Security Center Alert

Résolu
Bonjour,
Depuis 3-4 jours, j'ai un problème avec mon PC puisqu'une fenêtre Security Center Alert s'ouvre régulièrement me dirigeant vers un logiciel payant! J'ai téléchargé Spybot et SmitfraudFix mais je n'arrive pas à ouvrir ces logiciels pour faire un peu de ménage.
Si vous pouviez m'aider à résoudre ces problèmes je vous en serais reconnaissant.
Configuration: Windows XP
Firefox 3.5.6

23 réponses

Résumé de la discussion

Un problème récurrent de sécurité déclenche une fenêtre Security Center Alert qui dirige vers un logiciel payant, avec Windows XP et Firefox 3.5.6 et des difficultés à lancer les outils de nettoyage. Plusieurs réponses suggèrent des nettoyages en profondeur et l’utilisation d’outils dédiés comme ESET Online Scanner, avec rapport détaillé et suppression des infections identifiées et quarantaines associées. D’autres interventions proposent des outils supplémentaires tels que RSIT, TDSSKiller et Combofix, pour retrouver des composants indésirables, supprimer des dossiers suspects et récupérer des paramètres explorés par les extensions du navigateur. En parallèle, des nettoyages ciblés évoquent la suppression de programmes indésirables et de barres d’outils (AskSBar, ToolBar SD), puis la remise en ordre des navigateurs et l’obtention de rapports à partager.

Bobot (l’IA à votre service)
  1. Salut dédétraqué,

    Voici le rapport:

    [ Rapport ToolsCleaner version 2.3.11 (par A.Rothstein & dj QUIOU) ]

    --> Recherche:

    C:\Combofix.txt: trouvé !
    C:\TB.txt: trouvé !
    C:\Combofix: trouvé !
    C:\Qoobox: trouvé !
    C:\_OTM: trouvé !
    C:\Toolbar SD: trouvé !
    C:\Rsit: trouvé !
    C:\Backups\catchme.log: trouvé !
    C:\Documents and Settings\clovis\Bureau\OTM.exe: trouvé !
    C:\Documents and Settings\clovis\Bureau\ToolBarSD.exe: trouvé !
    C:\Documents and Settings\clovis\Bureau\mbr.log: trouvé !
    C:\Documents and Settings\clovis\Bureau\mbr.exe: trouvé !
    C:\Documents and Settings\clovis\Bureau\Rsit.exe: trouvé !
    C:\Program Files\trend micro\HijackThis.exe: trouvé !
    C:\Program Files\trend micro\hijackthis.log: trouvé !
    C:\Qoobox\Quarantine\catchme.log: trouvé !
    C:\WINDOWS\mbr.exe: trouvé !

    Point de restauration crée !
    Corbeille vidée!
    Fichiers temporaires nettoyés !
    ---------------------------------
    --> Suppression:
    C:\Documents and Settings\clovis\Bureau\OTM.exe: supprimé !
    C:\Documents and Settings\clovis\Bureau\ToolBarSD.exe: supprimé !
    C:\Program Files\trend micro\HijackThis.exe: supprimé !
    C:\Combofix.txt: supprimé !
    C:\TB.txt: supprimé !
    C:\Backups\catchme.log: supprimé !
    C:\Documents and Settings\clovis\Bureau\mbr.log: supprimé !
    C:\Documents and Settings\clovis\Bureau\mbr.exe: supprimé !
    C:\Documents and Settings\clovis\Bureau\Rsit.exe: supprimé !
    C:\Program Files\trend micro\hijackthis.log: supprimé !
    C:\Qoobox\Quarantine\catchme.log: supprimé !
    C:\WINDOWS\mbr.exe: supprimé !
    C:\Combofix: supprimé !
    C:\Qoobox: supprimé !
    C:\_OTM: supprimé !
    C:\Toolbar SD: supprimé !
    C:\Rsit: supprimé !

    Point de restauration crée !
    Corbeille vidée!
    Fichiers temporaires nettoyés !
    1. Contributeur sécurité
      Salut fatherted

      Effectivement tu as trop de programme et service inutile au démarrage, aide toi de ce lien :
      https://forum.malekal.com/viewtopic.php?t=16583&start=

      On va faire un ménage des outils téléchargés pour la désinfection, télécharge Tools Cleaner sur le bureau :

      http://pc-system.fr/

      - Double clique sur ToolsCleaner2.exe sur le bureau
      - Clique sur Recherche et laisse le scan agir.
      - Clique sur Suppression pour finaliser.
      - Tu peux, si tu le souhaites, te servir des Options facultatives.
      - Clique sur Quitter pour obtenir le rapport.
      - Poste le rapport (TCleaner.txt) qui se trouve à la racine de ton disque dur (C:\).
      - Si des outils restes après le passage de Tools Cleaner, tu pourras les supprimer manuellement ainsi que tous les rapports qui on été généré lors de la désinfection.

      -----

      Je te donne quelques consignes de sécurité :

      - Windows Update parfaitement à jour http://www.windowsupdate.com/windowsupdate/v6/default.aspx (catégories critique, Services Pack et Services Release)
      - pare-feu bien paramétré, je te conseil ZoneAlarm :
      https://www.malekal.com/tutoriel-zonealarm-firewall/
      - antivirus bien paramétré et mis à jour régulièrement (quotidiennement s'il le faut) avec un scan complet régulier (journalier s'il le faut).
      - une attitude prudente vis à vis de la navigation (pas de sites douteux : cracks, warez, sexe...) et vis à vis de la messagerie (fichiers joints aux messages doivent être scannés avant d'être ouverts)
      - pas de téléchargement illégal, qui est le principal facteur d’infection (µTorrent, BitTorrent, eMule, Limewire, etc..) http://forum.malekal.com/ftopic893.php
      - une attitude vigilante (être à l'affût d'un fonctionnement inhabituel de son système)
      - nettoyage hebdomadaire du système (suppression des fichiers inutiles, nettoyage de la base de registre, scandisk, defrag)
      - scan hebdomadaire antispyware, je conseil MalwareByte's Anti-Malware :
      https://www.malekal.com/tutoriel-malwarebyte-anti-malware/
      - un contrôle régulier de la console JAVA pour s'assurer qu'elle est à jour :
      https://www.java.com/en/download/uninstalltool.jsp
      - faire régulièrement un scan de vulnérabilités afin de vérifier que tes logiciels soit à jour sans failles de sécurités :
      https://www.malekal.com/tester-la-vulnerabilite-de-son-systeme-2/

      De bonne lecture si tu veux en savoir plus sur la sécurité et le fonctionnement de Windows :
      http://www.malekal.com/menu_windows_general.php
      http://www.malekal.com/menu_windows_securite.php

      Si tu considères ton problème comme résolu, tu pourras mettre en résolu :
      https://www.commentcamarche.net/infos/25917-marquer-un-fil-de-discussion-comme-etant-resolu/

      Bonne journée/soirée et bon surf

      @++ :)
      1. Salut dédétraqué,

        Ça m'a l'air d'être bon! Je te remercie de m'avoir assisté durant ce protocole de désinfection!
        Heureusement qu'il existe des personnes comme toi qui "sauvent" les ordis des novices.
        Bonne continuation!
    2. Salut dédétraqué,

      Voici le rapport RSIT:

      Logfile of random's system information tool 1.06 (written by random/random)
      Run by clovis at 2010-01-12 02:58:05
      Microsoft Windows XP Édition familiale Service Pack 3
      System drive C: has 8 GB (14%) free of 54 GB
      Total RAM: 2046 MB (49% free)

      Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 02:58:19, on 12/01/2010
      Platform: Windows XP SP3 (WinNT 5.01.2600)
      MSIE: Internet Explorer v8.00 (8.00.6001.18702)
      Boot mode: Normal

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\csrss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\Program Files\COMODO\Firewall\cmdagent.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\Program Files\Intel\WiFi\bin\S24EvMon.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\Explorer.EXE
      C:\WINDOWS\system32\spoolsv.exe
      C:\Program Files\Avira\AntiVir Desktop\sched.exe
      C:\WINDOWS\system32\svchost.exe
      C:\Program Files\Fichiers communs\ArcSoft\Connection Service\Bin\ACService.exe
      C:\Program Files\Avira\AntiVir Desktop\avguard.exe
      C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
      C:\Program Files\Bonjour\mDNSResponder.exe
      C:\Program Files\Home Cinema\PowerCinema\Kernel\TV\CLCapSvc.exe
      C:\Program Files\Home Cinema\PowerCinema\Kernel\CLML_NTService\CLMLServer.exe
      C:\Program Files\Intel\WiFi\bin\EvtEng.exe
      C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\Program Files\Java\jre6\bin\jqs.exe
      C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
      C:\WINDOWS\system32\nvsvc32.exe
      C:\WINDOWS\system32\PnkBstrA.exe
      C:\WINDOWS\system32\PnkBstrB.exe
      C:\Program Files\Fichiers communs\Intel\WirelessCommon\RegSrvc.exe
      C:\Program Files\Cyberlink\Shared files\RichVideo.exe
      C:\WINDOWS\system32\svchost.exe
      C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe
      C:\Program Files\Home Cinema\PowerCinema\Kernel\TV\CLSched.exe
      C:\Program Files\Windows Media Player\WMPNetwk.exe
      C:\WINDOWS\system32\wbem\wmiprvse.exe
      C:\WINDOWS\system32\wbem\wmiapsrv.exe
      C:\WINDOWS\System32\alg.exe
      C:\PROGRA~1\MESSAG~1\StartMessager.exe
      C:\PROGRA~1\Wanadoo\CnxMon.exe
      C:\Program Files\Fichiers communs\ArcSoft\Connection Service\Bin\ACDaemon.exe
      C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
      C:\Program Files\COMODO\SafeSurf\cssurf.exe
      C:\Program Files\COMODO\Firewall\cfp.exe
      C:\WINDOWS\system32\rundll32.exe
      C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
      C:\WINDOWS\system32\RUNDLL32.EXE
      C:\Program Files\Intel\WiFi\bin\ZCfgSvc.exe
      C:\Program Files\Fichiers communs\Intel\WirelessCommon\iFrmewrk.exe
      C:\WINDOWS\RTHDCPL.EXE
      C:\WINDOWS\6000RMT.exe
      C:\WINDOWS\vspc1300.exe
      C:\Program Files\Java\jre6\bin\jusched.exe
      C:\Program Files\BboxUpdate\BTLiveUpdate.exe
      C:\Program Files\iTunes\iTunesHelper.exe
      C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
      C:\Program Files\SuperCopier2\SuperCopier2.exe
      C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
      C:\Program Files\Fichiers communs\Nero\Lib\NMBgMonitor.exe
      C:\WINDOWS\system32\ctfmon.exe
      C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
      C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
      C:\Program Files\Logitech\SetPoint\SetPoint.exe
      C:\Program Files\Panasonic\PHOTOfunSTUDIO -viewer-\PhAutoRun.exe
      C:\Program Files\Logitech\SetPoint II\SetpointII.exe
      C:\Program Files\Philips\Philips SPC1300NC Webcam\TrayMin1300.exe
      C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
      C:\Program Files\SpywareGuard\sgmain.exe
      C:\Program Files\Fichiers communs\Logishrd\KHAL2\KHALMNPR.EXE
      C:\Program Files\Fichiers communs\Nero\Lib\NMIndexingService.exe
      C:\Program Files\SpywareGuard\sgbhp.exe
      C:\Program Files\Fichiers communs\Nero\Lib\NMIndexStoreSvr.exe
      C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\AlertModule\2\AlertModule.exe
      C:\WINDOWS\system32\wbem\unsecapp.exe
      C:\WINDOWS\system32\wbem\wmiprvse.exe
      C:\Program Files\iPod\bin\iPodService.exe
      C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
      C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe
      C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe
      C:\Program Files\OrangeHSS\systray\systrayapp.exe
      C:\WINDOWS\System32\svchost.exe
      C:\Program Files\iTunes\iTunes.exe
      C:\WINDOWS\system32\wscntfy.exe
      C:\Program Files\Mozilla Firefox\firefox.exe
      C:\Documents and Settings\clovis\Bureau\RSIT.exe
      C:\WINDOWS\system32\wbem\wmiprvse.exe
      C:\Program Files\trend micro\clovis.exe

      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
      R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
      R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\Program Files\OrangeHSS\SearchURLHook\SearchPageURL.dll
      O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
      O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
      O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
      O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
      O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
      O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll
      O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
      O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
      O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
      O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
      O4 - HKLM\..\Run: [DXM6Patch_981116] C:\WINDOWS\p_981116.exe /Q:A
      O4 - HKLM\..\Run: [MessagerStarter Wanadoo] C:\PROGRA~1\MESSAG~1\StartMessager.exe Messager Wanadoo
      O4 - HKLM\..\Run: [WooCnxMon] C:\PROGRA~1\Wanadoo\CnxMon.exe
      O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
      O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\Wanadoo\TaskbarIcon.exe
      O4 - HKLM\..\Run: [ArcSoft Connection Service] C:\Program Files\Fichiers communs\ArcSoft\Connection Service\Bin\ACDaemon.exe
      O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
      O4 - HKLM\..\Run: [hpqSRMon] C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe
      O4 - HKLM\..\Run: [COMODO SafeSurf] "C:\Program Files\COMODO\SafeSurf\cssurf.exe" -s
      O4 - HKLM\..\Run: [COMODO Firewall Pro] "C:\Program Files\COMODO\Firewall\cfp.exe" -h
      O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
      O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
      O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
      O4 - HKLM\..\Run: [COMODO Internet Security] "C:\Program Files\COMODO\Firewall\cfp.exe" -h
      O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
      O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\WiFi\bin\ZCfgSvc.exe"
      O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Fichiers communs\Intel\WirelessCommon\iFrmewrk.exe" /tf Intel Wireless Tray
      O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
      O4 - HKLM\..\Run: [TV Card Remote Control Device Monitor] C:\WINDOWS\6000RMT.exe
      O4 - HKLM\..\Run: [SPC1300] C:\WINDOWS\vspc1300.exe
      O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
      O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
      O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
      O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
      O4 - HKLM\..\Run: [ORAHSSSessionManager] "C:\Program Files\OrangeHSS\SessionManager\SessionManager.exe"
      O4 - HKLM\..\Run: [BboxUpdate] C:\Program Files\BboxUpdate\BTLiveUpdate.exe
      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
      O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
      O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
      O4 - HKCU\..\Run: [SuperCopier2.exe] C:\Program Files\SuperCopier2\SuperCopier2.exe
      O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
      O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Nero\Lib\NMBgMonitor.exe"
      O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
      O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
      O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
      O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
      O4 - Startup: OneNote 2007 - Capture d'écran et lancement.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
      O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
      O4 - Global Startup: DSLMON.lnk = C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
      O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
      O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
      O4 - Global Startup: PHOTOfunSTUDIO -viewer-.lnk = C:\Program Files\Panasonic\PHOTOfunSTUDIO -viewer-\PhAutoRun.exe
      O4 - Global Startup: SetPointII.lnk = ?
      O4 - Global Startup: TrayMin1300.lnk = ?
      O8 - Extra context menu item: &Recherche AOL Toolbar - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
      O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000
      O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
      O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll
      O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll
      O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\Office12\REFIEBAR.DLL
      O9 - Extra button: Organise-notes - {9455301C-CF6B-11D3-A266-00C04F689C50} - C:\Program Files\Fichiers communs\Microsoft Shared\Encarta Researcher\EROPROJ.DLL
      O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
      O9 - Extra button: Sélection intelligente HP - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
      O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
      O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra button: Wanadoo - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - http://www.wanadoo.fr (file missing) (HKCU)
      O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} (OnlineScanner Control) - http://download.eset.com/special/eos/OnlineScanner.cab
      O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
      O16 - DPF: {E77F23EB-E7AB-4502-8F37-247DBAF1A147} (Windows Live Hotmail Photo Upload Tool) - http://gfx1.hotmail.com/mail/w4/pr01/photouploadcontrol/MSNPUpld.cab
      O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
      O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft - C:\Program Files\Fichiers communs\ArcSoft\Connection Service\Bin\ACService.exe
      O23 - Service: Avira AntiVir Planificateur (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
      O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
      O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
      O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
      O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - C:\Program Files\Home Cinema\PowerCinema\Kernel\TV\CLCapSvc.exe
      O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - C:\Program Files\Home Cinema\PowerCinema\Kernel\TV\CLSched.exe
      O23 - Service: COMODO Internet Security Helper Service (cmdAgent) - Unknown owner - C:\Program Files\COMODO\Firewall\cmdagent.exe
      O23 - Service: CyberLink Media Library Service - Cyberlink - C:\Program Files\Home Cinema\PowerCinema\Kernel\CLML_NTService\CLMLServer.exe
      O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel(R) Corporation - C:\Program Files\Intel\WiFi\bin\EvtEng.exe
      O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom SA - C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
      O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
      O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
      O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
      O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
      O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Fichiers communs\Logitech\Bluetooth\LBTServ.exe
      O23 - Service: Ma-Config Service (maconfservice) - CybelSoft - C:\Program Files\ma-config.com\maconfservice.exe
      O23 - Service: MSSQL$PINNACLESYS - Unknown owner - C:\Program Files\Pinnacle\MediaServer\Microsoft SQL Server\MSSQL$PINNACLESYS\Binn\sqlservr.exe (file missing)
      O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
      O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Fichiers communs\Nero\Lib\NMIndexingService.exe
      O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
      O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
      O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe
      O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel(R) Corporation - C:\Program Files\Fichiers communs\Intel\WirelessCommon\RegSrvc.exe
      O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\Cyberlink\Shared files\RichVideo.exe
      O23 - Service: Intel® PROSet/Wireless WiFi Service (S24EventMonitor) - Intel(R) Corporation - C:\Program Files\Intel\WiFi\bin\S24EvMon.exe
      O23 - Service: X10 Device Network Service (x10nets) - X10 - C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe
      1. Contributeur sécurité
        Salut fatherted

        Supprime ce dossier C:\rsit

        Refais un scan avec RSIT et poste le rapport log.txt et info.txt à la fin de l’analyse

        Le rapport est dans le dossier ici C:\rsit

        @++ :)
        1. Contributeur sécurité
          Salut fatherted

          Cela est bon, as-tu d'autre souci?

          @++ :)
          1. Salut dédétraqué,

            Et bien écoute, à part le démarrage lent de mon ordi, j'ai l'impression que tout va bien!
            Merci beaucoup dédétraqué!
        2. Salut dédétraqué,

          Voici le rapport ESET:

          ESETSmartInstaller@High as CAB hook log:
          OnlineScanner.ocx - registred OK
          # version=7
          # IEXPLORE.EXE=8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339)
          # OnlineScanner.ocx=1.0.0.6211
          # api_version=3.0.2
          # EOSSerial=4bbb3f0750eced45a40084d4415af1c6
          # end=finished
          # remove_checked=true
          # archives_checked=true
          # unwanted_checked=true
          # unsafe_checked=true
          # antistealth_checked=true
          # utc_time=2010-01-11 01:08:33
          # local_time=2010-01-11 02:08:33 (+0100, Paris, Madrid)
          # country="France"
          # lang=1033
          # osver=5.1.2600 NT Service Pack 3
          # compatibility_mode=512 16777215 100 0 33853 33853 0 0
          # compatibility_mode=768 16777215 100 0 0 0 0 0
          # compatibility_mode=1797 16775141 100 100 25549 59222216 25753 0
          # compatibility_mode=3073 16777213 80 100 2695005 36052749 0 0
          # compatibility_mode=4096 16777215 100 0 0 0 0 0
          # compatibility_mode=8192 67108863 100 0 15114 15114 0 0
          # scanned=131775
          # found=3
          # cleaned=3
          # scan_time=10207
          C:\Mes documents\SmitfraudFix.exe multiple threats (deleted - quarantined) 00000000000000000000000000000000 C
          C:\Program Files\COMODO\Firewall\s1.tmp a variant of Win32/AdInstaller application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
          C:\Qoobox\Quarantine\C\WINDOWS\system32\Process.exe.vir Win32/PrcView application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
          1. Contributeur sécurité
            Salut fatherted

            Et le scan en ligne avait-il détecté quelque chose?

            @++ :)
            1. Salut dédétraqué,

              Oui le scan a détecté 4 fichiers infectés il me semble et les a nettoyé.
              Mais je suis en train de refaire le scan et pour le moment, 2 fichiers sont infectés:
              a variant of Win32/AdInstaller application
              multiple threats
          2. Contributeur sécurité
            Salut fatherted

            Important Désactive ton Antivirus et antispyware avant le scan :
            https://forum.pcastuces.com/default.asp

            - Double clique sur l’icône ToolBar S&D sur le bureau
            - Choisi F pour français et valide
            - Au menu principal de ToolBar S&D choisi l’option 2 (Suppression)
            - Le menu démarrer et les icônes vont à nouveau disparaître.. c'est normal.
            - Le nettoyage va prendre quelques minutes...
            - Une fois l'opération terminée, le rapport de nettoyage s'ouvre

            Copier/coller le rapport dans ton prochain poste.

            -----

            Faire un scan avec Nod32 en ligne (il faut utiliser Internet Explorer) ici :

            https://www.eset.com/int/home/online-scanner/

            (coche toutes les cases à chaque fois)
            A la fin, colle le rapport : C:\Program Files\EsetOnlineScanner\log.txt

            @++ :)
            1. Bonsoir dédétraqué,

              Je n'ai pas de rapport de ESET online scanner.
              Par contre je te poste le rapport TB:

              -----------\\ ToolBar S&D 1.2.9 XP/Vista

              Microsoft Windows XP Édition familiale ( v5.1.2600 ) Service Pack 3
              X86-based PC ( Multiprocessor Free : Genuine Intel(R) CPU T2300 @ 1.66GHz )
              BIOS : Ver 1.00PARTTBL8
              USER : clovis ( Administrator )
              BOOT : Normal boot
              Antivirus : AntiVir Desktop 9.0.1.32 (Not Activated)
              Firewall : COMODO Firewall 3.5 (Not Activated)
              C:\ (Local Disk) - NTFS - Total:53 Go (Free:7 Go)
              D:\ (Local Disk) - NTFS - Total:49 Go (Free:2 Go)
              E:\ (Local Disk) - FAT32 - Total:8 Go (Free:5 Go)
              F:\ (CD or DVD)
              H:\ (CD or DVD)

              "C:\ToolBar SD" ( MAJ : 22-08-2009|18:42 )
              Option : [2] ( 10/01/2010|20:00 )

              -----------\\ SUPPRESSION

              Supprime! - C:\Program Files\AskSBar\bar
              Supprime! - C:\DOCUME~1\clovis\Cookies\clovis@mywebsearch[2].txt
              Supprime! - C:\Program Files\AskSBar

              -----------\\ Recherche de Fichiers / Dossiers ...

              -----------\\ Extensions

              (clovis) - {20a82645-c095-46ed-80e3-08825760534b} => chrome_user

              -----------\\ [..\Internet Explorer\Main]

              [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
              "Local Page"="C:\\WINDOWS\\system32\\blank.htm"
              "Search Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"
              "Default_Search_URL"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"
              "Start Page"="https://www.google.com/?gws_rd=ssl"

              [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
              "Default_Page_URL"="https://www.msn.com/fr-fr/?ocid=iehp"
              "Default_Search_URL"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
              "Search Page"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
              "Local Page"="C:\\WINDOWS\\system32\\blank.htm"
              "Start Page"="https://www.msn.com/fr-fr/"

              --------------------\\ Recherche d'autres infections

              --------------------\\ Cracks & Keygens ..

              C:\DOCUME~1\clovis\Application Data\BitTorrent\Far.Cry.2.CRACK-DARKCODER.rar.torrent
              C:\DOCUME~1\clovis\Application Data\BitTorrent\RAZOR1911 [WEB SEED] FAR CRY 2 CRACK - REAL 100% FULLY WORKING.rar.torrent

              1 - "C:\ToolBar SD\TB_1.txt" - 10/01/2010|18:33 - Option : [1]
              2 - "C:\ToolBar SD\TB_2.txt" - 10/01/2010|20:03 - Option : [2]

              -----------\\ Fin du rapport a 20:03:08,79
          3. Contributeur sécurité
            Salut fatherted

            Télécharge Toolbar-S&D (de la Team IDN) sur ton Bureau.

            https://77b4795d-a-62cb3a1a-s-sites.googlegroups.com/site/eric71mespages/ToolBarSD.exe?attachauth=ANoY7cpVobGk5bHnxrhQ4yaoEUDJvOYNnEGyYjgqHZz5GqZLfutR3fMFPlsC3-CGIilfupPAguYATNyua3csodN_frdMK8sSzUpit10Yac-QJCOkMqJKkbdKcP6ySs8trWPgoNVIq4TGGWCe6o0txXQv-ZueJF9vZzw3RXsGwFYIqN2lvF2LPdQzS8mE1d5kWOVOz6EMzQuE5-lClSJM869uq3oc7-t7yg%3D%3D&attredirects=3

            - Double clique l’icône ToolBar S&D sur le bureau
            - Choisi F pour français et valide
            - Au menu principal de ToolBar S&D choisi l’option 1 (Recherche)
            - Le menu Démarrer et les icônes vont disparaîtrent, c'est normal
            - La recherche s'effectue, cela peut prendre plusieurs minutes, ne touche à rien.
            - Une fois l'analyse terminée, le rapport de recherche s'ouvre dans le Bloc-Note. (Dans le cas où le rapport ne s'ouvre pas, ce dernier se trouve sur C:\TB.txt)

            Copier/coller le rapport dans ton prochain poste

            @++ :)
            1. Resalut dédétraqué,

              voici le rapport:

              -----------\\ ToolBar S&D 1.2.9 XP/Vista

              Microsoft Windows XP Édition familiale ( v5.1.2600 ) Service Pack 3
              X86-based PC ( Multiprocessor Free : Genuine Intel(R) CPU T2300 @ 1.66GHz )
              BIOS : Ver 1.00PARTTBL8
              USER : clovis ( Administrator )
              BOOT : Normal boot
              Antivirus : AntiVir Desktop 9.0.1.32 (Activated)
              Firewall : COMODO Firewall 3.5 (Not Activated)
              C:\ (Local Disk) - NTFS - Total:53 Go (Free:7 Go)
              D:\ (Local Disk) - NTFS - Total:49 Go (Free:2 Go)
              E:\ (Local Disk) - FAT32 - Total:8 Go (Free:5 Go)
              F:\ (CD or DVD)
              H:\ (CD or DVD)

              "C:\ToolBar SD" ( MAJ : 22-08-2009|18:42 )
              Option : [1] ( 10/01/2010|18:31 )

              -----------\\ Recherche de Fichiers / Dossiers ...

              C:\Program Files\AskSBar
              C:\Program Files\AskSBar\bar
              C:\Program Files\AskSBar\bar\1.bin
              C:\Program Files\AskSBar\bar\Cache
              C:\Program Files\AskSBar\bar\History
              C:\Program Files\AskSBar\bar\Settings
              C:\Program Files\AskSBar\bar\1.bin\A2FFXTBR.JAR
              C:\Program Files\AskSBar\bar\1.bin\A2FFXTBR.MANIFEST
              C:\Program Files\AskSBar\bar\1.bin\A2HIGHIN.EXE
              C:\Program Files\AskSBar\bar\1.bin\A2NTSTBR.JAR
              C:\Program Files\AskSBar\bar\1.bin\A2NTSTBR.MANIFEST
              C:\Program Files\AskSBar\bar\1.bin\A2PLUGIN.DLL
              C:\Program Files\AskSBar\bar\1.bin\ASKSBAR.DLL
              C:\Program Files\AskSBar\bar\1.bin\NPASKSBR.DLL
              C:\Program Files\AskSBar\bar\Cache\002A932B.bin
              C:\Program Files\AskSBar\bar\Cache\002A982C.bin
              C:\Program Files\AskSBar\bar\Cache\002A9A5F.bin
              C:\Program Files\AskSBar\bar\Cache\002A9CA1.bin
              C:\Program Files\AskSBar\bar\Cache\002A9E85.bin
              C:\Program Files\AskSBar\bar\Cache\002AA079.bin
              C:\Program Files\AskSBar\bar\Cache\002AA56B.bin
              C:\Program Files\AskSBar\bar\Cache\002AA972.bin
              C:\Program Files\AskSBar\bar\Cache\files.ini
              C:\Program Files\AskSBar\bar\History\search2
              C:\Program Files\AskSBar\bar\Settings\prevcfg2.htm
              C:\DOCUME~1\clovis\Cookies\clovis@mywebsearch[2].txt

              -----------\\ Extensions

              (clovis) - {20a82645-c095-46ed-80e3-08825760534b} => chrome_user

              -----------\\ [..\Internet Explorer\Main]

              [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
              "Local Page"="C:\\WINDOWS\\system32\\blank.htm"
              "Search Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"
              "Default_Search_URL"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"
              "Start Page"="https://www.google.com/?gws_rd=ssl"

              [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
              "Default_Page_URL"="https://www.msn.com/fr-fr/?ocid=iehp"
              "Default_Search_URL"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
              "Search Page"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
              "Local Page"="C:\\WINDOWS\\system32\\blank.htm"
              "Start Page"="https://www.msn.com/fr-fr/?ocid=iehp"

              --------------------\\ Recherche d'autres infections

              --------------------\\ Cracks & Keygens ..

              C:\DOCUME~1\clovis\Application Data\BitTorrent\Far.Cry.2.CRACK-DARKCODER.rar.torrent
              C:\DOCUME~1\clovis\Application Data\BitTorrent\RAZOR1911 [WEB SEED] FAR CRY 2 CRACK - REAL 100% FULLY WORKING.rar.torrent

              1 - "C:\ToolBar SD\TB_1.txt" - 10/01/2010|18:33 - Option : [1]

              -----------\\ Fin du rapport a 18:33:07,78
          4. Contributeur sécurité
            Salut fatherted

            Télécharge OTM (de Old_Timer) sur le bureau :

            http://www.geekstogo.com/forum/files/file/402-otm-oldtimers-move-it/

            Double-clique sur OTM.exe sur le bureau

            - Copie le texte qui se trouve en gras ci-dessous et colle le dans le cadre de gauche de OTM nommé Paste Instructions for Items to be Moved

            :services
            catchme

            :reg
            [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}]
            [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F0D4B231-DA4B-4daf-81E4-DFEE4931A4AA}]
            [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{F0D4B239-DA4B-4daf-81E4-DFEE4931A4AA}]

            :files
            C:\Documents and Settings\All Users\Application Data\sysReserve.ini

            :commands
            [purity]
            [emptytemp]
            [reboot]


            - Clique sur MoveIt! pour lancer la suppression.
            - Ferme OTM

            Ton PC va redémarrer pour finir la suppression, si il ne le fais pas lui-même, redémarre le.

            Poste le rapport de OTMoveIt qui se trouve dans C:\_OTM\MovedFiles.

            @++ :)
            1. Resalut dédétraqué,

              Je te poste le rapport OTM:

              All processes killed
              ========== SERVICES/DRIVERS ==========
              Service catchme stopped successfully!
              Service catchme deleted successfully!
              ========== REGISTRY ==========
              Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersi­on\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}\ not found.
              Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5C255C8A-E604-49b4-9D64-90988571CECB}\ not found.
              Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersi­on\Explorer\Browser Helper Objects\{F0D4B231-DA4B-4daf-81E4-DFEE4931A4AA}\ not found.
              Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F0D4B231-DA4B-4daf-81E4-DFEE4931A4AA}\ deleted successfully.
              Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{F0D4B239-DA4B-4daf-81E4-DFEE4931A4AA}\ not found.
              Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F0D4B239-DA4B-4daf-81E4-DFEE4931A4AA}\ deleted successfully.
              ========== FILES ==========
              C:\Documents and Settings\All Users\Application Data\sysReserve.ini moved successfully.
              ========== COMMANDS ==========

              [EMPTYTEMP]

              User: All Users

              User: clovis
              ->Temp folder emptied: 1571540 bytes
              ->Temporary Internet Files folder emptied: 60998110 bytes
              ->Java cache emptied: 48222330 bytes
              ->FireFox cache emptied: 49552645 bytes
              ->Google Chrome cache emptied: 11848357 bytes
              ->Apple Safari cache emptied: 3895860 bytes

              User: Default User
              ->Temp folder emptied: 0 bytes
              ->Temporary Internet Files folder emptied: 426118 bytes

              User: LocalService
              ->Temp folder emptied: 0 bytes
              ->Temporary Internet Files folder emptied: 33170 bytes

              User: NetworkService
              ->Temp folder emptied: 0 bytes
              ->Temporary Internet Files folder emptied: 32902 bytes

              User: Propriétaire

              %systemdrive% .tmp files removed: 0 bytes
              %systemroot% .tmp files removed: 39138 bytes
              %systemroot%\System32 .tmp files removed: 2776064 bytes
              %systemroot%\System32\dllcache .tmp files removed: 0 bytes
              %systemroot%\System32\drivers .tmp files removed: 0 bytes
              Windows Temp folder emptied: 34552 bytes
              %systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
              %systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 78991 bytes
              RecycleBin emptied: 0 bytes

              Total Files Cleaned = 171,00 mb

              OTM by OldTimer - Version 3.1.5.0 log created on 01102010_171023

              Files moved on Reboot...

              Registry entries deleted on Reboot...
          5. Contributeur sécurité
            Salut fatherted

            Supprime ce dossier C:\rsit

            Refais un scan avec RSIT et poste le rapport log.txt seulement à la fin de l’analyse

            Le rapport est dans le dossier ici C:\rsit

            @++ :)
            1. Salut dédétraqué,

              Voici le rapport RSIT:

              Logfile of random's system information tool 1.06 (written by random/random)
              Run by clovis at 2010-01-10 14:54:12
              Microsoft Windows XP Édition familiale Service Pack 3
              System drive C: has 7 GB (14%) free of 54 GB
              Total RAM: 2046 MB (55% free)

              Logfile of Trend Micro HijackThis v2.0.2
              Scan saved at 14:54:21, on 10/01/2010
              Platform: Windows XP SP3 (WinNT 5.01.2600)
              MSIE: Internet Explorer v8.00 (8.00.6001.18702)
              Boot mode: Normal

              Running processes:
              C:\WINDOWS\System32\smss.exe
              C:\WINDOWS\system32\csrss.exe
              C:\WINDOWS\system32\winlogon.exe
              C:\WINDOWS\system32\services.exe
              C:\WINDOWS\system32\lsass.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\system32\svchost.exe
              C:\Program Files\COMODO\Firewall\cmdagent.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\system32\svchost.exe
              C:\Program Files\Intel\WiFi\bin\S24EvMon.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\Explorer.EXE
              C:\WINDOWS\system32\spoolsv.exe
              C:\Program Files\Avira\AntiVir Desktop\sched.exe
              C:\WINDOWS\system32\svchost.exe
              C:\Program Files\Fichiers communs\ArcSoft\Connection Service\Bin\ACService.exe
              C:\Program Files\Avira\AntiVir Desktop\avguard.exe
              C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
              C:\Program Files\Bonjour\mDNSResponder.exe
              C:\Program Files\Home Cinema\PowerCinema\Kernel\TV\CLCapSvc.exe
              C:\Program Files\Home Cinema\PowerCinema\Kernel\CLML_NTService\CLMLServer.exe
              C:\Program Files\Intel\WiFi\bin\EvtEng.exe
              C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\System32\svchost.exe
              C:\Program Files\Java\jre6\bin\jqs.exe
              C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
              C:\WINDOWS\System32\svchost.exe
              C:\WINDOWS\system32\nvsvc32.exe
              C:\PROGRA~1\MESSAG~1\StartMessager.exe
              C:\PROGRA~1\Wanadoo\CnxMon.exe
              C:\WINDOWS\System32\svchost.exe
              C:\Program Files\Fichiers communs\ArcSoft\Connection Service\Bin\ACDaemon.exe
              C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
              C:\WINDOWS\system32\PnkBstrA.exe
              C:\WINDOWS\system32\PnkBstrB.exe
              C:\Program Files\COMODO\SafeSurf\cssurf.exe
              C:\Program Files\Fichiers communs\Intel\WirelessCommon\RegSrvc.exe
              C:\Program Files\Cyberlink\Shared files\RichVideo.exe
              C:\Program Files\COMODO\Firewall\cfp.exe
              C:\WINDOWS\system32\svchost.exe
              C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe
              C:\Program Files\Home Cinema\PowerCinema\Kernel\TV\CLSched.exe
              C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
              C:\WINDOWS\system32\rundll32.exe
              C:\Program Files\Intel\WiFi\bin\ZCfgSvc.exe
              C:\Program Files\Fichiers communs\Intel\WirelessCommon\iFrmewrk.exe
              C:\Program Files\Windows Media Player\WMPNetwk.exe
              C:\WINDOWS\RTHDCPL.EXE
              C:\WINDOWS\6000RMT.exe
              C:\WINDOWS\vspc1300.exe
              C:\Program Files\Java\jre6\bin\jusched.exe
              C:\Program Files\BboxUpdate\BTLiveUpdate.exe
              C:\Program Files\iTunes\iTunesHelper.exe
              C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
              C:\Program Files\SuperCopier2\SuperCopier2.exe
              C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
              C:\Program Files\Fichiers communs\Nero\Lib\NMBgMonitor.exe
              C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\AlertModule\2\AlertModule.exe
              C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
              C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
              C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
              C:\Program Files\Logitech\SetPoint\SetPoint.exe
              C:\Program Files\Panasonic\PHOTOfunSTUDIO -viewer-\PhAutoRun.exe
              C:\Program Files\Philips\Philips SPC1300NC Webcam\TrayMin1300.exe
              C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
              C:\Program Files\SpywareGuard\sgmain.exe
              C:\Program Files\SpywareGuard\sgbhp.exe
              C:\Program Files\Fichiers communs\Logishrd\KHAL2\KHALMNPR.EXE
              C:\WINDOWS\system32\wbem\unsecapp.exe
              C:\WINDOWS\system32\wbem\wmiprvse.exe
              C:\Program Files\OrangeHSS\systray\systrayapp.exe
              C:\WINDOWS\system32\wbem\wmiprvse.exe
              C:\WINDOWS\system32\wscntfy.exe
              C:\Program Files\Fichiers communs\Nero\Lib\NMIndexingService.exe
              C:\Program Files\Fichiers communs\Nero\Lib\NMIndexStoreSvr.exe
              C:\WINDOWS\system32\wbem\wmiapsrv.exe
              C:\Program Files\iPod\bin\iPodService.exe
              C:\WINDOWS\System32\alg.exe
              C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
              C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe
              C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe
              C:\Program Files\Mozilla Firefox\firefox.exe
              C:\WINDOWS\system32\ctfmon.exe
              C:\Documents and Settings\clovis\Bureau\RSIT.exe
              C:\WINDOWS\system32\wbem\wmiprvse.exe
              C:\Program Files\trend micro\clovis.exe

              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
              R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
              R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
              R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
              R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\Program Files\OrangeHSS\SearchURLHook\SearchPageURL.dll
              O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
              O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
              O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
              O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
              O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
              O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll
              O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
              O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
              O2 - BHO: Ask Toolbar BHO - {F0D4B231-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\AskSBar\bar\1.bin\ASKSBAR.DLL
              O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
              O3 - Toolbar: Ask Toolbar - {F0D4B239-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\AskSBar\bar\1.bin\ASKSBAR.DLL
              O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
              O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
              O4 - HKLM\..\Run: [DXM6Patch_981116] C:\WINDOWS\p_981116.exe /Q:A
              O4 - HKLM\..\Run: [MessagerStarter Wanadoo] C:\PROGRA~1\MESSAG~1\StartMessager.exe Messager Wanadoo
              O4 - HKLM\..\Run: [WooCnxMon] C:\PROGRA~1\Wanadoo\CnxMon.exe
              O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
              O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\Wanadoo\TaskbarIcon.exe
              O4 - HKLM\..\Run: [ArcSoft Connection Service] C:\Program Files\Fichiers communs\ArcSoft\Connection Service\Bin\ACDaemon.exe
              O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
              O4 - HKLM\..\Run: [hpqSRMon] C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe
              O4 - HKLM\..\Run: [COMODO SafeSurf] "C:\Program Files\COMODO\SafeSurf\cssurf.exe" -s
              O4 - HKLM\..\Run: [COMODO Firewall Pro] "C:\Program Files\COMODO\Firewall\cfp.exe" -h
              O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
              O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
              O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
              O4 - HKLM\..\Run: [COMODO Internet Security] "C:\Program Files\COMODO\Firewall\cfp.exe" -h
              O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
              O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\WiFi\bin\ZCfgSvc.exe"
              O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Fichiers communs\Intel\WirelessCommon\iFrmewrk.exe" /tf Intel Wireless Tray
              O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
              O4 - HKLM\..\Run: [TV Card Remote Control Device Monitor] C:\WINDOWS\6000RMT.exe
              O4 - HKLM\..\Run: [SPC1300] C:\WINDOWS\vspc1300.exe
              O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
              O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
              O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
              O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
              O4 - HKLM\..\Run: [ORAHSSSessionManager] "C:\Program Files\OrangeHSS\SessionManager\SessionManager.exe"
              O4 - HKLM\..\Run: [BboxUpdate] C:\Program Files\BboxUpdate\BTLiveUpdate.exe
              O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
              O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
              O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
              O4 - HKCU\..\Run: [SuperCopier2.exe] C:\Program Files\SuperCopier2\SuperCopier2.exe
              O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
              O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Nero\Lib\NMBgMonitor.exe"
              O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
              O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
              O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
              O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
              O4 - Startup: OneNote 2007 - Capture d'écran et lancement.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
              O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
              O4 - Global Startup: DSLMON.lnk = C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
              O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
              O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
              O4 - Global Startup: PHOTOfunSTUDIO -viewer-.lnk = C:\Program Files\Panasonic\PHOTOfunSTUDIO -viewer-\PhAutoRun.exe
              O4 - Global Startup: SetPointII.lnk = ?
              O4 - Global Startup: TrayMin1300.lnk = ?
              O8 - Extra context menu item: &Recherche AOL Toolbar - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
              O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000
              O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
              O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll
              O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll
              O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\Office12\REFIEBAR.DLL
              O9 - Extra button: Organise-notes - {9455301C-CF6B-11D3-A266-00C04F689C50} - C:\Program Files\Fichiers communs\Microsoft Shared\Encarta Researcher\EROPROJ.DLL
              O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
              O9 - Extra button: Sélection intelligente HP - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
              O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
              O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
              O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
              O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
              O9 - Extra button: Wanadoo - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - https://www.orange.fr/portail (file missing) (HKCU)
              O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
              O16 - DPF: {E77F23EB-E7AB-4502-8F37-247DBAF1A147} (Windows Live Hotmail Photo Upload Tool) - http://gfx1.hotmail.com/mail/w4/pr01/photouploadcontrol/MSNPUpld.cab
              O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
              O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft - C:\Program Files\Fichiers communs\ArcSoft\Connection Service\Bin\ACService.exe
              O23 - Service: Avira AntiVir Planificateur (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
              O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
              O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
              O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
              O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - C:\Program Files\Home Cinema\PowerCinema\Kernel\TV\CLCapSvc.exe
              O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - C:\Program Files\Home Cinema\PowerCinema\Kernel\TV\CLSched.exe
              O23 - Service: COMODO Internet Security Helper Service (cmdAgent) - Unknown owner - C:\Program Files\COMODO\Firewall\cmdagent.exe
              O23 - Service: CyberLink Media Library Service - Cyberlink - C:\Program Files\Home Cinema\PowerCinema\Kernel\CLML_NTService\CLMLServer.exe
              O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel(R) Corporation - C:\Program Files\Intel\WiFi\bin\EvtEng.exe
              O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom SA - C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
              O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
              O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
              O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
              O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
              O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Fichiers communs\Logitech\Bluetooth\LBTServ.exe
              O23 - Service: Ma-Config Service (maconfservice) - CybelSoft - C:\Program Files\ma-config.com\maconfservice.exe
              O23 - Service: MSSQL$PINNACLESYS - Unknown owner - C:\Program Files\Pinnacle\MediaServer\Microsoft SQL Server\MSSQL$PINNACLESYS\Binn\sqlservr.exe (file missing)
              O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
              O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Fichiers communs\Nero\Lib\NMIndexingService.exe
              O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
              O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
              O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe
              O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel(R) Corporation - C:\Program Files\Fichiers communs\Intel\WirelessCommon\RegSrvc.exe
              O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\Cyberlink\Shared files\RichVideo.exe
              O23 - Service: Intel® PROSet/Wireless WiFi Service (S24EventMonitor) - Intel(R) Corporation - C:\Program Files\Intel\WiFi\bin\S24EvMon.exe
              O23 - Service: X10 Device Network Service (x10nets) - X10 - C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe
          6. Contributeur sécurité
            Salut fatherted

            Mettre MalwareByte's Anti-Malware à jour

            ---

            - Redémarre en mode sans échec :

            Au redémarrage de ton PC tapote sur la touche F8 ou F5, sur l'écran suivant déplace toi avec les flèches de direction et choisis Mode sans échec. Choisis ta session habituelle et non la session Administrateur

            ---

            - Double clique sur le raccourci de MalwareByte's Anti-Malware qui est sur le bureau.
            - Sélectionne Exécuter un examen complet si ce n'est pas déjà fait
            - clique sur Rechercher

            - Une fois le scan terminé, une fenêtre s'ouvre, clique sur sur OK

            - Si MalwareByte's n'a rien détecté, clique sur OK Un rapport va apparaître ferme-le.

            - Si MalwareByte's a détecté des infections, clique sur Afficher les résultats ensuite sur Supprimer la sélection

            - Enregistre le rapport sur ton Bureau comme cela il sera plus facile à retrouver, poste ensuite ce rapport.

            Note : Si MalwareByte's a besoin de redémarrer pour terminer la suppression, accepte en cliquant sur OK

            Tutoriel pour MalwareByte's ici :
            https://www.malekal.com/tutoriel-malwarebyte-anti-malware/

            @++ :)
            1. Salut dédétraqué,

              Alors voici le rapport:

              Malwarebytes' Anti-Malware 1.44
              Version de la base de données: 3510
              Windows 5.1.2600 Service Pack 3 (Safe Mode)
              Internet Explorer 8.0.6001.18702

              10/01/2010 03:09:26
              mbam-log-2010-01-10 (03-09-26).txt

              Type de recherche: Examen complet (C:\|D:\|E:\|)
              Eléments examinés: 257837
              Temps écoulé: 2 hour(s), 57 minute(s), 25 second(s)

              Processus mémoire infecté(s): 0
              Module(s) mémoire infecté(s): 0
              Clé(s) du Registre infectée(s): 17
              Valeur(s) du Registre infectée(s): 1
              Elément(s) de données du Registre infecté(s): 1
              Dossier(s) infecté(s): 0
              Fichier(s) infecté(s): 13

              Processus mémoire infecté(s):
              (Aucun élément nuisible détecté)

              Module(s) mémoire infecté(s):
              (Aucun élément nuisible détecté)

              Clé(s) du Registre infectée(s):
              HKEY_CLASSES_ROOT\Interface\{2e9937fc-cf2f-4f56-af54-5a6a3dd375cc} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
              HKEY_CLASSES_ROOT\Interface\{741de825-a6f0-4497-9aa6-8023cf9b0fff} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
              HKEY_CLASSES_ROOT\Interface\{cf54be1c-9359-4395-8533-1657cf209cfe} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
              HKEY_CLASSES_ROOT\Typelib\{d518921a-4a03-425e-9873-b9a71756821e} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
              HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{56256a51-b582-467e-b8d4-7786eda79ae0} (Trojan.Vundo) -> Quarantined and deleted successfully.
              HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{59c7fc09-1c83-4648-b3e6-003d2bbc7481} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
              HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68af847f-6e91-45dd-9b68-d6a12c30e5d7} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
              HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9170b96c-28d4-4626-8358-27e6caeef907} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
              HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{d1a71fa0-ff48-48dd-9b6d-7a13a3e42127} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
              HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{ddb1968e-ead6-40fd-8dae-ff14757f60c7} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
              HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{f138d901-86f0-4383-99b6-9cdd406036da} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
              HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{56256a51-b582-467e-b8d4-7786eda79ae0} (Trojan.Vundo) -> Quarantined and deleted successfully.
              HKEY_CLASSES_ROOT\bkqxdons.borb (Trojan.FakeAlert) -> Quarantined and deleted successfully.
              HKEY_CLASSES_ROOT\bkqxdons.toolbar.1 (Trojan.FakeAlert) -> Quarantined and deleted successfully.
              HKEY_LOCAL_MACHINE\SOFTWARE\EoRezo (Rogue.Eorezo) -> Quarantined and deleted successfully.
              HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\RunDll32Policy\f3ScrCtr.dll (Adware.MyWebSearch) -> Quarantined and deleted successfully.
              HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Schemes\f3pss (Adware.MyWebSearch) -> Quarantined and deleted successfully.

              Valeur(s) du Registre infectée(s):
              HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\MenuExt\&Search\(default) (Adware.Hotbar) -> Quarantined and deleted successfully.

              Elément(s) de données du Registre infecté(s):
              HKEY_CURRENT_USER\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

              Dossier(s) infecté(s):
              (Aucun élément nuisible détecté)

              Fichier(s) infecté(s):
              C:\Program Files\Windows Live\Messenger\riched20.dll (Adware.MyWebSearch) -> Quarantined and deleted successfully.
              C:\Qoobox\Quarantine\C\WINDOWS\system32\H8SRTbvrdupqpfw.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
              C:\Qoobox\Quarantine\C\WINDOWS\system32\H8SRTltknebqaoo.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
              C:\Qoobox\Quarantine\C\WINDOWS\system32\H8SRTownoxtexob.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
              C:\Qoobox\Quarantine\C\WINDOWS\system32\H8SRTqnnnfxtdaq.dll.vir (Trojan.FakeAlert) -> Quarantined and deleted successfully.
              C:\Qoobox\Quarantine\C\WINDOWS\system32\drivers\H8SRTqsoirmemvh.sys.vir (Malware.Packer) -> Quarantined and deleted successfully.
              C:\System Volume Information\_restore{E9E085E7-2D04-46BF-BF24-710AADD73283}\RP828\A0133012.sys (Malware.Packer) -> Quarantined and deleted successfully.
              C:\System Volume Information\_restore{E9E085E7-2D04-46BF-BF24-710AADD73283}\RP828\A0133013.dll (Trojan.FakeAlert) -> Quarantined and deleted successfully.
              C:\System Volume Information\_restore{E9E085E7-2D04-46BF-BF24-710AADD73283}\RP828\A0133014.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
              C:\System Volume Information\_restore{E9E085E7-2D04-46BF-BF24-710AADD73283}\RP828\A0133015.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
              C:\System Volume Information\_restore{E9E085E7-2D04-46BF-BF24-710AADD73283}\RP828\A0133064.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
              C:\System Volume Information\_restore{E9E085E7-2D04-46BF-BF24-710AADD73283}\RP828\A0133116.sys (Malware.Trace) -> Quarantined and deleted successfully.
              C:\WINDOWS\system32\krl32mainweq.dll (Trojan.DNSChanger) -> Quarantined and deleted successfully.

              Bonne soirée, à bientôt!
          7. Salut dédétraqué,

            J'ai fait ce que tu m'as demandé. Voici le rapport de mbr:

            Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

            device: opened successfully
            user: MBR read successfully
            kernel: MBR read successfully
            user & kernel MBR OK
            1. Merci mais entre temps j'ai fait la même manip que tu m'as demandé avec l'autre lien combofix que tu m'avais donné précédemment.
              Voici le rapport:
              ComboFix 10-01-04.01 - clovis 08/01/2010 6:16.3.2 - x86
              Microsoft Windows XP Édition familiale 5.1.2600.3.1252.33.1036.18.2046.1509 [GMT 1:00]
              Lancé depuis: c:\documents and settings\clovis\Bureau\bibite.exe
              AV: AntiVir Desktop *On-access scanning disabled* (Outdated) {AD166499-45F9-482A-A743-FDD3350758C7}
              FW: COMODO Firewall *disabled* {043803A3-4F86-4ef6-AFC5-F6E02A79969B}

              AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!
              .

              (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
              .

              c:\documents and settings\clovis\Application Data\agusizopi.bat
              c:\documents and settings\clovis\Local Settings\Application Data\imafucojir.reg
              c:\documents and settings\clovis\Local Settings\Application Data\olote.inf
              c:\program files\Fichiers communs\irihe.inf
              c:\program files\Malware Defense
              c:\program files\Malware Defense\md.db
              c:\windows\system32\404Fix.exe
              c:\windows\system32\drivers\H8SRTqsoirmemvh.sys
              c:\windows\system32\dumphive.exe
              c:\windows\system32\H8SRTbvrdupqpfw.dll
              c:\windows\system32\H8SRTduaxdtlfyi.dat
              c:\windows\system32\H8SRTltknebqaoo.dll
              c:\windows\system32\H8SRTownoxtexob.dll
              c:\windows\system32\H8SRTqnnnfxtdaq.dll
              c:\windows\system32\IEDFix.C.exe
              c:\windows\system32\IEDFix.exe
              c:\windows\system32\nyxegimo.inf
              c:\windows\system32\o4Patch.exe
              c:\windows\system32\Process.exe
              c:\windows\system32\rnaph.dll
              c:\windows\system32\SrchSTS.exe
              c:\windows\system32\srcr.dat
              c:\windows\system32\tmp.reg
              c:\windows\system32\VACFix.exe
              c:\windows\system32\VCCLSID.exe
              c:\windows\system32\WS2Fix.exe

              .
              ((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
              .

              -------\Service_H8SRTd.sys
              -------\Legacy_H8SRTd.sys

              ((((((((((((((((((((((((((((( Fichiers créés du 2009-12-08 au 2010-01-08 ))))))))))))))))))))))))))))))))))))
              .

              2009-12-28 20:29 . 2009-12-28 20:29 -------- d-----w- c:\documents and settings\All Users\Application Data\G DATA
              2009-12-28 17:50 . 2009-12-28 17:51 -------- d-----w- c:\program files\trend micro
              2009-12-28 17:50 . 2009-12-28 17:51 -------- d-----w- C:\rsit
              2009-12-26 02:17 . 2009-12-26 02:17 -------- d-sh--w- c:\windows\system32\config\systemprofile\IETldCache
              2009-12-26 01:26 . 2009-03-30 09:32 96104 ----a-w- c:\windows\system32\drivers\avipbb.sys
              2009-12-26 01:26 . 2009-02-13 11:28 22360 ----a-w- c:\windows\system32\drivers\avgntmgr.sys
              2009-12-26 01:26 . 2009-02-13 11:17 45416 ----a-w- c:\windows\system32\drivers\avgntdd.sys
              2009-12-26 01:26 . 2009-12-26 01:26 -------- d-----w- c:\program files\Avira
              2009-12-26 01:26 . 2009-12-26 01:26 -------- d-----w- c:\documents and settings\All Users\Application Data\Avira
              2009-12-25 04:49 . 2010-01-08 04:35 854 ----a-w- c:\windows\system32\krl32mainweq.dll

              .
              (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
              .
              2010-01-08 05:28 . 2009-02-11 20:46 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
              2009-12-28 15:43 . 2009-02-11 20:46 -------- d-----w- c:\program files\Spybot - Search & Destroy
              2009-12-28 02:17 . 2006-01-31 18:15 94036 ----a-w- c:\windows\system32\perfc00C.dat
              2009-12-28 02:17 . 2006-01-31 18:15 531394 ----a-w- c:\windows\system32\perfh00C.dat
              2009-12-23 22:52 . 2009-11-23 14:17 -------- d-----w- c:\program files\iTunes
              2009-12-09 18:05 . 2007-09-29 11:13 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
              2009-11-24 00:58 . 2008-10-03 13:52 -------- d-----w- c:\documents and settings\clovis\Application Data\BitTorrent
              2009-11-23 14:17 . 2009-11-23 14:17 -------- d-----w- c:\program files\iPod
              2009-11-23 14:17 . 2007-07-22 21:22 -------- d-----w- c:\program files\Fichiers communs\Apple
              2009-11-23 14:12 . 2009-11-23 14:11 -------- d-----w- c:\program files\QuickTime
              2009-11-23 14:02 . 2008-11-27 00:16 -------- d-----w- c:\program files\Safari
              2009-11-20 18:25 . 2009-11-20 18:25 -------- d-----w- c:\program files\BboxUpdate
              2009-11-20 18:25 . 2009-11-20 18:25 -------- d-----w- c:\program files\Bbox
              2009-11-20 17:30 . 2009-11-20 17:30 -------- d-----w- c:\program files\Techcity
              2009-10-29 07:42 . 2006-01-31 18:15 916480 ----a-w- c:\windows\system32\wininet.dll
              2009-10-23 13:00 . 2006-08-16 18:20 66992 -c--a-w- c:\documents and settings\clovis\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
              2009-10-21 05:39 . 2006-01-31 18:15 75776 ----a-w- c:\windows\system32\strmfilt.dll
              2009-10-21 05:39 . 2006-01-31 18:15 25088 ----a-w- c:\windows\system32\httpapi.dll
              2009-10-20 16:20 . 2004-08-03 23:00 265728 ----a-w- c:\windows\system32\drivers\http.sys
              2009-10-13 10:33 . 2006-01-31 18:15 271360 ----a-w- c:\windows\system32\oakley.dll
              2009-10-12 13:39 . 2006-01-31 18:15 79872 ----a-w- c:\windows\system32\raschap.dll
              2009-10-12 13:39 . 2006-01-31 18:15 150528 ----a-w- c:\windows\system32\rastls.dll
              2008-10-26 23:08 . 2008-10-26 23:08 18175 -c--a-w- c:\program files\Fichiers communs\ceba.exe
              2008-10-26 23:08 . 2008-10-26 23:08 17514 -c--a-w- c:\program files\Fichiers communs\wemy.scr
              2006-01-31 15:39 . 2006-01-31 15:39 8 -csh--r- c:\windows\system32\6C9E850446.sys
              2006-09-03 13:37 . 2006-09-03 13:37 56 -csh--r- c:\windows\system32\BA58F317A6.sys
              .

              ((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
              .
              .
              *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
              REGEDIT4

              [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
              "SuperCopier2.exe"="c:\program files\SuperCopier2\SuperCopier2.exe" [2006-07-07 1052672]
              "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-08-08 68856]
              "BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Fichiers communs\Nero\Lib\NMBgMonitor.exe" [2007-08-21 202024]
              "WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2006-11-03 204288]
              "SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-01-26 2144088]

              [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
              "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-01-30 13594624]
              "DXM6Patch_981116"="c:\windows\p_981116.exe" [1998-11-30 497376]
              "MessagerStarter Wanadoo"="c:\progra~1\MESSAG~1\StartMessager.exe" [2003-04-11 32768]
              "WooCnxMon"="c:\progra~1\Wanadoo\CnxMon.exe" [2003-10-16 24576]
              "WOOWATCH"="c:\progra~1\Wanadoo\Watch.exe" [2003-10-16 20480]
              "WOOTASKBARICON"="c:\progra~1\Wanadoo\TaskbarIcon.exe" [2003-10-16 53248]
              "ArcSoft Connection Service"="c:\program files\Fichiers communs\ArcSoft\Connection Service\Bin\ACDaemon.exe" [2007-10-11 31232]
              "HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-10-14 49152]
              "hpqSRMon"="c:\program files\HP\Digital Imaging\bin\hpqSRMon.exe" [2007-08-22 80896]
              "COMODO SafeSurf"="c:\program files\COMODO\SafeSurf\cssurf.exe" [2008-10-29 278264]
              "COMODO Firewall Pro"="c:\program files\COMODO\Firewall\cfp.exe" [2009-06-17 1794320]
              "nwiz"="nwiz.exe" [2009-01-30 1657376]
              "SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2007-12-06 1024000]
              "AppleSyncNotifier"="c:\program files\Fichiers communs\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2009-08-13 177440]
              "COMODO Internet Security"="c:\program files\COMODO\Firewall\cfp.exe" [2009-06-17 1794320]
              "NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-01-30 86016]
              "IntelZeroConfig"="c:\program files\Intel\WiFi\bin\ZCfgSvc.exe" [2008-10-16 1368064]
              "IntelWireless"="c:\program files\Fichiers communs\Intel\WirelessCommon\iFrmewrk.exe" [2008-10-16 1191936]
              "RTHDCPL"="RTHDCPL.EXE" [2008-12-30 18082304]
              "TV Card Remote Control Device Monitor"="c:\windows\6000RMT.exe" [2007-06-01 466944]
              "SPC1300"="c:\windows\vspc1300.exe" [2007-05-31 675840]
              "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
              "Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" [2009-06-17 55824]
              "Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2009-06-17 55824]
              "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-07-25 149280]
              "ORAHSSSessionManager"="c:\program files\OrangeHSS\SessionManager\SessionManager.exe" [2008-06-10 107248]
              "BboxUpdate"="c:\program files\BboxUpdate\BTLiveUpdate.exe" [2008-08-06 103936]
              "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-11-10 417792]
              "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-11-12 141600]
              "avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]

              [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
              "CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

              c:\documents and settings\clovis\Menu D‚marrer\Programmes\D‚marrage\
              OneNote 2007 - Capture d'‚cran et lancement.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2008-10-25 98696]
              SpywareGuard.lnk - c:\program files\SpywareGuard\sgmain.exe [2003-8-29 360448]

              c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
              DSLMON.lnk - c:\program files\SAGEM\SAGEM F@st 800-840\dslmon.exe [2006-8-29 954475]
              HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2007-10-14 214360]
              Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2008-5-5 813584]
              PHOTOfunSTUDIO -viewer-.lnk - c:\program files\Panasonic\PHOTOfunSTUDIO -viewer-\PhAutoRun.exe [2009-2-27 40960]
              SetPointII.lnk - c:\program files\Logitech\SetPoint II\SetpointII.exe [2008-11-13 323584]
              TrayMin1300.lnk - c:\program files\Philips\Philips SPC1300NC Webcam\TrayMin1300.exe [2009-2-27 245760]

              [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
              2009-07-20 10:28 72208 ----a-w- c:\program files\Fichiers communs\Logitech\Bluetooth\LBTWLgn.dll

              [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
              @=""

              [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
              "EnableFirewall"= 0 (0x0)

              [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
              "c:\\WINDOWS\\system32\\sessmgr.exe"=
              "c:\\Program Files\\Messenger\\msmsgs.exe"=
              "c:\\WINDOWS\\system32\\fxsclnt.exe"=
              "c:\\Program Files\\NetMeeting\\Conf.exe"=
              "c:\\Program Files\\EA GAMES\\Battlefield 2\\BF2.exe"=
              "c:\\WINDOWS\\system32\\usmt\\migwiz.exe"=
              "c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
              "c:\\Program Files\\BitTorrent\\BitTorrent.exe"= c:\\Program Files\\BitTorrent\\bittorrent.exe
              "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
              "%windir%\\system32\\sessmgr.exe"=
              "c:\\Program Files\\SPSSInc\\SPSS16\\spss.com"=
              "c:\\Program Files\\SPSSInc\\SPSS16\\spss.exe"=
              "c:\\Program Files\\SPSSInc\\SPSS16\\SPSSWinWrapIDE.exe"=
              "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
              "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
              "c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
              "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpiscnapp.exe"=
              "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
              "c:\\Program Files\\Ubisoft\\Far Cry 2\\bin\\FarCry2.exe"=
              "c:\\Program Files\\Ubisoft\\Far Cry 2\\bin\\FC2Launcher.exe"=
              "c:\\Program Files\\Ubisoft\\Far Cry 2\\bin\\FC2Editor.exe"=
              "c:\\WINDOWS\\system32\\PnkBstrA.exe"=
              "c:\\WINDOWS\\system32\\PnkBstrB.exe"=
              "c:\\Program Files\\Malwarebytes' Anti-Malware\\mbam.exe"=
              "c:\\Program Files\\LimeWire\\LimeWire.exe"=
              "c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
              "c:\\Documents and Settings\\clovis\\Bureau\\freezer.exe"=
              "c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
              "c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
              "c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
              "c:\\Program Files\\OrangeHSS\\Connectivity\\ConnectivityManager.exe"=
              "c:\\Program Files\\Nero\\Nero8\\Nero ShowTime\\ShowTime.exe"=
              "c:\\Program Files\\Bbox\\eSKernel.exe"=
              "c:\\Program Files\\BboxUpdate\\BTLiveUpdate.exe"=
              "c:\\Program Files\\iTunes\\iTunes.exe"=

              [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
              "1723:TCP"= 1723:TCP:@xpsp2res.dll,-22015
              "1701:UDP"= 1701:UDP:@xpsp2res.dll,-22016
              "500:UDP"= 500:UDP:@xpsp2res.dll,-22017

              R0 d347bus;d347bus;c:\windows\system32\drivers\d347bus.sys [23/05/2007 19:56 155136]
              R0 d347prt;d347prt;c:\windows\system32\drivers\d347prt.sys [23/05/2007 19:56 5248]
              R1 cmdGuard;COMODO Firewall Pro Sandbox Driver;c:\windows\system32\drivers\cmdguard.sys [29/10/2008 19:35 132640]
              R1 cmdHlp;COMODO Firewall Pro Helper Driver;c:\windows\system32\drivers\cmdhlp.sys [29/10/2008 19:35 24096]
              R2 AntiVirSchedulerService;Avira AntiVir Planificateur;c:\program files\Avira\AntiVir Desktop\sched.exe [26/12/2009 02:26 108289]
              R2 LBeepKE;LBeepKE;c:\windows\system32\drivers\LBeepKE.sys [24/02/2009 14:50 10384]
              R3 phaudlwr;Philips Audio Filter;c:\windows\system32\drivers\phaudlwr.sys [27/02/2009 13:43 88320]
              R3 SPC1300;USB2.0 PC Camera (SPC1300);c:\windows\system32\drivers\spc1300.sys [27/02/2009 13:43 3033856]
              S3 3xHybrid;3xHybrid service;c:\windows\system32\drivers\3xHybrid.sys [15/03/2006 09:42 845568]
              S3 hpoid407;IEEE-1284.4 Driver hpoid407;c:\windows\system32\drivers\hpoid407.sys [20/04/2009 23:01 50480]
              S3 hpoius07;USB to IEEE-1284.4 Translation Driver hpoius07;c:\windows\system32\drivers\hpoius07.sys [20/04/2009 23:00 18640]
              S3 maconfservice;Ma-Config Service;c:\program files\ma-config.com\maconfservice.exe [24/01/2009 14:46 216232]
              S4 sptd;sptd;c:\windows\system32\Drivers\sptd.sys --> c:\windows\system32\Drivers\sptd.sys [?]

              [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
              HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
              hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
              .
              Contenu du dossier 'Tâches planifiées'

              2009-12-21 c:\windows\Tasks\AppleSoftwareUpdate.job
              - c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 10:34]
              .
              .
              ------- Examen supplémentaire -------
              .
              uStart Page = hxxp://www.google.com/
              uInternet Settings,ProxyOverride = localhost
              IE: &Recherche AOL Toolbar - c:\program files\AOL Toolbar\toolbar.dll/SEARCH.HTML
              IE: &Search - http://edits.mywebsearch.com/toolbaredits/menusearch.jhtml?p=ZJfox000
              IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~4\Office12\EXCEL.EXE/3000
              IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
              FF - ProfilePath - c:\documents and settings\clovis\Application Data\Mozilla\Firefox\Profiles\zstk5v41.default\
              FF - plugin: c:\documents and settings\clovis\Application Data\Mozilla\Firefox\Profiles\zstk5v41.default\extensions\{bb628310-0ab7-11db-9cd8-0800200c9a66}\plugins\nphardwaredetection.dll
              FF - plugin: c:\program files\ma-config.com\nphardwaredetection.dll
              FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
              FF - plugin: c:\program files\Mozilla Firefox\plugins\npbittorrent.dll
              FF - plugin: c:\program files\Mozilla Firefox\plugins\npqtplugin8.dll
              FF - plugin: c:\program files\QuickTime\Plugins\npqtplugin8.dll
              FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
              FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
              FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

              ---- PARAMETRES FIREFOX ----
              FF - user.js: network.proxy.type - 0
              FF - user.js: browser.shell.checkDefaultBrowser - false
              FF - user.js: yahoo.homepage.dontask - true.
              - - - - ORPHELINS SUPPRIMES - - - -

              HKCU-Run-Malware Defense - c:\program files\Malware Defense\mdefense.exe
              AddRemove-UsbFix - c:\program files\UsbFix\Uninstal.exe

              **************************************************************************

              catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
              Rootkit scan 2010-01-08 06:30
              Windows 5.1.2600 Service Pack 3 NTFS

              detected NTDLL code modification:
              ZwClose, ZwOpenFile

              Recherche de processus cachés ...

              Recherche d'éléments en démarrage automatique cachés ...

              Recherche de fichiers cachés ...

              Scan terminé avec succès
              Fichiers cachés: 0

              **************************************************************************

              Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

              device: opened successfully
              user: MBR read successfully
              called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll >>UNKNOWN [0x8A744348]<<
              kernel: MBR read successfully
              detected MBR rootkit hooks:
              \Driver\Disk -> CLASSPNP.SYS @ 0xb810cf28
              \Driver\ACPI -> ACPI.sys @ 0xb7f58cb8
              \Driver\atapi -> 0x8a744348
              IoDeviceObjectType -> DeleteProcedure -> ntkrnlpa.exe @ 0x805836a8
              \Device\Harddisk0\DR0 -> DeleteProcedure -> ntkrnlpa.exe @ 0x805836a8
              Warning: possible MBR rootkit infection !
              user & kernel MBR OK

              **************************************************************************
              .
              --------------------- CLES DE REGISTRE BLOQUEES ---------------------

              [HKEY_USERS\S-1-5-21-3889398425-3364761815-2410325488-1006\Software\SecuROM\License information*]
              "datasecu"=hex:c6,4f,70,67,82,7f,56,3d,9d,7b,3e,fd,08,2d,53,1f,b0,ba,d5,ac,3e,
              54,25,00,00,aa,11,3e,2f,5e,19,98,b4,e1,77,a8,ce,91,ea,ec,d2,53,bc,d7,2c,8b,\
              "rkeysecu"=hex:29,23,be,84,e1,6c,d6,ae,52,90,49,f1,f1,bb,e9,eb
              .
              --------------------- DLLs chargées dans les processus actifs ---------------------

              - - - - - - - > 'winlogon.exe'(972)
              c:\program files\fichiers communs\logitech\bluetooth\LBTWlgn.dll
              c:\program files\fichiers communs\logitech\bluetooth\LBTServ.dll
              c:\windows\system32\netprovcredman.dll

              - - - - - - - > 'lsass.exe'(1028)
              c:\windows\system32\guard32.dll

              - - - - - - - > 'explorer.exe'(5692)
              c:\windows\system32\guard32.dll
              c:\windows\system32\nview.dll
              c:\program files\Logitech\SetPoint\lgscroll.dll
              c:\progra~1\WINDOW~2\wmpband.dll
              c:\program files\iTunes\iTunesMiniPlayer.dll
              c:\program files\iTunes\iTunesMiniPlayer.Resources\fr.lproj\iTunesMiniPlayerLocalized.dll
              c:\program files\iTunes\iTunesMiniPlayer.Resources\iTunesMiniPlayer.dll
              c:\windows\system32\netprovcredman.dll
              c:\program files\Fichiers communs\Nero\Lib\NeroDigitalExt.dll
              c:\program files\Fichiers communs\Adobe\Acrobat\ActiveX\PDFShell.dll
              c:\program files\Fichiers communs\Adobe\Acrobat\ActiveX\PDFShell.FRA
              c:\program files\Illustrate\dBpoweramp\dBShell.dll
              c:\windows\system32\webcheck.dll
              c:\windows\system32\WPDShServiceObj.dll
              c:\windows\system32\PortableDeviceTypes.dll
              c:\windows\system32\PortableDeviceApi.dll
              c:\windows\system32\eappprxy.dll
              .
              ------------------------ Autres processus actifs ------------------------
              .
              c:\program files\COMODO\Firewall\cmdagent.exe
              c:\program files\Intel\WiFi\bin\S24EvMon.exe
              c:\program files\Fichiers communs\ArcSoft\Connection Service\Bin\ACService.exe
              c:\program files\Avira\AntiVir Desktop\avguard.exe
              c:\program files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
              c:\program files\Bonjour\mDNSResponder.exe
              c:\program files\Home Cinema\PowerCinema\Kernel\TV\CLCapSvc.exe
              c:\program files\Home Cinema\PowerCinema\Kernel\CLML_NTService\CLMLServer.exe
              c:\program files\Intel\WiFi\bin\EvtEng.exe
              c:\progra~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
              c:\program files\Java\jre6\bin\jqs.exe
              c:\program files\Nero\Nero8\Nero BackItUp\NBService.exe
              c:\windows\system32\nvsvc32.exe
              c:\windows\system32\PnkBstrA.exe
              c:\windows\system32\PnkBstrB.exe
              c:\program files\Fichiers communs\Intel\WirelessCommon\RegSrvc.exe
              c:\program files\Cyberlink\Shared files\RichVideo.exe
              c:\progra~1\COMMON~1\X10\Common\x10nets.exe
              c:\program files\Home Cinema\PowerCinema\Kernel\TV\CLSched.exe
              c:\program files\Windows Media Player\WMPNetwk.exe
              c:\windows\system32\rundll32.exe
              c:\windows\system32\RUNDLL32.EXE
              c:\windows\RTHDCPL.EXE
              c:\windows\system32\wbem\unsecapp.exe
              c:\program files\Fichiers communs\Logishrd\KHAL2\KHALMNPR.EXE
              c:\progra~1\FICHIE~1\France Telecom\Shared Modules\AlertModule\2\AlertModule.exe
              c:\program files\SpywareGuard\sgbhp.exe
              c:\windows\system32\wbem\wmiapsrv.exe
              c:\windows\system32\wscntfy.exe
              c:\program files\Fichiers communs\Nero\Lib\NMIndexingService.exe
              c:\program files\iPod\bin\iPodService.exe
              c:\program files\Fichiers communs\Nero\Lib\NMIndexStoreSvr.exe
              c:\program files\OrangeHSS\systray\systrayapp.exe
              c:\program files\HP\Digital Imaging\bin\hpqSTE08.exe
              c:\program files\HP\Digital Imaging\bin\hpqbam08.exe
              c:\program files\HP\Digital Imaging\bin\hpqgpc01.exe
              .
              **************************************************************************
              .
              Heure de fin: 2010-01-08 06:41:10 - La machine a redémarré
              ComboFix-quarantined-files.txt 2010-01-08 05:41

              Avant-CF: 7 564 599 296 octets libres
              Après-CF: 7 872 200 704 octets libres

              - - End Of File - - A318443EF68AF182388789FBED230CDE
              1. Contributeur sécurité
                Salut fatherted

                Télécharge load_tdsskiller de Loup Blanc sur ton Bureau :
                http://fradesch.perso.cegetel.net/transf/Load_tdsskiller.exe

                Cet outil est conçu pour automatiser différentes tâches proposées par TDSSKiller, un fix de Kaspersky.

                - Lance load_tdsskiller en double-cliquant dessus : l'outil va se connecter au Net pour télécharger une copie à jour de TDSSKiller, puis va lancer le scan

                - A la fin du scan, appuie sur une touche pour continuer, comme l'indique le message dans la fenêtre noire d'invite de commande
                - Le rapport s'affichera automatiquement : copie-colle son contenu dans ta prochaine réponse (le fichier est également présent ici : C:\tdsskiller\report.txt)
                - Fais redémarrer ton PC

                @++ :)
                1. Rebonsoir dédétraqué,

                  J'ai essayé de l'enregistrer mais en vain, une fenêtre s'affiche me disant qu'une erreur est survenue ou que le site est corrompu que ce soit sur internet explorer ou bien firefox.
                  Quelle autre solution peux-tu me proposer?
                  Merci.
                  1. Contributeur sécurité
                    Salut fatherted

                    Supprime la version de Combofix que tu as télécharger

                    Faire un clic droit sur ce lien :

                    http://www.geekstogo.com/forum/files/file/197-combofix-by-subs/

                    Pour Internet Explorer

                    - Choisi Enregistrer la cible sous ...

                    Pour Firefox

                    - Choisi Enregistrer la cible du lien sous...

                    - Choisi le bureau comme lieu d'enregistrement

                    - Donne lui ce nom bibite.exe clique sur Enregistrer

                    -----

                    Redémarre en mode sans échec :

                    Au redémarrage de ton PC tapote sur la touche F8 ou F5, sur l'écran suivant déplace toi avec les flèches de direction et choisis Mode sans échec. Choisis ta session habituelle et non la session Administrateur

                    -----

                    Double clique sur bibite.exe, clique sur OUI et valide par Entrée

                    Lorsque le scan sera complété, un rapport apparaîtra. Copie/colle ce rapport dans ta prochaine réponse.

                    NOTE : Le rapport se trouve également ici : C:\Combofix.txt

                    Combofix est détecté par certains antivirus comme une infection, ne pas en tenir compte, il s'agit d'un faux positif, continue la procédure

                    @++ :)
                    1. Bonjour dédétraqué,

                      Désolé de ne pas t'avoir répondu plus tôt j'étais en période d'examens.
                      J'ai téléchargé Combofix mais il m'est impossible de le lancer et c'est le cas pour tous mes logiciels que ce soit avira antivir ou autre!
                      Comment puis-je les ouvrir afin d'éliminer ce virus?

                      En espérant que cela fonctionne, je te joins les 2 rapports du début:

                      info.txt logfile of random's system information tool 1.06 2009-12-28 18:51:32

                      ======Uninstall list======

                      -->C:\Program Files\InstallShield Installation Information\{C7C368E6-0B79-45A9-A9A4-5D57639EDAA2}\setup.exe -runfromtemp -l0x040c
                      -->C:\Program Files\Nero\Nero8\\nero\uninstall\UNNERO.exe /UNINSTALL
                      -->C:\WINDOWS\IsUn040c.exe -fC:\WINDOWS\orun32.isu
                      -->C:\WINDOWS\UNNeroBackItUp.exe /UNINSTALL
                      -->C:\WINDOWS\UNNeroMediaHome.exe /UNINSTALL
                      -->C:\WINDOWS\UNNeroShowTime.exe /UNINSTALL
                      -->C:\WINDOWS\UNNeroVision.exe /UNINSTALL
                      -->C:\WINDOWS\UNRecode.exe /UNINSTALL
                      -->MsiExec /X{DD1865F0-AD73-40FB-B23E-1822E02396FF}
                      -->MsiExec.exe /X{CBE9E8B5-95B3-4E24-A5CA-55503502DFCB}
                      -->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{2E47302B-8081-46D3-9FEA-BEB2E5F5C3EC}\setup.exe" -l0x40c anything
                      -->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
                      32 Bit HP CIO Components Installer-->MsiExec.exe /I{2614F54E-A828-49FA-93BA-45A3F756BFAA}
                      Adobe Flash Player 10 ActiveX-->C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
                      Adobe Flash Player 10 Plugin-->C:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe
                      Adobe Reader 9.1.3 - Français-->MsiExec.exe /I{AC76BA86-7AD7-1036-7B44-A91000000001}
                      Agere Systems HDA Modem-->agrsmdel
                      Apple Application Support-->MsiExec.exe /I{3FA365DF-2D68-45ED-8F83-8C8A33E65143}
                      Apple Mobile Device Support-->MsiExec.exe /I{AADEA55D-C834-4BCB-98A3-4B8D1C18F4EE}
                      Apple Software Update-->MsiExec.exe /I{6956856F-B6B3-4BE0-BA0B-8F495BE32033}
                      Archiveur WinRAR-->C:\Program Files\WinRAR\uninstall.exe
                      ArcSoft Software Suite-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{497A1721-088F-41EF-8876-B43C9DA5528B}\Setup.exe" -l0x40c
                      Arima LED Display Utility-->C:\WINDOWS\UnInst32.exe w810MmHk.uni
                      Ask Toolbar-->rundll32 C:\PROGRA~1\AskSBar\bar\1.bin\AskSBar.dll,O
                      Assistant de connexion Windows Live-->MsiExec.exe /I{D3116CC7-24DC-4CA3-9CE1-23FED836E9F2}
                      Avira AntiVir Personal - Free Antivirus-->C:\Program Files\Avira\AntiVir Desktop\setup.exe /REMOVE
                      Battlefield 2(TM)-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\10\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{04858915-9F49-4B2A-AED4-DC49A7DE6A7B}\setup.exe" -l0x40c -removeonly
                      Bbox - Bouygues Telecom - Utilitaire de mise à jour-->C:\Program Files\BboxUpdate\uninstall.exe
                      Bonjour-->MsiExec.exe /I{07287123-B8AC-41CE-8346-3D777245C35B}
                      Call of Duty(R) 2-->C:\PROGRA~1\FICHIE~1\INSTAL~1\Driver\9\INTEL3~1\IDriver.exe /M{D0A05794-48C2-4424-A15A-9F20FCFDD374} /l2057
                      CCleaner (remove only)-->"C:\Program Files\CCleaner\uninst.exe"
                      CDDRV_Installer-->MsiExec.exe /I{0C826C5B-B131-423A-A229-C71B3CACCD6A}
                      Collection Microsoft Encarta 2003-->MsiExec.exe /I{034600E1-3975-4267-9F39-1DC4745090B7}
                      COMODO Firewall Pro-->C:\Program Files\COMODO\Firewall\cfpconfg.exe -u
                      COMODO SafeSurf-->C:\Program Files\COMODO\SafeSurf\cssconfg.exe -u
                      Compel Adaptec WinASPI-->"C:\Program Files\WinASPI\unins000.exe"
                      Correctif pour Lecteur Windows Media 11 (KB939683)-->"C:\WINDOWS\$NtUninstallKB939683$\spuninst\spuninst.exe"
                      Correctif pour Windows Internet Explorer 7 (KB947864)-->"C:\WINDOWS\ie7updates\KB947864-IE7\spuninst\spuninst.exe"
                      Correctif pour Windows XP (KB952287)-->"C:\WINDOWS\$NtUninstallKB952287$\spuninst\spuninst.exe"
                      Correctif pour Windows XP (KB961118)-->"C:\WINDOWS\$NtUninstallKB961118$\spuninst\spuninst.exe"
                      Correctif pour Windows XP (KB970653-v3)-->"C:\WINDOWS\$NtUninstallKB970653-v3$\spuninst\spuninst.exe"
                      Correctif pour Windows XP (KB976098-v2)-->"C:\WINDOWS\$NtUninstallKB976098-v2$\spuninst\spuninst.exe"
                      DAEMON Tools-->MsiExec.exe /I{3DED3A72-61A8-4B87-98A5-EF0BC8038AA0}
                      dBpoweramp FLAC Codec-->"C:\WINDOWS\system32\SpoonUninstall.exe" <uninstall>C:\WINDOWS\system32\SpoonUninstall-dBpoweramp FLAC Codec.dat
                      dBpoweramp Music Converter-->"C:\WINDOWS\system32\SpoonUninstall.exe" <uninstall>C:\WINDOWS\system32\SpoonUninstall-dBpoweramp Music Converter.dat
                      Désinstaller Bouygues Telecom - CD d'installation Bbox-->C:\Program Files\Bbox\eSKernel.exe /Uninstall.xml
                      DivX Player-->C:\Program Files\DivX\DivXPlayerUninstall.exe /PLAYER
                      DivX-->C:\Program Files\DivX\DivXCodecUninstall.exe /CODEC
                      Driver Detective-->C:\Program Files\InstallShield Installation Information\{621C02EA-AAFF-4026-A903-165D59529A16}\setup.exe -runfromtemp -l0x0409
                      Ecran de veille AOL Photos-->C:\Program Files\Fichiers communs\AOL\Screensaver\uninst_ygpss.exe
                      EPSON Logiciel imprimante-->C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\EPUPDATE.EXE /R
                      EPSON Scan-->C:\Program Files\epson\escndv\setup\setup.exe /r
                      eTrust Registration-->MsiExec.exe /X{6BFF4534-7608-41F0-85F7-31A0569D8960}
                      Extension HighMAT pour l'Assistant Graver un CD de Microsoft Windows XP-->MsiExec.exe /X{FCE65C4E-B0E8-4FBD-AD16-EDCBE6CD591F}
                      Far Cry 2-->"C:\Program Files\InstallShield Installation Information\{F2835483-37F2-4123-B4FE-0E77D58447F2}\setup.exe" -runfromtemp -l0x040c -removeonly
                      Frets On Fire-->"C:\Program Files\Frets on Fire\Uninstall.exe"
                      Galerie de photos Windows Live-->MsiExec.exe /X{B131E59D-202C-43C6-84C9-68F0C37541F1}
                      GameShadow-->MsiExec.exe /I{F7C1C17E-70E3-475F-BD52-EA554391F15D}
                      Google Toolbar for Internet Explorer-->"C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarManager_0E996B068B56FCA2.exe" /uninstall
                      Google Toolbar for Internet Explorer-->MsiExec.exe /I{18455581-E099-4BA8-BC6B-F34B2F06600C}
                      Haali Media Splitter-->"C:\Program Files\Matroska Pack\haali\uninstall.exe"
                      High Definition Audio Driver Package - KB888111-->"C:\WINDOWS\$NtUninstallKB888111WXPSP2$\spuninst\spuninst.exe"
                      HijackThis 2.0.2-->"C:\Program Files\trend micro\HijackThis.exe" /uninstall
                      Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)-->C:\WINDOWS\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall /qb+ REBOOTPROMPT=""
                      Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)-->C:\WINDOWS\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {A7EEA2F2-BFCD-4A54-A575-7B81A786E658} /qb+ REBOOTPROMPT=""
                      Hotfix for Windows Media Format 11 SDK (KB929399)-->"C:\WINDOWS\$NtUninstallKB929399$\spuninst\spuninst.exe"
                      Hotfix for Windows Media Format SDK (KB902344)-->"C:\WINDOWS\$NtUninstallKB902344$\spuninst\spuninst.exe"
                      HP Customer Participation Program 10.0-->C:\Program Files\HP\Digital Imaging\ExtCapUninstall\hpzscr01.exe -datfile hpqhsc01.dat
                      HP Deskjet F4200 All-In-One Driver Software 10.0 Rel .3-->C:\Program Files\HP\Digital Imaging\{AE9A67F9-ADF1-4a44-BAB5-C1DB302B37A2}\setup\hpzscr01.exe -datfile hposcr28.dat -onestop
                      HP Imaging Device Functions 10.0-->C:\Program Files\HP\Digital Imaging\DeviceManagement\hpzscr01.exe -datfile hpqbud01.dat
                      HP Photosmart Essential 2.5-->C:\Program Files\HP\Digital Imaging\PhotoSmartEssential\hpzscr01.exe -datfile hpqbud13.dat
                      HP PSC & OfficeJet 5.3.A-->"C:\Program Files\HP\Digital Imaging\{3E386744-10FA-44b2-98C9-DF7A270DECB3}\setup\hpzscr01.exe" -datfile hposcr06.dat
                      hp psc 900 series - 1-->C:\WINDOWS\system32\hpocon07.exe /u 1240422091 /d "hp psc 900 series"
                      HP Share-to-Web-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{748F4870-8350-11D3-B0BF-080009FB4A19}\setup.exe" %MAIN -l9
                      HP Smart Web Printing-->C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpzscr01.exe -datfile hpqbud15.dat
                      HP Software Update-->MsiExec.exe /X{15EE79F4-4ED1-4267-9B0F-351009325D7D}
                      HP Solution Center 10.0-->C:\Program Files\HP\Digital Imaging\eSupport\hpzscr01.exe -datfile hpqbud05.dat
                      HP Update-->MsiExec.exe /X{FE57DE70-95DE-4B64-9266-84DA811053DB}
                      Inkscape 0.46-->C:\Program Files\Inkscape\Uninstall.exe
                      Installation Windows Live-->C:\Program Files\Windows Live\Installer\wlarp.exe
                      Installation Windows Live-->MsiExec.exe /I{46ABBC54-1872-4AA3-95E2-F2C063A63F31}
                      Intel PROSet Wireless-->Intel PROSet Wireless
                      IrfanView (remove only)-->C:\Program Files\IrfanView\iv_uninstall.exe
                      iTunes-->MsiExec.exe /I{A6FDF86A-F541-4E7B-AEA0-8849A2A700D5}
                      Java(TM) 6 Update 15-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216010FF}
                      Junk Mail filter update-->MsiExec.exe /I{E2DFE069-083E-4631-9B6C-43C48E991DE5}
                      KhalInstallWrapper-->MsiExec.exe /I{3101CB58-3482-4D21-AF1A-7057FC935355}
                      K-Lite Mega Codec Pack 1.38-->"C:\Program Files\K-Lite Codec Pack\unins000.exe"
                      L&H TTS3000 Français-->RunDll32 advpack.dll,LaunchINFSection C:\WINDOWS\INF\LHTTSFRF.inf, Uninstall
                      Learn2 Player (Uninstall Only)-->C:\Program Files\Learn2.com\StRunner\stuninst.exe
                      Lecteur Windows Media 11-->"C:\Program Files\Windows Media Player\Setup_wm.exe" /Uninstall
                      LimeWire 5.0.11-->"C:\Program Files\LimeWire\uninstall.exe"
                      Logitech SetPoint 5.10-->MsiExec.exe /I{D3120436-1358-4253-9EB2-257FFE8CE1D9}
                      Logitech SetPoint-->"C:\Program Files\InstallShield Installation Information\{F29B21BD-CAA6-445F-8EF7-A7E2B9D8B14E}\setup.exe" -runfromtemp -l0x040c -removeonly
                      Ma-Config.com-->MsiExec.exe /X{8AFB8FC4-3EBA-4C67-943F-CF43DB2180F1}
                      Macromedia Shockwave Player-->C:\WINDOWS\system32\Macromed\SHOCKW~1\UNWISE.EXE C:\WINDOWS\system32\Macromed\SHOCKW~1\Install.log
                      Malwarebytes' Anti-Malware-->"C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
                      Marvell Miniport Driver-->C:\Program Files\Marvell\Miniport Driver\Uninst.exe
                      Matroska Pack-->C:\Program Files\Matroska Pack\uninstall.exe
                      Messager Wanadoo-->C:\PROGRA~1\MESSAG~1\Uninstall.exe
                      Microsoft .NET Framework 1.1 French Language Pack-->MsiExec.exe /X{9A394342-4A68-4EBA-85A6-55B559F4E700}
                      Microsoft .NET Framework 1.1 Security Update (KB953297)-->"C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\hotfix.exe" "C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\M953297\M953297Uninstall.msp"
                      Microsoft .NET Framework 1.1-->msiexec.exe /X {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
                      Microsoft .NET Framework 1.1-->MsiExec.exe /X{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
                      Microsoft .NET Framework 2.0 Service Pack 2-->MsiExec.exe /I{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}
                      Microsoft .NET Framework 3.0 Service Pack 2-->MsiExec.exe /I{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}
                      Microsoft .NET Framework 3.5 SP1-->C:\WINDOWS\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setup.exe
                      Microsoft .NET Framework 3.5 SP1-->MsiExec.exe /I{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}
                      Microsoft Choice Guard-->MsiExec.exe /X{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}
                      Microsoft Compression Client Pack 1.0 for Windows XP-->"C:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe"
                      Microsoft Internationalized Domain Names Mitigation APIs-->"C:\WINDOWS\$NtServicePackUninstallIDNMitigationAPIs$\spuninst\spuninst.exe"
                      Microsoft Kernel-Mode Driver Framework Feature Pack 1.5-->"C:\WINDOWS\$NtUninstallWdf01005$\spuninst\spuninst.exe"
                      Microsoft National Language Support Downlevel APIs-->"C:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$\spuninst\spuninst.exe"
                      Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0016-040C-0000-0000000FF1CE} /uninstall {AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
                      Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0018-040C-0000-0000000FF1CE} /uninstall {AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
                      Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001B-040C-0000-0000000FF1CE} /uninstall {AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
                      Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-006E-040C-0000-0000000FF1CE} /uninstall {B165D3C2-40AE-4D39-86F7-E5C87C4264C0}
                      Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-00A1-040C-0000-0000000FF1CE} /uninstall {AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
                      Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}
                      Microsoft Office Excel MUI (French) 2007-->MsiExec.exe /X{90120000-0016-040C-0000-0000000FF1CE}
                      Microsoft Office Home and Student 2007-->"C:\Program Files\Fichiers communs\Microsoft Shared\OFFICE12\Office Setup Controller\setup.exe" /uninstall HOMESTUDENTR /dll OSETUP.DLL
                      Microsoft Office Home and Student 2007-->MsiExec.exe /X{91120000-002F-0000-0000-0000000FF1CE}
                      Microsoft Office Live Add-in 1.3-->MsiExec.exe /I{57F0ED40-8F11-41AA-B926-4A66D0D1A9CC}
                      Microsoft Office OneNote MUI (French) 2007-->MsiExec.exe /X{90120000-00A1-040C-0000-0000000FF1CE}
                      Microsoft Office PowerPoint MUI (French) 2007-->MsiExec.exe /X{90120000-0018-040C-0000-0000000FF1CE}
                      Microsoft Office Proof (Arabic) 2007-->MsiExec.exe /X{90120000-001F-0401-0000-0000000FF1CE}
                      Microsoft Office Proof (Dutch) 2007-->MsiExec.exe /X{90120000-001F-0413-0000-0000000FF1CE}
                      Microsoft Office Proof (English) 2007-->MsiExec.exe /X{90120000-001F-0409-0000-0000000FF1CE}
                      Microsoft Office Proof (French) 2007-->MsiExec.exe /X{90120000-001F-040C-0000-0000000FF1CE}
                      Microsoft Office Proof (German) 2007-->MsiExec.exe /X{90120000-001F-0407-0000-0000000FF1CE}
                      Microsoft Office Proof (Spanish) 2007-->MsiExec.exe /X{90120000-001F-0C0A-0000-0000000FF1CE}
                      Microsoft Office Proofing (French) 2007-->MsiExec.exe /X{90120000-002C-040C-0000-0000000FF1CE}
                      Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0401-0000-0000000FF1CE} /uninstall {14809F99-C601-4D4A-9391-F1E8FAA964C5}
                      Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0407-0000-0000000FF1CE} /uninstall {A0516415-ED61-419A-981D-93596DA74165}
                      Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0409-0000-0000000FF1CE} /uninstall {ABDDE972-355B-4AF1-89A8-DA50B7B5C045}
                      Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-040C-0000-0000000FF1CE} /uninstall {F580DDD5-8D37-4998-968E-EBB76BB86787}
                      Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0413-0000-0000000FF1CE} /uninstall {D66D5A44-E480-4BA4-B4F2-C554F6B30EBB}
                      Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0C0A-0000-0000000FF1CE} /uninstall {187308AB-5FA7-4F14-9AB9-D290383A10D9}
                      Microsoft Office Shared MUI (French) 2007-->MsiExec.exe /X{90120000-006E-040C-0000-0000000FF1CE}
                      Microsoft Office Word MUI (French) 2007-->MsiExec.exe /X{90120000-001B-040C-0000-0000000FF1CE}
                      Microsoft Silverlight-->MsiExec.exe /X{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
                      Microsoft SQL Server 2005 Compact Edition [ENU]-->MsiExec.exe /I{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}
                      Microsoft SQL Server Desktop Engine (PINNACLESYS)-->MsiExec.exe /X{E09B48B5-E141-427A-AB0C-D3605127224A}
                      Microsoft User-Mode Driver Framework Feature Pack 1.0-->"C:\WINDOWS\$NtUninstallWudf01000$\spuninst\spuninst.exe"
                      Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053-->MsiExec.exe /X{770657D0-A123-3C07-8E44-1C83EC895118}
                      Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
                      Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148-->MsiExec.exe /X{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}
                      Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17-->MsiExec.exe /X{9A25302D-30C0-39D9-BD6F-21E6EC160475}
                      Mise à jour critique pour Lecteur Windows Media 11 (KB959772)-->"C:\WINDOWS\$NtUninstallKB959772_WM11$\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Lecteur Windows Media (KB952069)-->"C:\WINDOWS\$NtUninstallKB952069_WM9$\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Lecteur Windows Media (KB954155)-->"C:\WINDOWS\$NtUninstallKB954155_WM9$\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Lecteur Windows Media (KB968816)-->"C:\WINDOWS\$NtUninstallKB968816_WM9$\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Lecteur Windows Media (KB973540)-->"C:\WINDOWS\$NtUninstallKB973540_WM9$\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Lecteur Windows Media 10 (KB911565)-->"C:\WINDOWS\$NtUninstallKB911565$\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Lecteur Windows Media 10 (KB917734)-->"C:\WINDOWS\$NtUninstallKB917734_WMP10$\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Lecteur Windows Media 10 (KB936782)-->"C:\WINDOWS\$NtUninstallKB936782_WMP10$\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Lecteur Windows Media 11 (KB936782)-->"C:\WINDOWS\$NtUninstallKB936782_WMP11$\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Lecteur Windows Media 11 (KB954154)-->"C:\WINDOWS\$NtUninstallKB954154_WM11$\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Step by Step Interactive Training (KB898458)-->"C:\WINDOWS\$NtUninstallKB898458$\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Step by Step Interactive Training (KB923723)-->"C:\WINDOWS\$NtUninstallKB923723$\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Windows Internet Explorer 7 (KB928090)-->"C:\WINDOWS\ie7updates\KB928090-IE7\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Windows Internet Explorer 7 (KB929969)-->"C:\WINDOWS\ie7updates\KB929969\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Windows Internet Explorer 7 (KB931768)-->"C:\WINDOWS\ie7updates\KB931768-IE7\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Windows Internet Explorer 7 (KB933566)-->"C:\WINDOWS\ie7updates\KB933566-IE7\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Windows Internet Explorer 7 (KB937143)-->"C:\WINDOWS\ie7updates\KB937143-IE7\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Windows Internet Explorer 7 (KB938127)-->"C:\WINDOWS\ie7updates\KB938127-IE7\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Windows Internet Explorer 7 (KB939653)-->"C:\WINDOWS\ie7updates\KB939653-IE7\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Windows Internet Explorer 7 (KB942615)-->"C:\WINDOWS\ie7updates\KB942615-IE7\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Windows Internet Explorer 7 (KB950759)-->"C:\WINDOWS\ie7updates\KB950759-IE7\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Windows Internet Explorer 7 (KB953838)-->"C:\WINDOWS\ie7updates\KB953838-IE7\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Windows Internet Explorer 7 (KB956390)-->"C:\WINDOWS\ie7updates\KB956390-IE7\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Windows Internet Explorer 7 (KB958215)-->"C:\WINDOWS\ie7updates\KB958215-IE7\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Windows Internet Explorer 7 (KB960714)-->"C:\WINDOWS\ie7updates\KB960714-IE7\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Windows Internet Explorer 7 (KB961260)-->"C:\WINDOWS\ie7updates\KB961260-IE7\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Windows Internet Explorer 7 (KB963027)-->"C:\WINDOWS\ie7updates\KB963027-IE7\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Windows Internet Explorer 7 (KB969897)-->"C:\WINDOWS\ie7updates\KB969897-IE7\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Windows Internet Explorer 8 (KB969897)-->"C:\WINDOWS\ie8updates\KB969897-IE8\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Windows Internet Explorer 8 (KB971961)-->"C:\WINDOWS\ie8updates\KB971961-IE8\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Windows Internet Explorer 8 (KB972260)-->"C:\WINDOWS\ie8updates\KB972260-IE8\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Windows Internet Explorer 8 (KB974455)-->"C:\WINDOWS\ie8updates\KB974455-IE8\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Windows Internet Explorer 8 (KB976325)-->"C:\WINDOWS\ie8updates\KB976325-IE8\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Windows XP (KB923561)-->"C:\WINDOWS\$NtUninstallKB923561$\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Windows XP (KB938464)-->"C:\WINDOWS\$NtUninstallKB938464$\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Windows XP (KB938464-v2)-->"C:\WINDOWS\$NtUninstallKB938464-v2$\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Windows XP (KB941569)-->"C:\WINDOWS\$NtUninstallKB941569$\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Windows XP (KB946648)-->"C:\WINDOWS\$NtUninstallKB946648$\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Windows XP (KB950760)-->"C:\WINDOWS\$NtUninstallKB950760$\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Windows XP (KB950762)-->"C:\WINDOWS\$NtUninstallKB950762$\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Windows XP (KB950974)-->"C:\WINDOWS\$NtUninstallKB950974$\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Windows XP (KB951066)-->"C:\WINDOWS\$NtUninstallKB951066$\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Windows XP (KB951376)-->"C:\WINDOWS\$NtUninstallKB951376$\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Windows XP (KB951376-v2)-->"C:\WINDOWS\$NtUninstallKB951376-v2$\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Windows XP (KB951698)-->"C:\WINDOWS\$NtUninstallKB951698$\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Windows XP (KB951748)-->"C:\WINDOWS\$NtUninstallKB951748$\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Windows XP (KB952004)-->"C:\WINDOWS\$NtUninstallKB952004$\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Windows XP (KB952954)-->"C:\WINDOWS\$NtUninstallKB952954$\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Windows XP (KB953839)-->"C:\WINDOWS\$NtUninstallKB953839$\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Windows XP (KB954211)-->"C:\WINDOWS\$NtUninstallKB954211$\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Windows XP (KB954459)-->"C:\WINDOWS\$NtUninstallKB954459$\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Windows XP (KB954600)-->"C:\WINDOWS\$NtUninstallKB954600$\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Windows XP (KB955069)-->"C:\WINDOWS\$NtUninstallKB955069$\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Windows XP (KB956391)-->"C:\WINDOWS\$NtUninstallKB956391$\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Windows XP (KB956572)-->"C:\WINDOWS\$NtUninstallKB956572$\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Windows XP (KB956744)-->"C:\WINDOWS\$NtUninstallKB956744$\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Windows XP (KB956802)-->"C:\WINDOWS\$NtUninstallKB956802$\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Windows XP (KB956803)-->"C:\WINDOWS\$NtUninstallKB956803$\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Windows XP (KB956841)-->"C:\WINDOWS\$NtUninstallKB956841$\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Windows XP (KB956844)-->"C:\WINDOWS\$NtUninstallKB956844$\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Windows XP (KB957095)-->"C:\WINDOWS\$NtUninstallKB957095$\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Windows XP (KB957097)-->"C:\WINDOWS\$NtUninstallKB957097$\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Windows XP (KB958644)-->"C:\WINDOWS\$NtUninstallKB958644$\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Windows XP (KB958687)-->"C:\WINDOWS\$NtUninstallKB958687$\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Windows XP (KB958690)-->"C:\WINDOWS\$NtUninstallKB958690$\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Windows XP (KB958869)-->"C:\WINDOWS\$NtUninstallKB958869$\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Windows XP (KB959426)-->"C:\WINDOWS\$NtUninstallKB959426$\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Windows XP (KB960225)-->"C:\WINDOWS\$NtUninstallKB960225$\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Windows XP (KB960715)-->"C:\WINDOWS\$NtUninstallKB960715$\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Windows XP (KB960803)-->"C:\WINDOWS\$NtUninstallKB960803$\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Windows XP (KB960859)-->"C:\WINDOWS\$NtUninstallKB960859$\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Windows XP (KB961371)-->"C:\WINDOWS\$NtUninstallKB961371$\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Windows XP (KB961373)-->"C:\WINDOWS\$NtUninstallKB961373$\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Windows XP (KB961501)-->"C:\WINDOWS\$NtUninstallKB961501$\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Windows XP (KB968537)-->"C:\WINDOWS\$NtUninstallKB968537$\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Windows XP (KB969059)-->"C:\WINDOWS\$NtUninstallKB969059$\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Windows XP (KB969898)-->"C:\WINDOWS\$NtUninstallKB969898$\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Windows XP (KB969947)-->"C:\WINDOWS\$NtUninstallKB969947$\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Windows XP (KB970238)-->"C:\WINDOWS\$NtUninstallKB970238$\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Windows XP (KB970430)-->"C:\WINDOWS\$NtUninstallKB970430$\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Windows XP (KB971486)-->"C:\WINDOWS\$NtUninstallKB971486$\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Windows XP (KB971557)-->"C:\WINDOWS\$NtUninstallKB971557$\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Windows XP (KB971633)-->"C:\WINDOWS\$NtUninstallKB971633$\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Windows XP (KB971657)-->"C:\WINDOWS\$NtUninstallKB971657$\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Windows XP (KB973346)-->"C:\WINDOWS\$NtUninstallKB973346$\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Windows XP (KB973354)-->"C:\WINDOWS\$NtUninstallKB973354$\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Windows XP (KB973507)-->"C:\WINDOWS\$NtUninstallKB973507$\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Windows XP (KB973525)-->"C:\WINDOWS\$NtUninstallKB973525$\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Windows XP (KB973869)-->"C:\WINDOWS\$NtUninstallKB973869$\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Windows XP (KB973904)-->"C:\WINDOWS\$NtUninstallKB973904$\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Windows XP (KB974112)-->"C:\WINDOWS\$NtUninstallKB974112$\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Windows XP (KB974318)-->"C:\WINDOWS\$NtUninstallKB974318$\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Windows XP (KB974392)-->"C:\WINDOWS\$NtUninstallKB974392$\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Windows XP (KB974571)-->"C:\WINDOWS\$NtUninstallKB974571$\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Windows XP (KB975025)-->"C:\WINDOWS\$NtUninstallKB975025$\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Windows XP (KB975467)-->"C:\WINDOWS\$NtUninstallKB975467$\spuninst\spuninst.exe"
                      Mise à jour pour Windows Internet Explorer 8 (KB971180)-->"C:\WINDOWS\ie8updates\KB971180-IE8\spuninst\spuninst.exe"
                      Mise à jour pour Windows Internet Explorer 8 (KB976749)-->"C:\WINDOWS\ie8updates\KB976749-IE8\spuninst\spuninst.exe"
                      Mise à jour pour Windows XP (KB951072-v2)-->"C:\WINDOWS\$NtUninstallKB951072-v2$\spuninst\spuninst.exe"
                      Mise à jour pour Windows XP (KB951978)-->"C:\WINDOWS\$NtUninstallKB951978$\spuninst\spuninst.exe"
                      Mise à jour pour Windows XP (KB955839)-->"C:\WINDOWS\$NtUninstallKB955839$\spuninst\spuninst.exe"
                      Mise à jour pour Windows XP (KB961503)-->"C:\WINDOWS\$NtUninstallKB961503$\spuninst\spuninst.exe"
                      Mise à jour pour Windows XP (KB967715)-->"C:\WINDOWS\$NtUninstallKB967715$\spuninst\spuninst.exe"
                      Mise à jour pour Windows XP (KB968389)-->"C:\WINDOWS\$NtUninstallKB968389$\spuninst\spuninst.exe"
                      Mise à jour pour Windows XP (KB971737)-->"C:\WINDOWS\$NtUninstallKB971737$\spuninst\spuninst.exe"
                      Mise à jour pour Windows XP (KB973687)-->"C:\WINDOWS\$NtUninstallKB973687$\spuninst\spuninst.exe"
                      Mise à jour pour Windows XP (KB973815)-->"C:\WINDOWS\$NtUninstallKB973815$\spuninst\spuninst.exe"
                      MobileMe Control Panel-->MsiExec.exe /I{3AC54383-31D1-4907-961B-B12CBB1D0AE8}
                      Module de prise en charge linguistique de Microsoft .NET Framework 2.0 - FRA-->C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0 Language Pack - FRA\install.exe
                      Mozilla Firefox (3.5.6)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
                      mProSafe-->MsiExec.exe /I{23FB368F-1399-4EAC-817C-4B83ECBE3D83}
                      MSVCRT-->MsiExec.exe /I{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}
                      MSXML 4.0 SP2 (KB927978)-->MsiExec.exe /I{37477865-A3F1-4772-AD43-AAFC6BCFF99F}
                      MSXML 4.0 SP2 (KB936181)-->MsiExec.exe /I{C04E32E0-0416-434D-AFB9-6969D703A9EF}
                      MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
                      MSXML 4.0 SP2 (KB973688)-->MsiExec.exe /I{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}
                      mWlsSafe-->MsiExec.exe /I{FCA651F3-5BDA-4DDA-9E4A-5D87D6914CC4}
                      Nero 8-->MsiExec.exe /X{2B8F4D70-F9CA-4E94-B2A5-49AAD4CE1036}
                      NetLogo 4.0.4-->"C:\Program Files\NetLogo 4.0.4\UninstallerData\Uninstall NetLogo.exe"
                      NVIDIA Drivers-->C:\WINDOWS\system32\nvuninst.exe UninstallGUI
                      NVIDIA PhysX-->MsiExec.exe /X{DD1865F0-AD73-40FB-B23E-1822E02396FF}
                      OpenOffice.org 2.0-->MsiExec.exe /I{E2C356F6-84B5-4CCB-8FED-12E0F1C2E97B}
                      Orange - Logiciels Internet-->C:\Program Files\OrangeHSS\installation\core\Installgui.exe -u
                      Outil de téléchargement Windows Live-->MsiExec.exe /I{205C6BDD-7B73-42DE-8505-9A093F35A238}
                      Package de base Microsoft de service de chiffrement pour cartes à puce-->"C:\WINDOWS\$NtUninstallbasecsp$\spuninst\spuninst.exe"
                      pdfsam-->C:\Program Files\pdfsam\uninstall.exe
                      Philips SPC1300NC Webcam-->C:\Program Files\InstallShield Installation Information\{314D592A-B234-4424-A49C-B43F993AB07B}\setup.exe -runfromtemp -l0x040c -removeonly
                      Philips VLounge-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{EA57A1B9-0DD2-44DD-9B70-64E8DA553F6F}\Setup.exe" -l0x40c
                      PHOTOfunSTUDIO -viewer--->C:\Program Files\InstallShield Installation Information\{9A9DBEBC-C800-4776-A970-D76D6AA405B1}\setup.exe -runfromtemp -l0x0c0c -z"Uninstall" -removeonly
                      PinnacleHollywood FX 5-->C:\WINDOWS\unvise32.exe C:\Program Files\Pinnacle\Hollywood FX 5\uninstal.log
                      PowerCinema Linux 4.5-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{D5F82F8F-4DE2-11D9-A373-0050BAE317E1}\setup.exe" -uninstall
                      PowerCinema-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{2637C347-9DAD-11D6-9EA2-00055D0CA761}\setup.exe" -uninstall
                      PowerDVD-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}\setup.exe" -uninstall
                      PowerProducer-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{B7A0CE06-068E-11D6-97FD-0050BACBF861}\setup.exe" -uninstall
                      PunkBuster Services-->C:\WINDOWS\system32\pbsvc.exe -u
                      QuickTime-->MsiExec.exe /I{1451DE6B-ABE1-4F62-BE9A-B363A17588A2}
                      R for Windows 2.9.2-->"C:\Program Files\R\R-2.9.2\unins000.exe"
                      Real Alternative 1.43-->"C:\Program Files\Real Alternative\unins000.exe"
                      Realtek High Definition Audio Driver-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}\Setup.exe" -l0x40c -removeonly
                      Regressi-->MsiExec.exe /I{E2E164AB-1367-488F-8F1F-BA312DB2FF18}
                      Rename-It!-->C:\Program Files\Rename-It!\Uninst.exe
                      Safari-->MsiExec.exe /I{D6E4E5D6-7693-4BB4-95BA-21F38FAFEE90}
                      SAGEM F@st 800-840-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{4AE3A0CB-87B0-4F51-BECD-3D1F8DFDD62F}\setup.exe" -l0x40c
                      Security Update for 2007 Microsoft Office System (KB969559)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {69F52148-9BF6-4CDC-BF76-103DEAF3DD08}
                      Security Update for 2007 Microsoft Office System (KB973704)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {E626DC89-A787-4553-9BB3-DC2EC7E1593F}
                      Security Update for CAPICOM (KB931906)-->MsiExec.exe /I{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
                      Security Update for CAPICOM (KB931906)-->MsiExec.exe /X{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
                      Security Update for Microsoft Office Excel 2007 (KB973593)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {7D6255E3-3423-4D8B-A328-F6F8D28DD5FE}
                      Security Update for Microsoft Office PowerPoint 2007 (KB957789)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {7559E742-FF9F-4FAE-B279-008ED296CB4D}
                      Security Update for Microsoft Office system 2007 (972581)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {3D019598-7B59-447A-80AE-815B703B84FF}
                      Security Update for Microsoft Office system 2007 (KB969613)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {5ECEB317-CBE9-4E08-AB10-756CB6F0FB6C}
                      Security Update for Microsoft Office system 2007 (KB974234)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {FCD742B9-7A55-44BC-A776-F795F21FEDDC}
                      Security Update for Microsoft Office Visio Viewer 2007 (KB973709)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {71127777-8B2C-4F97-AF7A-6CF8CAC8224D}
                      Security Update for Microsoft Office Word 2007 (KB969604)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {CF3D6499-709C-43D0-8908-BC5652656050}
                      Segoe UI-->MsiExec.exe /I{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}
                      Shockwave-->C:\WINDOWS\system32\Macromed\SHOCKW~2\UNWISE.EXE C:\WINDOWS\system32\Macromed\SHOCKW~2\Install.log
                      Shop for HP Supplies-->C:\Program Files\HP\Digital Imaging\HPSSupply\hpzscr01.exe -datfile hpqbud16.dat
                      SPSS 16.0 for Windows-->MsiExec.exe /X{621025AE-3510-478E-BC27-1A647150976F}
                      Spybot - Search & Destroy-->"C:\Program Files\Spybot - Search & Destroy\unins000.exe"
                      SpywareBlaster 4.1-->"C:\Program Files\SpywareBlaster\unins000.exe"
                      SpywareGuard v2.2-->"C:\Program Files\SpywareGuard\unins000.exe"
                      Studio 9-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{9E491AB7-4589-48CA-9CBB-874CB2788391}\Setup.exe" -l0x40c UNINSTALL
                      Studio Content DVD-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{B67624DE-75CE-4FAD-9F29-5C115773CE61}\Setup.exe" -l0x40c
                      SuperCopier2-->"C:\Program Files\SuperCopier2\SC2Uninst.exe"
                      Synaptics Pointing Device Driver-->rundll32.exe "C:\Program Files\Synaptics\SynTP\SynISDLL.dll",standAloneUninstall
                      Thrustmaster Force Feedback Driver-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{8F5A0981-5CDC-41D0-BCA2-AD3B777FC358}\setup.exe" -l0x40c -removeonly
                      Update for 2007 Microsoft Office System (KB967642)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {C444285D-5E4F-48A4-91DD-47AAAA68E92D}
                      Update for Microsoft .NET Framework 3.5 SP1 (KB963707)-->C:\WINDOWS\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {B2AE9C82-DC7B-3641-BFC8-87275C4F3607} /qb+ REBOOTPROMPT=""
                      Update for Microsoft Office InfoPath 2007 (KB976416)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {432C5EE4-8096-4FF1-95E1-65219365DFF7}
                      UsbFix-->C:\Program Files\UsbFix\Uninstal.exe
                      Utilitaire de configuration iPhone-->MsiExec.exe /I{FA54AFB1-5745-4389-B8C1-9F7509672ED1}
                      Utilitaire de sauvegarde Windows-->MsiExec.exe /I{76EFFC7C-17A6-479D-9E47-8E658C1695AE}
                      VideoLAN VLC media player 0.8.6a-->C:\Program Files\VideoLAN\VLC\uninstall.exe
                      Viewpoint Media Player-->C:\Program Files\Viewpoint\Viewpoint Experience Technology\mtsAxInstaller.exe /u
                      VoiceOver Kit-->MsiExec.exe /I{6DE13770-01B7-4366-8DA6-48237793F445}
                      Wanadoo-->C:\PROGRA~1\Wanadoo\Shell.exe desinstall.shl
                      Windows Genuine Advantage v1.3.0254.0-->MsiExec.exe /I{63569CE9-FA00-469C-AF5C-E5D4D93ACF91}
                      Windows Internet Explorer 8-->"C:\WINDOWS\ie8\spuninst\spuninst.exe"
                      Windows Live Call-->MsiExec.exe /I{82C7B308-0BDD-49D8-8EA5-9CD3A3F9DF41}
                      Windows Live Communications Platform-->MsiExec.exe /I{3B4E636E-9D65-4D67-BA61-189800823F52}
                      Windows Live FolderShare-->MsiExec.exe /X{2075CB0A-D26F-4DAA-B424-5079296B43BA}
                      Windows Live Mail-->MsiExec.exe /I{5DD76286-9BE7-4894-A990-E905E91AC818}
                      Windows Live Messenger-->MsiExec.exe /X{770F1BEC-2871-4E70-B837-FB8525FFA3B1}
                      Windows Media Connect-->"C:\WINDOWS\$NtUninstallWMCSetup$\spuninst\spuninst.exe"
                      Windows Media Format 11 runtime-->"C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll
                      Windows Media Format 11 runtime-->"C:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe"
                      Windows Media Format SDK Hotfix - KB891122-->"C:\WINDOWS\$NtUninstallKB891122$\spuninst\spuninst.exe"
                      Windows Media Player 11-->"C:\WINDOWS\$NtUninstallwmp11$\spuninst\spuninst.exe"
                      Windows XP Service Pack 3-->"C:\WINDOWS\$NtServicePackUninstall$\spuninst\spuninst.exe"
                      X10 Hardware(TM)-->C:\WINDOWS\UNWISE.EXE C:\PROGRA~1\X10HAR~1\Install.log
                      Yahoo! Toolbar avec bloqueur de fenêtres pop-up-->C:\PROGRA~1\Yahoo!\Common\unyt.exe

                      ======Security center information======

                      AV: Malware Defense (outdated)
                      AV: AntiVir Desktop (disabled) (outdated)
                      FW: COMODO Firewall (disabled)

                      ======System event log======

                      Computer Name: CLOCLO
                      Event Code: 7035
                      Message: Un contrôle Démarrer a correctement été envoyé au service Gestionnaire de connexions d'accès distant.

                      Record Number: 79795
                      Source Name: Service Control Manager
                      Time Written: 20091112212409.000000+060
                      Event Type: Informations
                      User: AUTORITE NT\SYSTEM

                      Computer Name: CLOCLO
                      Event Code: 7035
                      Message: Un contrôle Démarrer a correctement été envoyé au service Service COM de gravage de CD IMAPI.

                      Record Number: 79794
                      Source Name: Service Control Manager
                      Time Written: 20091112212409.000000+060
                      Event Type: Informations
                      User: AUTORITE NT\SYSTEM

                      Computer Name: CLOCLO
                      Event Code: 7035
                      Message: Un contrôle Démarrer a correctement été envoyé au service hpqcxs08.

                      Record Number: 79793
                      Source Name: Service Control Manager
                      Time Written: 20091112212407.000000+060
                      Event Type: Informations
                      User: AUTORITE NT\SYSTEM

                      Computer Name: CLOCLO
                      Event Code: 7036
                      Message: Le service Compatibilité avec le Changement rapide d'utilisateur est entré dans l'état : en cours d'exécution.

                      Record Number: 79792
                      Source Name: Service Control Manager
                      Time Written: 20091112212407.000000+060
                      Event Type: Informations
                      User:

                      Computer Name: CLOCLO
                      Event Code: 7035
                      Message: Un contrôle Démarrer a correctement été envoyé au service Compatibilité avec le Changement rapide d'utilisateur.

                      Record Number: 79791
                      Source Name: Service Control Manager
                      Time Written: 20091112212407.000000+060
                      Event Type: Informations
                      User: AUTORITE NT\SYSTEM

                      =====Application event log=====

                      Computer Name: CLOCLO
                      Event Code: 101
                      Message: msnmsgr (6044) Le moteur de base de données est arrêté.

                      Record Number: 2924
                      Source Name: ESENT
                      Time Written: 20090705181132.000000+120
                      Event Type: Informations
                      User:

                      Computer Name: CLOCLO
                      Event Code: 103
                      Message: msnmsgr (6044) \\.\C:\Documents and Settings\clovis\Local Settings\Application Data\Microsoft\Messenger\visdenice88@hotmail.com\SharingMetadata\Working\database_76C0_78D1_C078_98D7\dfsr.db: Le moteur de base de données a arrêté une instance (0).

                      Record Number: 2923
                      Source Name: ESENT
                      Time Written: 20090705181132.000000+120
                      Event Type: Informations
                      User:

                      Computer Name: CLOCLO
                      Event Code: 102
                      Message: msnmsgr (6044) \\.\C:\Documents and Settings\clovis\Local Settings\Application Data\Microsoft\Messenger\visdenice88@hotmail.com\SharingMetadata\Working\database_76C0_78D1_C078_98D7\dfsr.db: Le moteur de base de données a démarré une nouvelle instance (0).

                      Record Number: 2922
                      Source Name: ESENT
                      Time Written: 20090705180945.000000+120
                      Event Type: Informations
                      User:

                      Computer Name: CLOCLO
                      Event Code: 100
                      Message: msnmsgr (6044) Le moteur de base de données 5.01.2600.5512 est démarré.

                      Record Number: 2921
                      Source Name: ESENT
                      Time Written: 20090705180945.000000+120
                      Event Type: Informations
                      User:

                      Computer Name: CLOCLO
                      Event Code: 101
                      Message: msnmsgr (6044) Le moteur de base de données est arrêté.

                      Record Number: 2920
                      Source Name: ESENT
                      Time Written: 20090705180932.000000+120
                      Event Type: Informations
                      User:

                      =====Security event log=====

                      Computer Name: CLOCLO
                      Event Code: 576
                      Message: Privilèges spéciaux assignés à la nouvelle session :

                      Utilisateur : SERVICE RÉSEAU

                      Domaine : AUTORITE NT

                      Id. de la session : (0x0,0x3E4)

                      Privilèges : SeAuditPrivilege
                      SeAssignPrimaryTokenPrivilege
                      SeChangeNotifyPrivilege

                      Record Number: 190180
                      Source Name: Security
                      Time Written: 20091216020514.000000+060
                      Event Type: Succès de l'audit
                      User: AUTORITE NT\SERVICE RÉSEAU

                      Computer Name: CLOCLO
                      Event Code: 528
                      Message: Ouverture de session réseau réussie :

                      Utilisateur : SERVICE RÉSEAU

                      Domaine : AUTORITE NT

                      Id. de la session : (0x0,0x3E4)

                      Type de session : 5

                      Processus de session : Advapi

                      Package d'authentification : Negotiate

                      Station de travail :

                      GUID d'ouv. de session : -

                      Record Number: 190179
                      Source Name: Security
                      Time Written: 20091216020514.000000+060
                      Event Type: Succès de l'audit
                      User: AUTORITE NT\SERVICE RÉSEAU

                      Computer Name: CLOCLO
                      Event Code: 576
                      Message: Privilèges spéciaux assignés à la nouvelle session :

                      Utilisateur : SERVICE RÉSEAU

                      Domaine : AUTORITE NT

                      Id. de la session : (0x0,0x3E4)

                      Privilèges : SeAuditPrivilege
                      SeAssignPrimaryTokenPrivilege
                      SeChangeNotifyPrivilege

                      Record Number: 190178
                      Source Name: Security
                      Time Written: 20091216020419.000000+060
                      Event Type: Succès de l'audit
                      User: AUTORITE NT\SERVICE RÉSEAU

                      Computer Name: CLOCLO
                      Event Code: 528
                      Message: Ouverture de session réseau réussie :

                      Utilisateur : SERVICE RÉSEAU

                      Domaine : AUTORITE NT

                      Id. de la session : (0x0,0x3E4)

                      Type de session : 5

                      Processus de session : Advapi

                      Package d'authentification : Negotiate

                      Station de travail :

                      GUID d'ouv. de session : -

                      Record Number: 190177
                      Source Name: Security
                      Time Written: 20091216020419.000000+060
                      Event Type: Succès de l'audit
                      User: AUTORITE NT\SERVICE RÉSEAU

                      Computer Name: CLOCLO
                      Event Code: 515
                      Message: Un Processus d'ouv. de session s'est fait reconnaître par l'autorité locale de sécurité.
                      Ce Processus d'ouv. de session sera autorisé à soumettre des requêtes d'ouverture de session.

                      Processus d'ouv. de session : Secondary Logon Service

                      Record Number: 190176
                      Source Name: Security
                      Time Written: 20091216020418.000000+060
                      Event Type: Succès de l'audit
                      User: AUTORITE NT\SYSTEM

                      ======Environment variables======

                      "ComSpec"=%SystemRoot%\system32\cmd.exe
                      "Path"=%systemroot%\system32;%systemroot%;%systemroot%\system32\wbem;C:\Program Files\Microsoft SQL Server\80\Tools\Binn;C:\Program Files\Samsung\Samsung PC Studio 3;C:\Program Files\QuickTime\QTSystem;C:\Program Files\Intel\WiFi\bin\;C:\Program Files\QuickTime\QTSystem\
                      "windir"=%SystemRoot%
                      "FP_NO_HOST_CHECK"=NO
                      "OS"=Windows_NT
                      "PROCESSOR_ARCHITECTURE"=x86
                      "PROCESSOR_LEVEL"=6
                      "PROCESSOR_IDENTIFIER"=x86 Family 6 Model 14 Stepping 8, GenuineIntel
                      "PROCESSOR_REVISION"=0e08
                      "NUMBER_OF_PROCESSORS"=2
                      "PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
                      "TEMP"=%SystemRoot%\TEMP
                      "TMP"=%SystemRoot%\TEMP
                      "CLASSPATH"=.;C:\Program Files\Java\jre6\lib\ext\QTJava.zip
                      "QTJAVA"=C:\Program Files\Java\jre6\lib\ext\QTJava.zip

                      -----------------EOF-----------------

                      Logfile of random's system information tool 1.06 (written by random/random)
                      Run by clovis at 2009-12-28 18:50:53
                      Microsoft Windows XP Édition familiale Service Pack 3
                      System drive C: has 7 GB (14%) free of 54 GB
                      Total RAM: 2046 MB (53% free)

                      Logfile of Trend Micro HijackThis v2.0.2
                      Scan saved at 18:51:26, on 28/12/2009
                      Platform: Windows XP SP3 (WinNT 5.01.2600)
                      MSIE: Internet Explorer v8.00 (8.00.6001.18702)
                      Boot mode: Normal

                      Running processes:
                      C:\WINDOWS\System32\smss.exe
                      C:\WINDOWS\system32\csrss.exe
                      C:\WINDOWS\system32\winlogon.exe
                      C:\WINDOWS\system32\services.exe
                      C:\WINDOWS\system32\lsass.exe
                      C:\WINDOWS\system32\svchost.exe
                      C:\WINDOWS\system32\svchost.exe
                      C:\Program Files\COMODO\Firewall\cmdagent.exe
                      C:\WINDOWS\system32\svchost.exe
                      C:\WINDOWS\system32\svchost.exe
                      C:\Program Files\Intel\WiFi\bin\S24EvMon.exe
                      C:\WINDOWS\system32\svchost.exe
                      C:\WINDOWS\system32\svchost.exe
                      C:\WINDOWS\Explorer.EXE
                      C:\WINDOWS\system32\spoolsv.exe
                      C:\PROGRA~1\MESSAG~1\StartMessager.exe
                      C:\PROGRA~1\Wanadoo\CnxMon.exe
                      C:\Program Files\Fichiers communs\ArcSoft\Connection Service\Bin\ACDaemon.exe
                      C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
                      C:\Program Files\COMODO\SafeSurf\cssurf.exe
                      C:\Program Files\COMODO\Firewall\cfp.exe
                      C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                      C:\WINDOWS\system32\rundll32.exe
                      C:\Program Files\Intel\WiFi\bin\ZCfgSvc.exe
                      C:\Program Files\Fichiers communs\Intel\WirelessCommon\iFrmewrk.exe
                      C:\WINDOWS\RTHDCPL.EXE
                      C:\WINDOWS\6000RMT.exe
                      C:\WINDOWS\vspc1300.exe
                      C:\Program Files\Java\jre6\bin\jusched.exe
                      C:\Program Files\BboxUpdate\BTLiveUpdate.exe
                      C:\Program Files\iTunes\iTunesHelper.exe
                      C:\WINDOWS\system32\ctfmon.exe
                      C:\Program Files\SuperCopier2\SuperCopier2.exe
                      C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                      C:\Program Files\Fichiers communs\Nero\Lib\NMBgMonitor.exe
                      C:\DOCUME~1\clovis\LOCALS~1\Temp\richtx64.exe
                      C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\AlertModule\2\AlertModule.exe
                      C:\WINDOWS\system32\svchost.exe
                      C:\Program Files\Fichiers communs\ArcSoft\Connection Service\Bin\ACService.exe
                      C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
                      C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                      C:\Program Files\Logitech\SetPoint\SetPoint.exe
                      C:\Program Files\Panasonic\PHOTOfunSTUDIO -viewer-\PhAutoRun.exe
                      C:\Program Files\Philips\Philips SPC1300NC Webcam\TrayMin1300.exe
                      C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
                      C:\Program Files\Fichiers communs\Logishrd\KHAL2\KHALMNPR.EXE
                      C:\Program Files\SpywareGuard\sgmain.exe
                      C:\DOCUME~1\clovis\LOCALS~1\Temp\wscsvc32.exe
                      C:\Program Files\SpywareGuard\sgbhp.exe
                      C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                      C:\Program Files\Bonjour\mDNSResponder.exe
                      C:\Program Files\Home Cinema\PowerCinema\Kernel\TV\CLCapSvc.exe
                      C:\Program Files\Home Cinema\PowerCinema\Kernel\CLML_NTService\CLMLServer.exe
                      C:\Program Files\Intel\WiFi\bin\EvtEng.exe
                      C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
                      C:\WINDOWS\system32\svchost.exe
                      C:\WINDOWS\System32\svchost.exe
                      C:\Program Files\Java\jre6\bin\jqs.exe
                      C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
                      C:\WINDOWS\System32\svchost.exe
                      C:\WINDOWS\system32\nvsvc32.exe
                      C:\WINDOWS\System32\svchost.exe
                      C:\WINDOWS\system32\PnkBstrA.exe
                      C:\WINDOWS\system32\PnkBstrB.exe
                      C:\Program Files\Fichiers communs\Intel\WirelessCommon\RegSrvc.exe
                      C:\Program Files\Cyberlink\Shared files\RichVideo.exe
                      C:\WINDOWS\system32\svchost.exe
                      C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe
                      C:\Program Files\Home Cinema\PowerCinema\Kernel\TV\CLSched.exe
                      C:\Program Files\Windows Media Player\WMPNetwk.exe
                      C:\Program Files\OrangeHSS\systray\systrayapp.exe
                      C:\WINDOWS\system32\wbem\wmiprvse.exe
                      C:\WINDOWS\system32\wbem\unsecapp.exe
                      C:\WINDOWS\system32\wbem\wmiprvse.exe
                      C:\Program Files\Fichiers communs\Nero\Lib\NMIndexingService.exe
                      C:\Program Files\iPod\bin\iPodService.exe
                      C:\Program Files\Fichiers communs\Nero\Lib\NMIndexStoreSvr.exe
                      C:\WINDOWS\system32\wbem\wmiapsrv.exe
                      C:\WINDOWS\System32\alg.exe
                      C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
                      C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe
                      C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe
                      C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                      C:\Program Files\Windows Live\Contacts\wlcomm.exe
                      C:\Program Files\Java\jre6\bin\jucheck.exe
                      C:\Program Files\Mozilla Firefox\firefox.exe
                      C:\Documents and Settings\clovis\Local Settings\Temporary Internet Files\Content.IE5\6SPTB633\RSIT[1].exe
                      C:\WINDOWS\system32\wbem\wmiprvse.exe
                      C:\Program Files\trend micro\clovis.exe
                      C:\Program Files\Internet Explorer\Iexplore.exe
                      C:\Program Files\Internet Explorer\Iexplore.exe

                      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
                      R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
                      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                      R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\Program Files\OrangeHSS\SearchURLHook\SearchPageURL.dll
                      O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
                      O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
                      O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
                      O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
                      O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
                      O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll
                      O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
                      O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
                      O2 - BHO: Ask Toolbar BHO - {F0D4B231-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\AskSBar\bar\1.bin\ASKSBAR.DLL
                      O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                      O3 - Toolbar: Ask Toolbar - {F0D4B239-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\AskSBar\bar\1.bin\ASKSBAR.DLL
                      O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
                      O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
                      O4 - HKLM\..\Run: [DXM6Patch_981116] C:\WINDOWS\p_981116.exe /Q:A
                      O4 - HKLM\..\Run: [MessagerStarter Wanadoo] C:\PROGRA~1\MESSAG~1\StartMessager.exe Messager Wanadoo
                      O4 - HKLM\..\Run: [WooCnxMon] C:\PROGRA~1\Wanadoo\CnxMon.exe
                      O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
                      O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\Wanadoo\TaskbarIcon.exe
                      O4 - HKLM\..\Run: [ArcSoft Connection Service] C:\Program Files\Fichiers communs\ArcSoft\Connection Service\Bin\ACDaemon.exe
                      O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
                      O4 - HKLM\..\Run: [hpqSRMon] C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe
                      O4 - HKLM\..\Run: [COMODO SafeSurf] "C:\Program Files\COMODO\SafeSurf\cssurf.exe" -s
                      O4 - HKLM\..\Run: [COMODO Firewall Pro] "C:\Program Files\COMODO\Firewall\cfp.exe" -h
                      O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
                      O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                      O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
                      O4 - HKLM\..\Run: [COMODO Internet Security] "C:\Program Files\COMODO\Firewall\cfp.exe" -h
                      O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
                      O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\WiFi\bin\ZCfgSvc.exe"
                      O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Fichiers communs\Intel\WirelessCommon\iFrmewrk.exe" /tf Intel Wireless Tray
                      O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
                      O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
                      O4 - HKLM\..\Run: [TV Card Remote Control Device Monitor] C:\WINDOWS\6000RMT.exe
                      O4 - HKLM\..\Run: [SPC1300] C:\WINDOWS\vspc1300.exe
                      O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
                      O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
                      O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
                      O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
                      O4 - HKLM\..\Run: [ORAHSSSessionManager] "C:\Program Files\OrangeHSS\SessionManager\SessionManager.exe"
                      O4 - HKLM\..\Run: [BboxUpdate] C:\Program Files\BboxUpdate\BTLiveUpdate.exe
                      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
                      O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
                      O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
                      O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
                      O4 - HKCU\..\Run: [SuperCopier2.exe] C:\Program Files\SuperCopier2\SuperCopier2.exe
                      O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
                      O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Nero\Lib\NMBgMonitor.exe"
                      O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
                      O4 - HKCU\..\Run: [EPSON Stylus DX8400 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATICEE.EXE /FU "C:\WINDOWS\TEMP\E_SD8.tmp" /EF "HKCU"
                      O4 - HKCU\..\Run: [richtx64.exe] C:\DOCUME~1\clovis\LOCALS~1\Temp\richtx64.exe
                      O4 - HKCU\..\Run: [Malware Defense] "C:\Program Files\Malware Defense\mdefense.exe" -noscan
                      O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                      O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
                      O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
                      O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
                      O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
                      O4 - Startup: OneNote 2007 - Capture d'écran et lancement.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
                      O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
                      O4 - Global Startup: DSLMON.lnk = C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
                      O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                      O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
                      O4 - Global Startup: PHOTOfunSTUDIO -viewer-.lnk = C:\Program Files\Panasonic\PHOTOfunSTUDIO -viewer-\PhAutoRun.exe
                      O4 - Global Startup: SetPointII.lnk = ?
                      O4 - Global Startup: TrayMin1300.lnk = ?
                      O8 - Extra context menu item: &Recherche AOL Toolbar - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
                      O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/menusearch.jhtml?p=ZJfox000
                      O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000
                      O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
                      O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll
                      O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll
                      O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\Office12\REFIEBAR.DLL
                      O9 - Extra button: Organise-notes - {9455301C-CF6B-11D3-A266-00C04F689C50} - C:\Program Files\Fichiers communs\Microsoft Shared\Encarta Researcher\EROPROJ.DLL
                      O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
                      O9 - Extra button: Sélection intelligente HP - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
                      O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
                      O9 - Extra 'Tools' menuitem: Spybot - Search && De
                      1. Contributeur sécurité
                        Salut fatherted

                        Télécharge combofix.exe (de sUBs) sur le bureau :

                        http://download.bleepingcomputer.com/sUBs/ComboFix.exe
                        http://www.geekstogo.com/forum/files/file/197-combofix-by-subs/

                        Important Désactive ton Antivirus et antispyware avant le scan avec Combofix :
                        https://forum.pcastuces.com/default.asp

                        ==> Sauvegarde ton travail et ferme toutes les fenêtres actives, il peut y avoir un redémarrage du PC. Ne lance aucun programme tant que Combofix n’est pas fini. <==

                        Double clique sur combofix.exe, clique sur OUI et valide par Entrée

                        Lorsque le scan sera complété, un rapport apparaîtra. Copie/colle ce rapport dans ta prochaine réponse.

                        NOTE : Le rapport se trouve également ici : C:\Combofix.txt

                        Combofix est détecté par certains antivirus comme une infection, ne pas en tenir compte, il s'agit d'un faux positif, continue la procédure

                        @++ :)
                        • 1
                        • 2