E:\ -> Disque CD-ROM # 201,21 Mo (0 Mo free) [KasperskyIS2009] # CDFS
                      J:\ -> Disque amovible # 1,92 Go (1,9 Go free) [GWEN CLE] # FAT

                      ############################## | Processus actifs |

                      C:\Windows\System32\smss.exe
                      C:\Windows\system32\csrss.exe
                      C:\Windows\system32\wininit.exe
                      C:\Windows\system32\csrss.exe
                      C:\Windows\system32\services.exe
                      C:\Windows\system32\lsass.exe
                      C:\Windows\system32\lsm.exe
                      C:\Windows\system32\winlogon.exe
                      C:\Windows\system32\svchost.exe
                      C:\Windows\system32\svchost.exe
                      C:\Windows\System32\svchost.exe
                      C:\Windows\System32\svchost.exe
                      C:\Windows\System32\svchost.exe
                      C:\Windows\system32\svchost.exe
                      C:\Windows\system32\svchost.exe
                      C:\Windows\system32\SLsvc.exe
                      C:\Windows\system32\svchost.exe
                      C:\Windows\system32\svchost.exe
                      C:\Windows\System32\spoolsv.exe
                      C:\Windows\system32\svchost.exe
                      C:\Windows\system32\Dwm.exe
                      C:\Windows\Explorer.EXE
                      C:\PVSW\Bin\WGE_SRV.exe
                      C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
                      C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
                      C:\PVSW\BIN\W3dbsmgr.EXE
                      C:\Windows\system32\svchost.exe
                      C:\Program Files\CyberLink\Shared Files\RichVideo.exe
                      C:\Windows\Installer\MSIDFCC.tmp
                      C:\Windows\system32\svchost.exe
                      C:\Windows\System32\svchost.exe
                      C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
                      C:\Windows\system32\SearchIndexer.exe
                      C:\Windows\system32\DRIVERS\xaudio.exe
                      C:\Program Files\Hewlett-Packard\Shared\hpqWmiEx.exe
                      C:\Windows\system32\WUDFHost.exe
                      C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
                      C:\Windows\system32\taskeng.exe
                      C:\Windows\System32\alg.exe
                      C:\Windows\system32\wbem\wmiprvse.exe
                      C:\Windows\system32\runonce.exe
                      C:\Windows\system32\taskeng.exe
                      C:\Windows\system32\conime.exe
                      C:\Windows\system32\PresentationSettings.exe

                      ################## | Fichiers # Dossiers infectieux |

                      Non supprimé ! E:\autorun.inf

                      ################## | Registre # Clés Run infectieuses |

                      ################## | Registre # Mountpoints2 |

                      Supprimé ! HKCU\...\Explorer\MountPoints2\I\Shell\AutoRun\Command
                      Supprimé ! HKCU\...\Explorer\MountPoints2\J\Shell\AutoRun\Command
                      Supprimé ! HKCU\...\Explorer\MountPoints2\{55588069-5424-11dd-bebb-806e6f6e6963}\Shell\AutoRun\Command
                      Supprimé ! HKCU\...\Explorer\MountPoints2\{749690e5-09f3-11de-9473-001eec30ce9e}\Shell\AutoRun\Command
                      Supprimé ! HKCU\...\Explorer\MountPoints2\{b935229e-5db5-11dd-ab76-001eec30ce9e}\Shell\AutoRun\Command

                      ################## | Listing des fichiers présent |

                      [03/07/2009 10:07|--a------|19079] C:\1082877284[1].jpg
                      [17/07/2009 14:57|--a------|140882] C:\1_9_25_fond-usa-las_vegas-180[1].jpg
                      [08/07/2009 12:01|--a------|195368] C:\6036[1].png
                      [21/11/2007 07:34|--a------|74] C:\autoexec.bat
                      [02/11/2006 10:53|-rahs----|438840] C:\bootmgr
                      [18/09/2006 22:43|--a------|10] C:\config.sys
                      [23/10/2009 17:43|--a------|1273] C:\DCB_INS.LOG
                      [07/11/2007 07:00|--a------|17734] C:\eula.1028.txt
                      [07/11/2007 07:00|--a------|17734] C:\eula.1031.txt
                      [07/11/2007 07:00|--a------|10134] C:\eula.1033.txt
                      [07/11/2007 07:00|--a------|17734] C:\eula.1036.txt
                      [07/11/2007 07:00|--a------|17734] C:\eula.1040.txt
                      [07/11/2007 07:00|--a------|118] C:\eula.1041.txt
                      [07/11/2007 07:00|--a------|17734] C:\eula.1042.txt
                      [07/11/2007 07:00|--a------|17734] C:\eula.2052.txt
                      [07/11/2007 07:00|--a------|17734] C:\eula.3082.txt
                      [03/11/2009 00:19|--a------|4484] C:\FindyKill.txt
                      [07/11/2007 07:00|--a------|1110] C:\globdata.ini
                      [18/08/2008 08:24|-rahs----|171136] C:\grldr
                      [?|?|?] C:\hiberfil.sys
                      [07/11/2007 07:03|--a------|562688] C:\install.exe
                      [07/11/2007 07:00|--a------|843] C:\install.ini
                      [07/11/2007 07:03|--a------|76304] C:\install.res.1028.dll
                      [07/11/2007 07:03|--a------|96272] C:\install.res.1031.dll
                      [07/11/2007 07:03|--a------|91152] C:\install.res.1033.dll
                      [07/11/2007 07:03|--a------|97296] C:\install.res.1036.dll
                      [07/11/2007 07:03|--a------|95248] C:\install.res.1040.dll
                      [07/11/2007 07:03|--a------|81424] C:\install.res.1041.dll
                      [07/11/2007 07:03|--a------|79888] C:\install.res.1042.dll
                      [07/11/2007 07:03|--a------|75792] C:\install.res.2052.dll
                      [07/11/2007 07:03|--a------|96272] C:\install.res.3082.dll
                      [11/10/2008 22:09|-rahs----|0] C:\IO.SYS
                      [21/11/2007 07:11|--ah-----|360] C:\IPH.PH
                      [11/10/2008 22:09|-rahs----|0] C:\MSDOS.SYS
                      [?|?|?] C:\pagefile.sys
                      [03/05/2009 17:36|--a------|594] C:\updatedatfix.log
                      [03/11/2009 20:19|--a------|5148] C:\UsbFix.txt
                      [07/11/2007 07:00|--a------|5686] C:\vcredist.bmp
                      [07/11/2007 07:09|--a------|1442522] C:\VC_RED.cab
                      [07/11/2007 07:12|--a------|232960] C:\VC_RED.MSI
                      [09/07/2009 15:51|--a------|270038] C:\xvi08lwr[1].gif
                      [11/09/2005 16:18|---hs----|340] D:\AUTOMODE
                      [17/07/2008 19:16|---hs----|13] D:\BLOCK.RIN
                      [04/10/2006 00:02|---hs----|438328] D:\bootmgr
                      [06/09/2008 12:19|---hs----|891] D:\Desktop.ini
                      [10/09/2002 17:14|---hs----|8134] D:\Folder.htt
                      [18/08/2008 08:24|-rahs----|171136] D:\grldr
                      [17/07/2008 19:51|--ahs----|828] D:\MASTER.LOG
                      [29/01/2007 18:59|---hs----|109342] D:\protect.chinese hong kong
                      [29/01/2007 18:59|---hs----|109360] D:\protect.chinese simplified
                      [29/01/2007 18:59|---hs----|109342] D:\protect.chinese traditional
                      [14/02/2007 19:30|---hs----|111653] D:\protect.czech
                      [29/01/2007 18:55|---hs----|109124] D:\protect.danish
                      [29/01/2007 18:57|---hs----|109049] D:\protect.dutch
                      [29/01/2007 18:55|---hs----|109092] D:\protect.ed
                      [29/01/2007 18:55|---hs----|109092] D:\protect.english
                      [29/01/2007 18:56|---hs----|109092] D:\protect.finnish
                      [29/01/2007 18:56|---hs----|109060] D:\protect.french
                      [29/01/2007 18:55|---hs----|109094] D:\protect.german
                      [14/02/2007 19:38|---hs----|112541] D:\protect.greek
                      [14/02/2007 19:40|---hs----|112375] D:\protect.hebrew
                      [28/08/2007 15:57|---hs----|111475] D:\protect.hungarian
                      [29/01/2007 18:56|---hs----|108979] D:\protect.italian
                      [29/01/2007 18:57|---hs----|109795] D:\protect.japanese
                      [29/01/2007 18:57|---hs----|109487] D:\protect.korean
                      [14/02/2007 19:44|---hs----|111402] D:\protect.norwegian
                      [14/02/2007 19:45|---hs----|111585] D:\protect.polish
                      [14/02/2007 19:46|---hs----|111448] D:\protect.portuguese
                      [14/02/2007 19:46|---hs----|111697] D:\protect.portuguese brazilian
                      [29/01/2007 18:58|---hs----|163804] D:\protect.russian
                      [29/01/2007 18:55|---hs----|109016] D:\protect.spanish
                      [14/02/2007 19:48|---hs----|111445] D:\protect.swedish
                      [14/02/2007 19:49|---hs----|111598] D:\protect.turkish
                      [14/05/2008 06:58|---hs----|0] D:\USER
                      [22/12/2006 12:21|-r-------|38] E:\autorun.inf
                      [04/05/2008 09:30|-r-------|34443264] E:\kis.fr.msi
                      [09/04/2001 11:10|-r-------|7398] E:\kl.ico
                      [05/05/2008 09:18|-r-------|59166] E:\release_notes_kis8.0_fr.htm
                      [04/05/2008 09:31|-r-------|75088] E:\setup.exe
                      [15/05/2008 14:40|-r-------|300] E:\setup.reg
                      [01/10/2009 13:02|--a------|38912] J:\cv.doc
                      [01/10/2009 09:51|--a------|408064] J:\381px-Montgolfi%C3%A8re[1].jpg.doc

                      ################## | Vaccination |

                      # C:\autorun.inf -> Dossier créé par UsbFix.
                      # D:\autorun.inf -> Dossier créé par UsbFix.
                      # J:\autorun.inf -> Dossier créé par UsbFix.

                      ################## | Suspect | https://www.virustotal.com/gui/ |

                      ################## | Cracks / Keygens / Serials |

                      "J:\xooloo\patch\crack.exe"
                      28/09/2009 07:00 |Size 144384 |Crc32 3f591fad |Md5 873e0e88a209fa0dcca5ade7167c76b3

                      "J:\parental filtrer\keygen\keygen.exe"
                      28/09/2009 07:00 |Size 180224 |Crc32 fd0f2ddb |Md5 b9d3d760a6bc64a7f844cd97db6ac0cc
                      1. bonsoir
                        J'ai réinstallé kaspersky et tjs le même message, pas application win32, impossible de le lancer

                        j'ai remis ma clé usb et ma souris dans les prises usb, aucune réaction, la souris fonctionne pas, clé non reconnu
                        j'ai fais le test avec usbfix option1, il y a pas eu de redemarage

                        le rapport :

                        ############################## | UsbFix V6.047 |

                        User : ghesquiere (Administrateurs) # PC-DE-GHESQUIER
                        Update on 02/11/2009 by Chiquitine29, C_XX & Chimay8
                        Start at: 20:01:57 | 03/11/2009
                        Website : http://pagesperso-orange.fr/NosTools/index.html
                        Contact : FindyKill.Contact@gmail.com

                        Intel(R) Pentium(R) Dual CPU T2370 @ 1.73GHz
                        Microsoft® Windows Vista™ Édition Familiale Premium (6.0.6000 32-bit) #
                        Internet Explorer 8.0.6001.18828
                        Windows Firewall Status : Disabled
                        AV : Kaspersky Internet Security 8.0.0.357 [ (!) Disabled | Updated ]

                        C:\ -> Disque fixe local # 221,29 Go (130,45 Go free) # NTFS
                        D:\ -> Disque fixe local # 11,6 Go (2,13 Go free) [PRESARIO_RP] # NTFS
                        E:\ -> Disque CD-ROM # 201,21 Mo (0 Mo free) [KasperskyIS2009] # CDFS

                        ############################## | Processus actifs |

                        C:\Windows\System32\smss.exe
                        C:\Windows\system32\csrss.exe
                        C:\Windows\system32\wininit.exe
                        C:\Windows\system32\csrss.exe
                        C:\Windows\system32\winlogon.exe
                        C:\Windows\system32\services.exe
                        C:\Windows\system32\lsass.exe
                        C:\Windows\system32\lsm.exe
                        C:\Windows\system32\svchost.exe
                        C:\Windows\system32\svchost.exe
                        C:\Windows\System32\svchost.exe
                        C:\Windows\System32\svchost.exe
                        C:\Windows\System32\svchost.exe
                        C:\Windows\system32\svchost.exe
                        C:\Windows\system32\svchost.exe
                        C:\Windows\system32\SLsvc.exe
                        C:\Windows\system32\svchost.exe
                        C:\Windows\system32\svchost.exe
                        C:\Windows\System32\spoolsv.exe
                        C:\Windows\system32\svchost.exe
                        C:\Windows\system32\Dwm.exe
                        C:\Windows\Explorer.EXE
                        C:\Program Files\Hp\QuickPlay\QPService.exe
                        C:\Windows\System32\igfxpers.exe
                        C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
                        C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
                        C:\Program Files\Apoint2K\Apoint.exe
                        C:\Windows\WindowsMobile\wmdSync.exe
                        C:\Program Files\Java\jre6\bin\jusched.exe
                        C:\Program Files\Hp\HP Software Update\hpwuSchd2.exe
                        C:\Windows\System32\wpcumi.exe
                        C:\Program Files\Windows Sidebar\sidebar.exe
                        C:\Program Files\Registry Mechanic\RMTray.exe
                        C:\Windows\ehome\ehtray.exe
                        C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
                        C:\Program Files\Free Download Manager\fdm.exe
                        C:\Program Files\Micro Application\LauncherMA.exe
                        C:\Windows\system32\igfxsrvc.exe
                        C:\Windows\ehome\ehmsas.exe
                        C:\PVSW\Bin\WGE_SRV.exe
                        C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
                        C:\PVSW\BIN\W3dbsmgr.EXE
                        C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
                        C:\Windows\system32\svchost.exe
                        C:\Program Files\CyberLink\Shared Files\RichVideo.exe
                        C:\Windows\Installer\MSIDFCC.tmp
                        C:\Windows\system32\svchost.exe
                        C:\Windows\System32\svchost.exe
                        C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
                        C:\Windows\system32\SearchIndexer.exe
                        C:\Windows\system32\DRIVERS\xaudio.exe
                        C:\Program Files\Hewlett-Packard\Shared\hpqWmiEx.exe
                        C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
                        C:\Windows\system32\taskeng.exe
                        C:\Windows\system32\wbem\wmiprvse.exe
                        C:\Windows\system32\svchost.exe
                        C:\Program Files\Hewlett-Packard\HP wireless Assistant\WiFiMsg.EXE
                        C:\Windows\System32\alg.exe
                        C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
                        C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe
                        C:\Program Files\Apoint2K\ApMsgFwd.exe
                        C:\Program Files\Apoint2K\Apntex.exe
                        C:\Windows\system32\conime.exe
                        c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
                        C:\Program Files\Internet Explorer\iexplore.exe
                        C:\Program Files\Internet Explorer\iexplore.exe
                        C:\Windows\system32\wuauclt.exe
                        C:\Windows\servicing\TrustedInstaller.exe
                        C:\Windows\system32\wbem\wmiprvse.exe

                        ################## | Fichiers # Dossiers infectieux |

                        E:\autorun.inf

                        ################## | Registre # Clés Run infectieuses |

                        ################## | Registre # Mountpoints2 |

                        HKCU\..\..\Explorer\MountPoints2\I
                        shell\AutoRun\command =I:\LaunchU3.exe -a

                        HKCU\..\..\Explorer\MountPoints2\J
                        shell\AutoRun\command =J:\LaunchU3.exe

                        HKCU\..\..\Explorer\MountPoints2\{55588069-5424-11dd-bebb-806e6f6e6963}
                        shell\AutoRun\command =E:\setup.exe

                        HKCU\..\..\Explorer\MountPoints2\{749690e5-09f3-11de-9473-001eec30ce9e}
                        shell\AutoRun\command =I:\LaunchU3.exe -a

                        HKCU\..\..\Explorer\MountPoints2\{b935229e-5db5-11dd-ab76-001eec30ce9e}
                        shell\AutoRun\command =G:\LaunchU3.exe

                        ################## | Suspect | https://www.virustotal.com/gui/ |

                        ################## | Cracks / Keygens / Serials |

                        ################## | ! Fin du rapport # UsbFix V6.047 ! |
                        1. 1)reinstalle kaspersky .

                          les cracks sont toujours present source de reinfection surtout si les programmes redemarrent automatiquement.

                          2)--> Télécharge UsbFix (de Chiquitine29) sur ton Bureau.
                          http://pagesperso-orange.fr/NosTools/usbfix.html

                          --> Branche tes sources de données externes à ton PC (clé USB, disque dur externe, carte SD, etc...) sans les ouvrir.

                          --> Clique droit sur le raccourci UsbFix situé sur ton Bureau et choisis Exécuter en tant qu'administrateur.

                          --> Choisis l'option 1 (recherche).

                          --> Le PC va redémarrer.

                          --> Après redémarrage, poste le rapport UsbFix.txt

                          Note : le rapport UsbFix.txt est sauvegardé à la racine du disque.

                          (Si le Bureau ne réapparaît pas, presse Ctrl+Alt+Suppr, Onglet "Fichier", "Nouvelle tâche", tape explorer.exe et valide)

                          refais pareil mais en option 2 apres colle le rapport que tu obtiens.
                          1. j'ai oublié :
                            les prises usb ne fonctionnent tjs pas

                            Merci de votre aide
                            1. 1_ j'ai refait findykill option 2, le rapport est ci dessous

                              2_ j'ai supprimé les cracks

                              3_ j'ai desinstallé tous les antivirus sur ordi, j'attends votre feu vert pour reinstaller

                              le rapport :

                              ############################## | FindyKill V5.017 |

                              # User : ghesquiere (Administrateurs) # PC-DE-GHESQUIER
                              # Update on 01/11/2009 by Chiquitine29
                              # Start at: 23:51:02 | 02/11/2009
                              # Website : http://pagesperso-orange.fr/NosTools/index.html
                              # Contact : FindyKill.Contact@gmail.com

                              # Intel(R) Pentium(R) Dual CPU T2370 @ 1.73GHz
                              # Microsoft® Windows Vista™ Édition Familiale Premium (6.0.6000 32-bit) #
                              # Internet Explorer 8.0.6001.18828
                              # Windows Firewall Status : Enabled
                              # AV : Kaspersky Internet Security 8.0.0.357 [ (!) Disabled | Updated ]
                              # AV : Microsoft Security Essentials 2.0.6212.0 [ Enabled | Updated ]

                              # C:\ # Disque fixe local # 221,29 Go (132,5 Go free) # NTFS
                              # D:\ # Disque fixe local # 11,6 Go (2,13 Go free) [PRESARIO_RP] # NTFS
                              # E:\ # Disque CD-ROM

                              ############################## | Processus actifs |

                              C:\Windows\System32\smss.exe
                              C:\Windows\system32\csrss.exe
                              C:\Windows\system32\wininit.exe
                              C:\Windows\system32\csrss.exe
                              C:\Windows\system32\services.exe
                              C:\Windows\system32\lsass.exe
                              C:\Windows\system32\lsm.exe
                              C:\Windows\system32\winlogon.exe
                              C:\Windows\system32\svchost.exe
                              C:\Windows\system32\svchost.exe
                              c:\Program Files\Microsoft Security Essentials\MsMpEng.exe
                              C:\Windows\System32\svchost.exe
                              C:\Windows\System32\svchost.exe
                              C:\Windows\system32\svchost.exe
                              C:\Windows\system32\svchost.exe
                              C:\Windows\system32\SLsvc.exe
                              C:\Windows\system32\svchost.exe
                              C:\Windows\system32\svchost.exe
                              C:\Windows\System32\spoolsv.exe
                              C:\Windows\system32\svchost.exe
                              C:\Windows\system32\Dwm.exe
                              C:\Windows\Explorer.EXE
                              C:\PVSW\Bin\WGE_SRV.exe
                              C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
                              C:\PVSW\BIN\W3dbsmgr.EXE
                              C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
                              C:\Windows\system32\svchost.exe
                              C:\Program Files\CyberLink\Shared Files\RichVideo.exe
                              C:\Windows\Installer\MSIDFCC.tmp
                              C:\Windows\system32\svchost.exe
                              C:\Windows\System32\svchost.exe
                              C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
                              C:\Windows\system32\SearchIndexer.exe
                              C:\Windows\system32\DRIVERS\xaudio.exe
                              C:\Program Files\Hewlett-Packard\Shared\hpqWmiEx.exe
                              C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
                              C:\Windows\system32\WerCon.exe
                              C:\Windows\system32\taskeng.exe
                              C:\Windows\System32\alg.exe
                              C:\Windows\system32\wbem\wmiprvse.exe
                              C:\Windows\system32\runonce.exe
                              C:\Windows\system32\taskeng.exe
                              C:\Windows\system32\conime.exe
                              C:\Windows\system32\PresentationSettings.exe

                              ################## | C: |

                              ################## | C:\Windows |

                              Supprimé ! C:\Windows\Prefetch\WINUPGRO.EXE-CCC1740C.pf

                              ################## | C:\Windows\system32 |

                              ################## | C:\Windows\system32\drivers |

                              ################## | C:\Users\ghesquiere\AppData\Roaming |

                              ################## | Autres suppressions ... |

                              ################## | Temporary Internet Files |

                              ################## | Registre / Clés infectieuses |

                              ################## | Etat / Services / Informations |

                              # Mode sans echec : OK

                              # Affichage des fichiers cachés : OK

                              # Uac : OK

                              # Ndisuio -> Start = 3 ( Good = 3 | Bad = 4 )
                              # EapHost -> Start = 2 ( Good = 2 | Bad = 4 )
                              # Wlansvc -> Start = 2 ( Good = 2 | Bad = 4 )
                              # SharedAccess -> Start = 2 ( Good = 2 | Bad = 4 )
                              # windefend -> Start = 2 ( Good = 2 | Bad = 4 )
                              # wuauserv -> Start = 2 ( Good = 2 | Bad = 4 )
                              # wscsvc -> Start = 2 ( Good = 2 | Bad = 4 )

                              ################## | PEH ... |

                              Corrompu : C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe
                              [Offset = 000000FC - Valeur = 0x0001]

                              ################## | Cracks / Keygens / Serials |

                              "C:\Program Files\BoontyGames\Supermarket Mania\keygen.exe"
                              04/07/2009 03:39 |Size 165888 |Crc32 bbbfaf15 |Md5 67aabe94b82b15a885d41d5188a7330b

                              "C:\Program Files\web creator\Crack\WebCreatorPro4.exe"
                              27/12/2007 17:30 |Size 3506176 |Crc32 8358ba44 |Md5 234bec69956c97d1d17e2dbb17f3bf6c

                              "C:\Users\ghesquiere\Downloads\eMule\Incoming\batiprix divers\EBP_BATIMENT_2008MAINTENANCE_FR_9_0_0_1681\Crack\BatimentMaintenance.exe"
                              13/01/2008 14:58 |Size 16286720 |Crc32 4a3e2a54 |Md5 f08817e4a48a299e2abef9cb1e1ad2b5

                              "C:\Users\ghesquiere\Downloads\eMule\Incoming\batiprix divers\EBP_BATIMENT_2008PRO_FR_9_0_0_1681\Crack\BatimentPro.exe"
                              13/01/2008 03:13 |Size 16436736 |Crc32 338f755f |Md5 5bbb0febabfa6e1baadd49af39e7bfd0

                              ################## | ! Fin du rapport # FindyKill V5.017 ! |
                              1. 1)repasse findykill en option 2 et colle le rapport. merci

                                2)enleve cela car en relancant ces programmes tu pourrais de nouveau etre infecte.
                                ################## | Cracks / Keygens / Serials |

                                "C:\Program Files\BoontyGames\Supermarket Mania\keygen.exe"
                                04/07/2009 03:39 |Size 165888 |Crc32 bbbfaf15 |Md5 67aabe94b82b15a885d41d5188a7330b

                                "C:\Program Files\web creator\Crack\WebCreatorPro4.exe"
                                27/12/2007 17:30 |Size 3506176 |Crc32 8358ba44 |Md5 234bec69956c97d1d17e2dbb17f3bf6c

                                "C:\Users\ghesquiere\Downloads\eMule\Incoming\batiprix divers\EBP_BATIMENT_2008MAINTENANCE_FR_9_0_0_1681\Crack\BatimentMaintenance.exe"
                                13/01/2008 14:58 |Size 16286720 |Crc32 4a3e2a54 |Md5 f08817e4a48a299e2abef9cb1e1ad2b5

                                "C:\Users\ghesquiere\Downloads\eMule\Incoming\batiprix divers\EBP_BATIMENT_2008PRO_FR_9_0_0_1681\Crack\BatimentPro.exe"
                                13/01/2008 03:13 |Size 16436736 |Crc32 338f755f |Md5 5bbb0febabfa6e1baadd49af39e7bfd0

                                ################## | ! Fin du rapport # FindyKill V5.017 ! |

                                3)il ne faut qu un seul antivirus sur un pc ,desinstalle celui qui te reste et je dirai de reinstaller kaspersky,(spybot plus la peine tu en mieux en gratuit on verra apres).
                                1. bonsoir
                                  merci de votre aide
                                  J'ai désinstallé KIS et spybot de mon ordi
                                  Les prises usb ne fonctionnent tjrs pas
                                  j'ai refait findykill option 1 le rapport est ci_dessous
                                  Je peux reinstaller KIS ou Microsoft securité essencial est suffisant ?
                                  merci encore

                                  Rapport :

                                  ############################## | FindyKill V5.017 |

                                  # User : ghesquiere (Administrateurs) # PC-DE-GHESQUIER
                                  # Update on 01/11/2009 by Chiquitine29
                                  # Start at: 18:11:21 | 02/11/2009
                                  # Website : http://pagesperso-orange.fr/NosTools/index.html
                                  # Contact : FindyKill.Contact@gmail.com

                                  # Intel(R) Pentium(R) Dual CPU T2370 @ 1.73GHz
                                  # Microsoft® Windows Vista™ Édition Familiale Premium (6.0.6000 32-bit) #
                                  # Internet Explorer 8.0.6001.18828
                                  # Windows Firewall Status : Enabled
                                  # AV : Kaspersky Internet Security 8.0.0.357 [ (!) Disabled | Updated ]
                                  # AV : Microsoft Security Essentials 2.0.6212.0 [ Enabled | Updated ]

                                  # C:\ # Disque fixe local # 221,29 Go (134,71 Go free) # NTFS
                                  # D:\ # Disque fixe local # 11,6 Go (2,13 Go free) [PRESARIO_RP] # NTFS
                                  # E:\ # Disque CD-ROM # 201,21 Mo (0 Mo free) [KasperskyIS2009] # CDFS

                                  ############################## | Processus actifs |

                                  C:\Windows\System32\smss.exe
                                  C:\Windows\system32\csrss.exe
                                  C:\Windows\system32\wininit.exe
                                  C:\Windows\system32\csrss.exe
                                  C:\Windows\system32\services.exe
                                  C:\Windows\system32\lsass.exe
                                  C:\Windows\system32\lsm.exe
                                  C:\Windows\system32\winlogon.exe
                                  C:\Windows\system32\svchost.exe
                                  C:\Windows\system32\svchost.exe
                                  c:\Program Files\Microsoft Security Essentials\MsMpEng.exe
                                  C:\Windows\System32\svchost.exe
                                  C:\Windows\System32\svchost.exe
                                  C:\Windows\system32\svchost.exe
                                  C:\Windows\system32\svchost.exe
                                  C:\Windows\system32\SLsvc.exe
                                  C:\Windows\system32\svchost.exe
                                  C:\Windows\system32\svchost.exe
                                  C:\Windows\System32\spoolsv.exe
                                  C:\Windows\system32\svchost.exe
                                  C:\Windows\system32\Dwm.exe
                                  C:\Windows\Explorer.EXE
                                  C:\PVSW\Bin\WGE_SRV.exe
                                  C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
                                  C:\PVSW\BIN\W3dbsmgr.EXE
                                  C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
                                  C:\Windows\system32\svchost.exe
                                  C:\Program Files\CyberLink\Shared Files\RichVideo.exe
                                  C:\Windows\Installer\MSIDFCC.tmp
                                  C:\Windows\system32\svchost.exe
                                  C:\Windows\System32\svchost.exe
                                  C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
                                  C:\Windows\system32\SearchIndexer.exe
                                  C:\Windows\system32\DRIVERS\xaudio.exe
                                  C:\Program Files\Hewlett-Packard\Shared\hpqWmiEx.exe
                                  C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
                                  C:\Windows\system32\taskeng.exe
                                  C:\Windows\System32\alg.exe
                                  C:\Windows\system32\taskeng.exe
                                  C:\Program Files\Hp\QuickPlay\QPService.exe
                                  C:\Windows\System32\igfxpers.exe
                                  C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
                                  C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
                                  C:\Program Files\Apoint2K\Apoint.exe
                                  C:\Program Files\Java\jre6\bin\jusched.exe
                                  C:\Program Files\Hp\HP Software Update\hpwuSchd2.exe
                                  C:\Windows\System32\wpcumi.exe
                                  C:\Program Files\Registry Mechanic\RMTray.exe
                                  C:\Windows\ehome\ehtray.exe
                                  C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
                                  C:\Program Files\Free Download Manager\fdm.exe
                                  C:\Windows\system32\wbem\wmiprvse.exe
                                  C:\Windows\WindowsMobile\wmdSync.exe
                                  C:\Program Files\Microsoft Security Essentials\msseces.exe
                                  C:\Windows\system32\msiexec.exe
                                  C:\Windows\system32\svchost.exe
                                  C:\Windows\system32\wuauclt.exe
                                  C:\Windows\system32\igfxsrvc.exe
                                  C:\Program Files\Windows Sidebar\sidebar.exe
                                  C:\Windows\servicing\TrustedInstaller.exe
                                  C:\Windows\ehome\ehmsas.exe
                                  C:\Program Files\Hewlett-Packard\HP wireless Assistant\WiFiMsg.EXE
                                  C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe
                                  C:\Program Files\Apoint2K\ApMsgFwd.exe
                                  C:\Program Files\Apoint2K\Apntex.exe
                                  C:\Windows\system32\conime.exe
                                  C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
                                  c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
                                  C:\Windows\system32\SearchProtocolHost.exe
                                  C:\Windows\system32\SearchFilterHost.exe
                                  C:\Windows\system32\wbem\wmiprvse.exe

                                  ################## | C: |

                                  ################## | C:\Windows |

                                  ################## | C:\Windows\system32 |

                                  ################## | C:\Windows\system32\drivers |

                                  ################## | C:\Users\ghesquiere\AppData\Roaming |

                                  ################## | Autres detections ... |

                                  ################## | Temporary Internet Files |

                                  ################## | Registre / Clés infectieuses |

                                  Présent ! [HKLM\software\microsoft\security center\Svc] "AntiVirusOverride"
                                  Présent ! [HKLM\software\microsoft\security center\Svc] "FirewallOverride"

                                  ################## | Etat / Services / Informations |

                                  # Affichage des fichiers cachés : OK

                                  # Mode sans echec : OK

                                  # Uac : OK

                                  # Ndisuio -> Start = 3 ( Good = 3 | Bad = 4 )
                                  # EapHost -> Start = 2 ( Good = 2 | Bad = 4 )
                                  # Wlansvc -> Start = 2 ( Good = 2 | Bad = 4 )
                                  # SharedAccess -> Start = 2 ( Good = 2 | Bad = 4 )
                                  # windefend -> Start = 2 ( Good = 2 | Bad = 4 )
                                  # wuauserv -> Start = 2 ( Good = 2 | Bad = 4 )
                                  # wscsvc -> Start = 2 ( Good = 2 | Bad = 4 )

                                  ################## | Cracks / Keygens / Serials |

                                  "C:\Program Files\BoontyGames\Supermarket Mania\keygen.exe"
                                  04/07/2009 03:39 |Size 165888 |Crc32 bbbfaf15 |Md5 67aabe94b82b15a885d41d5188a7330b

                                  "C:\Program Files\web creator\Crack\WebCreatorPro4.exe"
                                  27/12/2007 17:30 |Size 3506176 |Crc32 8358ba44 |Md5 234bec69956c97d1d17e2dbb17f3bf6c

                                  "C:\Users\ghesquiere\Downloads\eMule\Incoming\batiprix divers\EBP_BATIMENT_2008MAINTENANCE_FR_9_0_0_1681\Crack\BatimentMaintenance.exe"
                                  13/01/2008 14:58 |Size 16286720 |Crc32 4a3e2a54 |Md5 f08817e4a48a299e2abef9cb1e1ad2b5

                                  "C:\Users\ghesquiere\Downloads\eMule\Incoming\batiprix divers\EBP_BATIMENT_2008PRO_FR_9_0_0_1681\Crack\BatimentPro.exe"
                                  13/01/2008 03:13 |Size 16436736 |Crc32 338f755f |Md5 5bbb0febabfa6e1baadd49af39e7bfd0

                                  ################## | ! Fin du rapport # FindyKill V5.017 ! |
                                  1. etrange le rapport option 2(tu l avais peut etre effectue mais je ne l ai pas vu ce rapport de suppression) , refais findykill en option 1.

                                    je te conseille de desinstaller kaspersky , spybot et del es reinstaller.

                                    supprime les cracks car si tu les relances tu peux a nouveau etre infecte.

                                    merci.
                                    1. ma souris et mes prises usb ne fonctionnent tjs pas
                                      j'ai refait un rsit
                                      voici le rapport:

                                      Logfile of random's system information tool 1.06 (written by random/random)
                                      Run by ghesquiere at 2009-11-02 08:01:53
                                      Microsoft® Windows Vista™ Édition Familiale Premium
                                      System drive C: has 137 GB (60%) free of 227 GB
                                      Total RAM: 3061 MB (50% free)

                                      Logfile of Trend Micro HijackThis v2.0.2
                                      Scan saved at 08:02:01, on 02/11/2009
                                      Platform: Windows Vista (WinNT 6.00.1904)
                                      MSIE: Internet Explorer v8.00 (8.00.6001.18828)
                                      Boot mode: Normal

                                      Running processes:
                                      C:\Windows\system32\Dwm.exe
                                      C:\Windows\Explorer.EXE
                                      C:\Windows\system32\taskeng.exe
                                      C:\Windows\system32\conime.exe
                                      C:\Program Files\Hp\QuickPlay\QPService.exe
                                      C:\Windows\System32\igfxpers.exe
                                      C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
                                      C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
                                      C:\Windows\System32\hkcmd.exe
                                      C:\Program Files\Apoint2K\Apoint.exe
                                      C:\Windows\WindowsMobile\wmdSync.exe
                                      C:\Program Files\Java\jre6\bin\jusched.exe
                                      C:\Program Files\Hp\HP Software Update\hpwuSchd2.exe
                                      C:\Windows\System32\wpcumi.exe
                                      C:\Program Files\Microsoft Security Essentials\msseces.exe
                                      C:\Program Files\Windows Sidebar\sidebar.exe
                                      C:\Program Files\Registry Mechanic\RMTray.exe
                                      C:\Windows\ehome\ehtray.exe
                                      C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
                                      C:\Program Files\Free Download Manager\fdm.exe
                                      C:\Windows\system32\igfxsrvc.exe
                                      C:\Program Files\Micro Application\LauncherMA.exe
                                      C:\Windows\system32\wuauclt.exe
                                      C:\Windows\ehome\ehmsas.exe
                                      C:\Program Files\Hewlett-Packard\HP wireless Assistant\WiFiMsg.EXE
                                      C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe
                                      C:\Program Files\Apoint2K\ApMsgFwd.exe
                                      C:\Program Files\Apoint2K\Apntex.exe
                                      C:\Program Files\Internet Explorer\iexplore.exe
                                      C:\Program Files\Internet Explorer\iexplore.exe
                                      C:\Windows\system32\Macromed\Flash\FlashUtil10b.exe
                                      C:\Windows\system32\SearchProtocolHost.exe
                                      C:\Windows\system32\SearchFilterHost.exe
                                      C:\Users\ghesquiere\Desktop\RSIT.exe
                                      C:\Program Files\trend micro\ghesquiere.exe

                                      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr?cobrand=compaq-notebook.msn.com&ocid=HPDHP&pc=CPNTDF
                                      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
                                      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr?cobrand=compaq-notebook.msn.com&ocid=HPDHP&pc=CPNTDF
                                      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                                      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                                      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr?cobrand=compaq-notebook.msn.com&ocid=HPDHP&pc=CPNTDF
                                      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
                                      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
                                      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                                      R3 - Default URLSearchHook is missing
                                      O1 - Hosts: ::1 localhost
                                      O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                                      O2 - BHO: Smart-Shopper - {4A7C84E2-E95C-43C6-8DD3-03ABCD0EB60E} - (no file)
                                      O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
                                      O2 - BHO: IEVkbdBHO - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\ievkbd.dll
                                      O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
                                      O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - (no file)
                                      O2 - BHO: RoboForm - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
                                      O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live ID - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                                      O2 - BHO: FDMIECookiesBHO Class - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Program Files\Free Download Manager\iefdm2.dll
                                      O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
                                      O3 - Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - (no file)
                                      O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
                                      O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe"
                                      O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
                                      O4 - HKLM\..\Run: [UCam_Menu] "C:\Program Files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\YouCam" update "Software\CyberLink\YouCam\1.0"
                                      O4 - HKLM\..\Run: [RoxWatchTray] "C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe"
                                      O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
                                      O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
                                      O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
                                      O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
                                      O4 - HKLM\..\Run: [IAAnotif] "C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe"
                                      O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
                                      O4 - HKLM\..\Run: [HP Health Check Scheduler] [ProgramFilesFolder]Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
                                      O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
                                      O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
                                      O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
                                      O4 - HKLM\..\Run: [Windows Mobile-based device management] %windir%\WindowsMobile\wmdSync.exe
                                      O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
                                      O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
                                      O4 - HKLM\..\Run: [WPCUMI] C:\Windows\system32\WpcUmi.exe
                                      O4 - HKLM\..\Run: [MSSE] "c:\Program Files\Microsoft Security Essentials\msseces.exe" -hide
                                      O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
                                      O4 - HKCU\..\Run: [RegistryMechanic] C:\Program Files\Registry Mechanic\RMTray.exe /H
                                      O4 - HKCU\..\Run: [HPAdvisor] C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe autoRun
                                      O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
                                      O4 - HKCU\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler
                                      O4 - HKCU\..\Run: [Free Download Manager] "C:\Program Files\Free Download Manager\fdm.exe" -autorun
                                      O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                                      O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
                                      O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
                                      O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
                                      O4 - Startup: Lanceur.lnk = C:\Program Files\Micro Application\LauncherMA.exe
                                      O4 - Startup: OneNote 2007 - Capture d'écran et lancement.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
                                      O4 - Global Startup: Desktop Manager.lnk = C:\Program Files\Research In Motion\BlackBerry\DesktopMgr.exe
                                      O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
                                      O8 - Extra context menu item: Tout télécharger avec Free Download Manager - file://C:\Program Files\Free Download Manager\dlall.htm
                                      O8 - Extra context menu item: Télécharger avec Free Download Manager - file://C:\Program Files\Free Download Manager\dllink.htm
                                      O8 - Extra context menu item: Télécharger la sélection avec Free Download Manager - file://C:\Program Files\Free Download Manager\dlselected.htm
                                      O8 - Extra context menu item: Télécharger la vidéo avec Free Download Manager - file://C:\Program Files\Free Download Manager\dlfvideo.htm
                                      O9 - Extra button: Statistiques de la protection du trafic Internet - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\SCIEPlgn.dll
                                      O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
                                      O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
                                      O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
                                      O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
                                      O9 - Extra button: Remplir - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
                                      O9 - Extra 'Tools' menuitem: Remplir le formulaire - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
                                      O9 - Extra button: Enregistrer - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
                                      O9 - Extra 'Tools' menuitem: Enregistrer le formulaire - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
                                      O9 - Extra button: Run WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - F:\App\WinHTTrack\WinHTTrackIEBar.dll (file missing)
                                      O9 - Extra 'Tools' menuitem: Launch WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - F:\App\WinHTTrack\WinHTTrackIEBar.dll (file missing)
                                      O9 - Extra button: Barre RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
                                      O9 - Extra 'Tools' menuitem: Barre RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
                                      O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe (file missing)
                                      O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe (file missing)
                                      O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
                                      O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
                                      O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
                                      O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
                                      O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
                                      O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
                                      O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
                                      O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
                                      O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
                                      O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
                                      O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
                                      O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
                                      O13 - Gopher Prefix:
                                      O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} (OnlineScanner Control) - http://download.eset.com/special/eos-beta/OnlineScanner.cab
                                      O17 - HKLM\System\CCS\Services\Tcpip\..\{A34DCA64-67D3-4D22-ADB7-8FF4DBAEFE8A}: NameServer = 192.168.1.1
                                      O20 - AppInit_DLLs: C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd.dll,C:\PROGRA~1\KASPER~1\KASPER~1\adialhk.dll,C:\PROGRA~1\KASPER~1\KASPER~1\kloehk.dll
                                      O23 - Service: Kaspersky Internet Security (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe
                                      O23 - Service: Boonty Games - BOONTY - C:\Program Files\Common Files\BOONTY Shared\Service\Boonty.exe
                                      O23 - Service: Com4Qlb - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4Qlb.exe
                                      O23 - Service: EBP Pervasive.SQL - Unknown owner - C:\PVSW\Bin\WGE_SRV.exe
                                      O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files\HP Games\My HP Game Console\GameConsoleService.exe
                                      O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
                                      O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqWmiEx.exe
                                      O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
                                      O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
                                      O23 - Service: Nero BackItUp Scheduler 4.0 - Nero AG - C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
                                      O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
                                      O23 - Service: Roxio UPnP Renderer 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUPnPRenderer9.exe
                                      O23 - Service: Roxio Upnp Server 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUpnpService9.exe
                                      O23 - Service: LiveShare P2P Server 9 (RoxLiveShare9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe
                                      O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
                                      O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
                                      O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
                                      O23 - Service: SolidConverterPDFReadSpool (SCPDFReadSpool) - Solid Documents, LLC - C:\Windows\Installer\MSIDFCC.tmp
                                      O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
                                      • 1
                                      • 2