Personal security + téléchargement bloqué

Résolu
Bonjour,

mon PC est infecté depuis 2/3 jours, j'ai réinstallé avast, supprimé et mis en quarantaine certains virus, mais un persiste, le personnal security.
En esaayant de l'éradiquer je me suis rendue compte que mon antispyware (spybot) ne marchait pas. Et en cherchant à en installer un nouveau, je ne parvenais pas à ouvrir le fichier ou à l'executer. Ce qui pose problème, car aucun téléchargement n'aboutit. Pour l'installation de spybot par exemple, le message uivant s'est affiché : "Windows ne parvient pas à accéder au périphérique, au chemin d'accèsou au fichié spécifié. vous ne disposez peut être pas des autorisatins appropriées pour avoir accès à l'élement"
Je ne paviens pas églement à ouvrir des fichiers exécutables tels que word par exemple se trouvant dans la colonne gauche du menu déroulant de "démarrer".
Parrallèlement, je n'ai plus aucune icône sur mon bureau.

en somme : 2 pb
-le personal security qui ouvre des fenêtres intempestives en me disant d'acheter leur protection!
-l'accès aux fichiers qui n'aboutit pas

Merc d'avance
Configuration: Windows XP Internet Explorer 8.0

25 réponses

Résumé de la discussion

Une infection persistante, notamment le logiciel Personal Security, génère des fenêtres intempestives et bloque l'installation de nouveaux outils antivirus sur un PC équipé de Windows XP et IE8. Plusieurs réponses proposent des outils de suppression comme UsbFix, Malwarebytes et HijackThis, avec des procédures impliquant des rapports à envoyer et des redémarrages pour nettoyer les clés et fichiers. Les conseils incluent aussi des précautions liées à des alertes antivirus incomprises, le contrôle des comptes utilisateurs (UAC) et la gestion des autorisations pour régler l'impossibilité d'accéder aux dossiers ou aux exécutables. En parallèle, il est mentionné que certains outils détectés comme Process.exe ou certaines entrées de registre peuvent sembler risqués ou nécessiter une désinfection complète suivie d'un redémarrage.

Bobot (l’IA à votre service)
  1. merci moment de grâce pour ton aide précieuse
    je ne suis désormais plus désormais une bille de l'ordi...mais reste encore bcp de progrès.
    pour la disponibilité et la réactivité...chapeau

    PS : c'est vrai qu'en cherchant....parfois on trouve! ;)
    0
    1. Contributeur sécurité
      tools n'as pas fonctionné

      Télécharge OTC de Old Timer.

      http://www.geekstogo.com/forum/files/file/403-otc-oldtimers-clean-it/

      Clique droit sur OTCleanIt et choisis Exécuter en tant qu'administrateur.
      Clique sur le bouton "CleanUp!" .
      Sélectionne Oui lorsque la demande " processus de nettoyage?" s'affiche.
      Si tu es invité à redémarrer le PC au cours de l'assainissement, sélectionne Oui.
      L'outil va se supprimer lui-même une fois la fin de l'opération.
      Sinon supprime le manuellement.
      0
      1. le processus de nettoyage est fait, par contre, j'ai du éteindre moi même l'ordi

        en ce qui concerne la configuration de antivir, j'ai pourtant comancé à suivre le tuto...mais les fenêtres qui s'ouvraient au fur et à mesure ne correspondaient pas à ce qui y était inscrit! du coup j'ai poursuivi quand même
        0
    2. Contributeur sécurité
      Recherche de Rootkits.........................: arrêt
      tu n'as pas suivi le tuto !

      sélectionnez Mode Expert. Vous serez directement sur le sous-onglet Recherche.
      Cochez les éléments ci-dessous :
      • Fichiers : tous les fichiers (mode paranoïaque)
      • Autres réglages : Recherche rootkits au démarrage de la recherche


      sinon c'est ok
      0
      1. en ce qui concerne l'étape 3 voici le rapport de antivir apres l'avoir installé :

        Avira AntiVir Personal
        Date de création du fichier de rapport : mercredi 13 janvier 2010 23:47

        La recherche porte sur 1284893 souches de virus.

        Détenteur de la licence : Avira AntiVir Personal - FREE Antivirus
        Numéro de série : 0000149996-ADJIE-0000001
        Plateforme : Windows XP
        Version de Windows : (Service Pack 3) [5.1.2600]
        Mode Boot : Démarré normalement
        Identifiant : Delphine
        Nom de l'ordinateur : DELPHINE

        Informations de version :
        BUILD.DAT : 9.0.0.65 17959 Bytes 22/04/2009 12:06:00
        AVSCAN.EXE : 9.0.3.6 466689 Bytes 21/04/2009 13:20:54
        AVSCAN.DLL : 9.0.3.0 49409 Bytes 03/03/2009 10:21:02
        LUKE.DLL : 9.0.3.2 209665 Bytes 20/02/2009 11:35:11
        LUKERES.DLL : 9.0.2.0 13569 Bytes 03/03/2009 10:21:31
        ANTIVIR0.VDF : 7.1.0.0 15603712 Bytes 27/10/2008 12:30:36
        ANTIVIR1.VDF : 7.1.2.12 3336192 Bytes 11/02/2009 20:33:26
        ANTIVIR2.VDF : 7.1.2.105 513536 Bytes 03/03/2009 07:41:14
        ANTIVIR3.VDF : 7.1.2.127 110592 Bytes 05/03/2009 14:58:20
        Version du moteur : 8.2.0.100
        AEVDF.DLL : 8.1.1.0 106868 Bytes 27/01/2009 17:36:42
        AESCRIPT.DLL : 8.1.1.56 352634 Bytes 26/02/2009 20:01:56
        AESCN.DLL : 8.1.1.7 127347 Bytes 12/02/2009 11:44:25
        AERDL.DLL : 8.1.1.3 438645 Bytes 29/10/2008 18:24:41
        AEPACK.DLL : 8.1.3.10 397686 Bytes 04/03/2009 13:06:10
        AEOFFICE.DLL : 8.1.0.36 196987 Bytes 26/02/2009 20:01:56
        AEHEUR.DLL : 8.1.0.100 1618295 Bytes 25/02/2009 15:49:16
        AEHELP.DLL : 8.1.2.2 119158 Bytes 26/02/2009 20:01:56
        AEGEN.DLL : 8.1.1.24 336244 Bytes 04/03/2009 13:06:10
        AEEMU.DLL : 8.1.0.9 393588 Bytes 09/10/2008 14:32:40
        AECORE.DLL : 8.1.6.6 176501 Bytes 17/02/2009 14:22:44
        AEBB.DLL : 8.1.0.3 53618 Bytes 09/10/2008 14:32:40
        AVWINLL.DLL : 9.0.0.3 18177 Bytes 12/12/2008 08:47:30
        AVPREF.DLL : 9.0.0.1 43777 Bytes 03/12/2008 11:39:26
        AVREP.DLL : 8.0.0.3 155905 Bytes 20/01/2009 14:34:28
        AVREG.DLL : 9.0.0.0 36609 Bytes 07/11/2008 15:24:42
        AVARKT.DLL : 9.0.0.3 292609 Bytes 24/03/2009 15:05:22
        AVEVTLOG.DLL : 9.0.0.7 167169 Bytes 30/01/2009 10:36:37
        SQLITE3.DLL : 3.6.1.0 326401 Bytes 28/01/2009 15:03:49
        SMTPLIB.DLL : 9.2.0.25 28417 Bytes 02/02/2009 08:20:57
        NETNT.DLL : 9.0.0.0 11521 Bytes 07/11/2008 15:40:59
        RCIMAGE.DLL : 9.0.0.21 2438401 Bytes 17/02/2009 13:49:32
        RCTEXT.DLL : 9.0.37.0 88321 Bytes 15/04/2009 10:07:05

        Configuration pour la recherche actuelle :
        Nom de la tâche...............................: Bref contrôle système après installation
        Fichier de configuration......................: c:\program files\avira\antivir desktop\setupprf.dat
        Documentation.................................: bas
        Action principale.............................: interactif
        Action secondaire.............................: ignorer
        Recherche sur les secteurs d'amorçage maître..: marche
        Recherche sur les secteurs d'amorçage.........: marche
        Recherche dans les programmes actifs..........: marche
        Recherche en cours sur l'enregistrement.......: marche
        Recherche de Rootkits.........................: arrêt
        Contrôle d'intégrité de fichiers système......: arrêt
        Fichier mode de recherche.....................: Sélection de fichiers intelligente
        Recherche sur les archives....................: marche
        Limiter la profondeur de récursivité..........: 20
        Archive Smart Extensions......................: marche
        Heuristique de macrovirus.....................: marche
        Heuristique fichier...........................: élevé
        Catégories de dangers divergentes.............: +APPL,+GAME,+JOKE,+PCK,+SPR,

        Début de la recherche : mercredi 13 janvier 2010 23:47

        La recherche sur les processus démarrés commence :
        Processus de recherche 'avscan.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'avconfig.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'avgnt.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'sched.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'avguard.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'Update.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'setup.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'presetup.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'avira_antivir_personal_free.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'iexplore.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'iexplore.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'iexplore.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'iexplore.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'BDTUpdateService.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'pctsTray.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'pctsSvc.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'pctsAuxs.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'wscntfy.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'SSScheduler.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'ctfmon.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'rundll32.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'GoogleToolbarNotifier.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'iexplore.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'wuauclt.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'explorer.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'alg.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'ULCDRSvr.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'svchost.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'HPZipm12.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'AluSchedulerSvc.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'mdm.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'LSSrvc.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'CDANTSRV.EXE' - '1' module(s) sont contrôlés
        Processus de recherche 'svchost.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'spoolsv.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'ati2evxx.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'ashServ.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'svchost.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'svchost.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'svchost.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'svchost.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'svchost.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'svchost.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'ati2evxx.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'lsass.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'services.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'winlogon.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'csrss.exe' - '1' module(s) sont contrôlés
        Processus de recherche 'smss.exe' - '1' module(s) sont contrôlés
        '49' processus ont été contrôlés avec '49' modules

        La recherche sur les secteurs d'amorçage maître commence :
        Secteur d'amorçage maître HD0
        [INFO] Aucun virus trouvé !
        Secteur d'amorçage maître HD1
        [INFO] Aucun virus trouvé !
        Secteur d'amorçage maître HD2
        [INFO] Aucun virus trouvé !

        La recherche sur les secteurs d'amorçage commence :

        La recherche sur les renvois aux fichiers exécutables (registre) commence :
        Le registre a été contrôlé ( '49' fichiers).

        Fin de la recherche : mercredi 13 janvier 2010 23:48
        Temps nécessaire: 00:48 Minute(s)

        La recherche a été effectuée intégralement

        0 Les répertoires ont été contrôlés
        463 Des fichiers ont été contrôlés
        0 Des virus ou programmes indésirables ont été trouvés
        0 Des fichiers ont été classés comme suspects
        0 Des fichiers ont été supprimés
        0 Des virus ou programmes indésirables ont été réparés
        0 Les fichiers ont été déplacés dans la quarantaine
        0 Les fichiers ont été renommés
        0 Impossible de contrôler des fichiers
        463 Fichiers non infectés
        3 Les archives ont été contrôlées
        0 Avertissements
        0 Consignes
        0
        1. Contributeur sécurité
          oui il est gratuit bien qu'il existe une version complete payante

          prends la gratuite comme nous tous
          0
          1. en cliquant dessus ca m'a renvoyé à spyware doctor antivirus...est ce normal?
            0
        2. Contributeur sécurité
          1)
          Cherches et cliques sur C:\Program Files\trend micro\Delphine.exe
          Au menu principal, choisir do a scan only, puis cocher la case devant les lignes suivantes à corriger et cliquer en bas sur Fix Checked

          O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
          O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
          O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
          O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
          O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')

          ……………………..

          2)
          Mets à jour Adobe Reader si ce n'est pas le cas (désinstalle avant la version antérieure)
          https://get2.adobe.com/reader/otherversions/

          ………….

          3)
          Désinstaller avast et les restes de norton

          https://www.commentcamarche.net/telecharger/securite/22859-utilitaire-de-desinstallation-de-avast/
          https://www.commentcamarche.net/faq/2453-supprimer-desinstaller-norton-antivirus-norton-internet-security

          Installer antivir

          http://www.commentcamarche.net/telecharger/telecharger-55-antivir

          et le configurer

          https://kerio.probb.fr/t3106-tuto-antivir-antivirus-version-franaise

          ……………………….

          4)
          IMPORTANT

          Purger la restauration systeme XP

          http://www.bibou0007.com/windows-xp-f101/purger-la-restauration-du-systeme-sous-windows-xp-t151.htm

          ……………..

          5)
          Télécharge ToolsCleaner2sur ton Bureau.
          https://www.commentcamarche.net/telecharger/securite/22061-toolscleaner/

          * Double-clique (clic droit "en tant qu'administrateur" pour Vista) sur ToolsCleaner2.exe pour le lancer.
          * Clique sur Recherche et laisse le scan agir.
          * Clique sur Suppression pour finaliser.
          * Tu peux, si tu le souhaites, te servir des Options Facultatives.
          * Clique sur Quitter pour obtenir le rapport.
          * Poste le rapport (TCleaner.txt) qui se trouve à la racine de ton disque dur (C:\).

          Tu peux supprimer ToolCleaner ensuite

          0
          1. antivir n'est pas gratuit?!
            0
          2. le rapport toolclean :

            [ Rapport ToolsCleaner version 2.3.11 (par A.Rothstein & dj QUIOU) ]

            --> Recherche:

            C:\Combofix.txt: trouvé !
            C:\UsbFix.txt: trouvé !
            C:\Qoobox: trouvé !
            C:\UsbFix: trouvé !
            C:\Rsit: trouvé !
            C:\Documents and Settings\Delphine\Bureau\UsbFix.exe: trouvé !
            C:\Documents and Settings\Delphine\Bureau\Rsit.exe: trouvé !
            C:\MDG\Combofix.txt: trouvé !
            C:\Program Files\trend micro\HijackThis.exe: trouvé !
            C:\Program Files\trend micro\hijackthis.log: trouvé !
            C:\Qoobox\Quarantine\catchme.log: trouvé !
            C:\WINDOWS\mbr.exe: trouvé !

            ---------------------------------
            --> Suppression:

            C:\Program Files\trend micro\HijackThis.exe: supprimé !
            C:\Combofix.txt: supprimé !
            C:\UsbFix.txt: supprimé !
            C:\Documents and Settings\Delphine\Bureau\UsbFix.exe: supprimé !
            C:\Documents and Settings\Delphine\Bureau\Rsit.exe: supprimé !
            C:\MDG\Combofix.txt: supprimé !
            C:\Program Files\trend micro\hijackthis.log: supprimé !
            C:\Qoobox\Quarantine\catchme.log: supprimé !
            C:\WINDOWS\mbr.exe: supprimé !
            C:\Qoobox: supprimé !
            C:\UsbFix: ERREUR DE SUPPRESSION !!
            C:\Rsit: supprimé !

            Fichiers temporaires nettoyés !
            Corbeille vidée!
            0
        3. Contributeur sécurité
          je m'en occupe

          restes là
          0
          1. Contributeur sécurité
            le rapport est bien

            sauf que tu as fait l'option 1 d'usbfix au lieu de la 2 comme demandé

            donc

            ● Relance UsbFix

            ● Dans le menu principale cette fois choisit l'option2

            Le menu démarrer et les icônes vont à nouveau disparaître.. c'est normal.

            Si un message te demande de redémarrer l'ordinateur fais le ...

            ● Au redémarrage, le fix se relance... laisses l'opération s'effectuer.

            ● Le bloc note s'ouvre avec un rapport, envoies le dans la prochaine réponse

            UsbFix peut te demander d'uploader un dossier compressé à cette adresse : https://www.ionos.fr/?affiliate_id=77097

            Il est enregistré sur ton bureau.

            Merci de l'envoyer à l'adresse indiquée afin d'aider l'auteur de UsbFix dans ses recherches.

            Merci

            apres ca, tu me dis comment va le pc--

            Je cherche beaucoup...et maintenant je trouve ! 
            (sourire)
            0
            1. j'ai envoyé le fichier compressé à l'auteur de usbfix, et voici le rapport :

              ############################## | UsbFix V6.073 |

              User : Delphine (Administrateurs) # DELPHINE
              Update on 09/01/2010 by El Desaparecido , C_XX & Chimay8
              Start at: 21:52:27 | 13/01/2010
              Website : http://pagesperso-orange.fr/NosTools/index.html
              Contact : FindyKill.Contact@gmail.com

              AMD Sempron(tm) Processor 3200+
              Microsoft Windows XP Édition familiale (5.1.2600 32-bit) # Service Pack 3
              Internet Explorer 8.0.6001.18702
              Windows Firewall Status : Enabled
              AV : avast! antivirus 4.8.1368 [VPS 100113-0] 4.8.1368 [ Enabled | Updated ]

              C:\ -> Disque fixe local # 55,88 Go (16,15 Go free) # NTFS
              D:\ -> Disque CD-ROM
              E:\ -> Disque amovible # 3,61 Go (172,09 Mo free) [CLÉ 09-10] # FAT32
              F:\ -> Disque amovible # 1,89 Go (2,97 Mo free) [UDISK 2.0] # FAT
              G:\ -> Disque amovible # 1,88 Go (217,25 Mo free) [CLÉ 08-09] # FAT32
              H:\ -> Disque amovible # 983,72 Mo (245,19 Mo free) [CLÉ 07-08] # FAT

              ############################## | Processus actifs |

              C:\WINDOWS\System32\smss.exe 572
              C:\WINDOWS\system32\csrss.exe 636
              C:\WINDOWS\system32\winlogon.exe 660
              C:\WINDOWS\system32\services.exe 712
              C:\WINDOWS\system32\lsass.exe 724
              C:\WINDOWS\system32\Ati2evxx.exe 868
              C:\WINDOWS\system32\svchost.exe 888
              C:\WINDOWS\system32\svchost.exe 1004
              C:\WINDOWS\System32\svchost.exe 1056
              C:\WINDOWS\system32\svchost.exe 1092
              C:\WINDOWS\system32\svchost.exe 1296
              C:\WINDOWS\system32\svchost.exe 1344
              C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe 1572
              C:\Program Files\Alwil Software\Avast4\ashServ.exe 1628
              C:\WINDOWS\system32\Ati2evxx.exe 1908
              C:\WINDOWS\Explorer.EXE 1984
              C:\WINDOWS\system32\spoolsv.exe 1888
              C:\Program Files\Alwil Software\Avast4\setup\avast.setup 172
              C:\WINDOWS\system32\svchost.exe 1184
              C:\WINDOWS\system32\DRIVERS\CDANTSRV.EXE 1220
              C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe 1268
              C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe 1148
              C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe 1380
              C:\WINDOWS\system32\HPZipm12.exe 1440
              C:\WINDOWS\system32\svchost.exe 1472
              C:\Program Files\Fichiers communs\Ulead Systems\DVD\ULCDRSvr.exe 1852
              C:\WINDOWS\system32\wuauclt.exe 404
              C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe 904
              C:\Program Files\Alwil Software\Avast4\ashWebSv.exe 824
              C:\WINDOWS\system32\wbem\wmiprvse.exe 1508
              C:\WINDOWS\System32\alg.exe 2200
              C:\WINDOWS\system32\wbem\wmiprvse.exe 2248

              ################## | Elements infectieux |

              Supprimé ! C:\Recycler\S-1-5-21-2553885343-4160726450-2658981467-1006
              E:\autorun.inf -> fichier appelé : "E:\vtchpk.exe" ( Absent ! )
              E:\autorun.inf -> fichier appelé : "E:\vtchpk.exe" ( Absent ! )
              Supprimé ! E:\autorun.inf
              F:\autorun.inf -> fichier appelé : "F:\vtchpk.exe" ( Absent ! )
              F:\autorun.inf -> fichier appelé : "F:\vtchpk.exe" ( Absent ! )
              Supprimé ! F:\autorun.inf
              G:\autorun.inf -> fichier appelé : "G:\vtchpk.exe" ( Absent ! )
              G:\autorun.inf -> fichier appelé : "G:\vtchpk.exe" ( Absent ! )
              Supprimé ! G:\autorun.inf
              Supprimé ! H:\Recycler\S-1-6-22-4564031308-1609158761-021649731-2350

              ################## | Registre |

              Supprimé ! [HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System] "DisableRegistryTools"
              Supprimé ! [HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer] "NoDrives"
              Supprimé ! [HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer] "NoDrives"

              ################## | Mountpoints2 |

              Supprimé ! HKCU\...\Explorer\MountPoints2\{200a4f58-a024-11db-8a6c-0014a529f1cf}\Shell\Auto\Command
              Supprimé ! HKCU\...\Explorer\MountPoints2\{246e8b63-f0d0-11db-8a99-0014a529f1cf}\Shell\Auto\Command
              Supprimé ! HKCU\...\Explorer\MountPoints2\{7bfe60e6-fe48-11de-8bad-0014a529f1cf}\Shell\AutoRun\Command
              Supprimé ! HKCU\...\Explorer\MountPoints2\{9612e14f-f805-11db-8a9f-0014a529f1cf}\Shell\Auto\Command
              Supprimé ! HKCU\...\Explorer\MountPoints2\{a22c269e-f3dc-11db-8a9d-0014a529f1cf}\Shell\Auto\Command
              Supprimé ! HKCU\...\Explorer\MountPoints2\{d7f2e720-3b7e-11db-9b47-0014a529f1cf}\Shell\AutoRun\Command
              Supprimé ! HKCU\...\Explorer\MountPoints2\{e68bd072-f9f4-11dc-8b08-0014a529f1cf}\Shell\AutoRun\Command
              Supprimé ! HKCU\...\Explorer\MountPoints2\{e88290de-ef17-11db-8a98-0014a529f1cf}\Shell\Auto\Command
              Supprimé ! HKCU\...\Explorer\MountPoints2\{ec7c3b36-4bbb-11db-9b56-0014a529f1cf}\Shell\Auto\Command
              Supprimé ! HKCU\...\Explorer\MountPoints2\{f80dde29-e78d-11db-8a90-0014a529f1cf}\Shell\Auto\Command

              ################## | Listing des fichiers présent |

              [26/10/2009 00:15|-rahs----|216] C:\boot.ini
              [05/08/2004 09:00|-rahs----|4952] C:\Bootfont.bin
              [29/05/2008 11:40|--a------|2914296] C:\ccsetup208.exe
              [13/01/2010 16:39|--a------|21992] C:\ComboFix.txt
              [28/10/2004 10:08|--a------|10647] C:\diagtt.zip
              [28/10/2004 10:10|--a------|519407] C:\ExcelFond2.0.zip
              [28/10/2004 10:10|--a------|5048] C:\Fiche comportement.zip
              [13/10/2006 22:09|-rahs----|0] C:\IO.SYS
              [13/10/2006 22:09|-rahs----|0] C:\MSDOS.SYS
              [06/11/2007 00:18|--a------|445584] C:\msgr9fr.exe
              [28/10/2004 10:12|--a------|270657] C:\muscles.zip
              [05/08/2004 09:00|-rahs----|47564] C:\ntdetect.com
              [28/05/2009 16:57|-rahs----|252240] C:\ntldr
              [29/02/2004 16:44|--a------|52576] C:\orange.bmp
              [?|?|?] C:\pagefile.sys
              [23/01/2005 10:58|--a------|5923] C:\pocket leger.zip
              [02/10/2008 06:25|--a------|10526] C:\RECUP.DOC
              [15/01/2009 20:58|--a------|2109] C:\RECUP1.DOC
              [28/10/2004 10:12|--a------|11170] C:\reglestt.zip
              [30/11/2001 18:37|--a------|11811416] C:\rp505fra.exe
              [25/11/2003 16:51|--a------|4793856] C:\s3a01frx.exe
              [13/01/2010 21:59|--a------|5608] C:\UsbFix.txt
              [28/10/2004 10:13|--a------|40250] C:\volley.zip
              [28/10/2007 04:46|--a------|2402832] C:\WLinstaller.exe
              [26/06/2008 00:55|--a------|3466] C:\xscan.txt
              [22/01/1998 23:54|--a------|290733] C:\_INST32I.EX_
              [02/09/2009 11:51|--a------|29696] E:\REGLEMENT EPS 09-10.doc
              [02/09/2009 12:28|--a------|30208] E:\questionnaire de rentr‚e 09-10.doc
              [02/09/2009 14:59|--a------|73728] E:\planning d'utilisation des salles.doc
              [30/08/2009 12:44|--a------|198209] E:\abonnement-eps-2009.pdf
              [23/09/2009 15:17|--a------|36864] E:\exploitation possible du questionnaire.doc
              [18/11/2009 17:01|--a------|30720] E:\APPRECIATIONS TYPES 1ER TRIMESTRE.doc
              [24/11/2009 12:40|--a------|42496] E:\cahier de texte MODELE.doc
              [25/11/2009 15:16|--a------|30720] E:\commande EPS.doc
              [25/11/2009 17:53|--a------|44544] E:\musiques EPS.xls
              [27/11/2008 20:28|--a------|1626] G:\BOOTEX.LOG
              [08/03/2009 12:42|--ah-----|4096] G:\._.Trashes
              [21/01/2008 13:35|--a------|24576] G:\Il ‚tait une fois.doc
              [23/01/2009 09:40|--a------|32768] G:\modŠle cahier de texte.doc
              [09/02/2009 14:07|--a------|1027664] G:\thŠse-l'‚cole au corps.pdf
              [12/05/2009 20:02|--a------|82487] G:\Bulletin officiel nø 29 du 20 juillet 2006.webarchive
              [26/05/2009 15:54|--a------|23250] G:\pekin express.pdf
              [08/03/2009 12:53|--a------|1451454] G:\37 piscines … Paris - Paris.fr.webarchive
              [08/03/2009 12:53|--ah-----|82] G:\._37 piscines … Paris - Paris.fr.webarchive
              [12/05/2009 20:00|--a------|44544] G:\LE SOCLE COMMUN DE CONNAISSANCES ET DE COMPETENCESÿ.doc
              [12/05/2009 20:00|--ah-----|82] G:\._LE SOCLE COMMUN DE CONNAISSANCES ET DE COMPETENCESÿ.doc
              [12/05/2009 20:02|--ah-----|82] G:\._Bulletin officiel nø 29 du 20 juillet 2006.webarchive
              [17/05/2009 15:48|--ah-----|12292] G:\.DS_Store
              [11/06/2009 11:10|--a------|54784] G:\gaysetsenegalais.textefinal
              [12/10/2008 12:17|--ah-----|12292] H:\.DS_Store
              [22/08/2008 22:30|--a------|1620] H:\BOOTEX.LOG
              [04/12/2004 21:56|--a------|836563] H:\basket.exe
              [25/08/2008 10:13|--ah-----|4096] H:\._.Trashes
              [25/08/2008 10:18|--ah-----|82] H:\._AIP2008.pdf
              [25/08/2008 10:14|--ah-----|82] H:\._formulaireCV2008.pdf
              [11/10/2008 09:23|--a------|40740] H:\Caisse Regionale du FinistŠre.webarchive
              [18/03/2008 16:20|--a------|1965] H:\header.htm
              [11/10/2008 09:23|--ah-----|82] H:\._Caisse Regionale du FinistŠre.webarchive

              ################## | Vaccination |

              # C:\autorun.inf -> Dossier créé par UsbFix.
              # E:\autorun.inf -> Dossier créé par UsbFix.
              # F:\autorun.inf -> Dossier créé par UsbFix.
              # G:\autorun.inf -> Dossier créé par UsbFix.
              # H:\autorun.inf -> Dossier créé par UsbFix.

              ################## | Crack > Keygen > Serial |

              ################## | Upload |

              Veuillez envoyer le fichier : C:\DOCUME~1\Delphine\Bureau\UsbFix_Upload_Me_DELPHINE.zip : https://www.ionos.fr/?affiliate_id=77097
              Merci pour votre contribution .

              ...et je regarde comment va le PC!
              0
            2. @labilledelordiben écoue, j'ai l'impression que ça fonctionne plutot bien
              je peux accéder au net via google chrome et fire fox, word...
              ça va bien plus vite
              ...et plus de personal security intempestive!

              Suis-je maintenant bien couverte, bien protogée par ls logiciels de sécu, avast en anti virus, malware en anti spywares
              enfin, peut être faut il que je fasse un peu de nettoyage; tout ce que j'ai pu télécharger depuis la maintenance, dois-je le conserver?
              0
          2. Contributeur sécurité
            t'inquiètes, ca se présentes bien, tu peux vider la quarantaine

            comment va le pc ?

            • Télécharge Random's System Information Tool (RSIT) de Random/Random.

            http://images.malwareremoval.com/random/RSIT.exe

            • Enregistre le sur ton Bureau.

            • Double clique sur RSIT.exe pour lancer l'outil.

            • Clique sur "Continue" à l'écran Disclaimer.

            • Si l'outil HijackThis n'est pas présent ou non détecté sur l'ordinateur, RSIT le téléchargera (autorise l'accès dans ton pare-feu s'il te le demande)

            et tu devras accepter la licence.

            • Une fois le scan terminé, deux rapports vont apparaître : poste les dans deux messages séparés stp

            Les rapports se trouvent à cet endroit:
            C:\rsit\info.txt
            C:\rsit\log.txt
            0
            1. voilà pour le premier :

              info.txt logfile of random's system information tool 1.06 2010-01-13 21:34:16

              ======Uninstall list======

              -->C:\Program Files\Nero\Nero 7\nero\uninstall\UNNERO.exe /UNINSTALL
              -->C:\WINDOWS\IsUn040c.exe -fC:\WINDOWS\orun32.isu
              -->C:\WINDOWS\system32\\MSIEXEC.EXE /x {075473F5-846A-448B-BCB3-104AA1760205}
              -->C:\WINDOWS\system32\\MSIEXEC.EXE /x {AB708C9B-97C8-4AC9-899B-DBF226AC9382}
              -->C:\WINDOWS\system32\\MSIEXEC.EXE /x {B12665F4-4E93-4AB4-B7FC-37053B524629}
              -->C:\WINDOWS\UNNeroBackItUp.exe /UNINSTALL
              -->C:\WINDOWS\UNNeroMediaHome.exe /UNINSTALL
              -->C:\WINDOWS\UNNeroShowTime.exe /UNINSTALL
              -->C:\WINDOWS\UNNeroVision.exe /UNINSTALL
              -->C:\WINDOWS\UNRecode.exe /UNINSTALL
              -->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
              µTorrent-->"C:\Program Files\uTorrent\uTorrent.exe" /UNINSTALL
              Adobe Acrobat 5.0-->C:\WINDOWS\ISUN040C.EXE -f"C:\Program Files\Fichiers communs\Adobe\Acrobat 5.0\NT\Uninst.isu" -c"C:\Program Files\Fichiers communs\Adobe\Acrobat 5.0\NT\Uninst.dll"
              Adobe Flash Player 10 Plugin-->C:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe
              Adobe Flash Player ActiveX-->C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
              AIDA32 v3.93-->"C:\Program Files\AIDA32 - Personal System Information\unins000.exe"
              Apple Software Update-->MsiExec.exe /I{6956856F-B6B3-4BE0-BA0B-8F495BE32033}
              Archiveur WinRAR-->C:\Program Files\WinRAR\uninstall.exe
              Athlon 64 Processor Driver-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{C151CE54-E7EA-4804-854B-F515368B0798}\setup.exe" -l0x40c
              ATI Control Panel-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{0BEDBD4E-2D34-47B5-9973-57E62B29307C}\setup.exe"
              ATI Display Driver-->rundll32 C:\WINDOWS\system32\atiiiexx.dll,_InfEngUnInstallINFFile_RunDLL@16 -force_restart -flags:0x2010001 -inf_class:DISPLAY -clean
              avast! Antivirus-->C:\Program Files\Alwil Software\Avast4\aswRunDll.exe "C:\Program Files\Alwil Software\Avast4\Setup\setiface.dll",RunSetup
              Canon MP Navigator 3.0-->"C:\Program Files\Canon\MP Navigator 3.0\Maint.exe" /UninstallRemove C:\Program Files\Canon\MP Navigator 3.0\uninst.ini
              Canon MP160-->"C:\WINDOWS\system32\CanonIJ Uninstaller Information\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MP160\DelDrv.exe" /U:{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MP160 /L0x000c
              Canon PhotoRecord-->C:\WINDOWS\IsUn040c.exe -f"C:\Program Files\Canon\PhotoRecord\Uninst.isu" -c"C:\Program Files\Canon\PhotoRecord\Program\uninstdll.dll"
              Canon PIXMA iP3000-->C:\WINDOWS\system32\CNMCP61.exe "-PRINTERNAMECanon PIXMA iP3000" "-HELPERDLLC:\BJPrinter\CNMWINDOWS\Canon PIXMA iP3000 Installer\Inst2\cnmis.dll" "-RCDLLC:\BJPrinter\CNMWINDOWS\Canon PIXMA iP3000 Installer\Inst2\cnmi040c.dll"
              Canon PowerShot A40 WIA Driver-->C:\WINDOWS\IsUn040c.exe -f"C:\Program Files\Canon\PowerShot A40 WIA\Uninst.isu" -c"C:\Program Files\Canon\PowerShot A40 WIA\UNSTD113.dll"
              Canon Utilities Easy-PhotoPrint-->C:\Program Files\Canon\Easy-PhotoPrint\uninst.exe uninst.ini
              Canon Utilities PhotoStitch 3.1-->C:\WINDOWS\IsUn040c.exe -f"C:\Program Files\Canon\PhotoStitch\Uninst.isu"
              Canon Utilities RAW Image Converter-->C:\WINDOWS\IsUn040c.exe -f"C:\Program Files\Canon\RAW Image Converter\Uninst.isu"
              Canon Utilities RemoteCapture 2.2-->C:\WINDOWS\IsUn040c.exe -f"C:\Program Files\Canon\RemoteCapture\Uninst.isu"
              Canon Utilities RemoteCapture 2.7-->C:\PROGRA~1\FICHIE~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{14220DB1-DD96-4BCD-B3D5-03A4EA6631C4} /x
              Canon Utilities ZoomBrowser EX-->C:\WINDOWS\IsUn040c.exe -f"C:\Program Files\Canon\ZoomBrowser EX\Uninst.isu" -c"C:\Program Files\Canon\ZoomBrowser EX\Program\uninstallutilities.dll"
              CanoScan Toolbox 4.1-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{BCE46757-7674-4416-BEDB-68205A60409E}\Setup.exe" -l0x40c anything
              CARNET-->C:\WINDOWS\IsUn040c.exe -f"C:\Program Files\Carnet\Carnet.isu"
              CCleaner (remove only)-->"C:\Program Files\CCleaner\uninst.exe"
              C-Dilla Licence Management System-->C:\C_DILLA\setup\cdunin16.exe
              Compaq Presario r4000 User Guides-->C:\PROGRA~1\CPQ\UNWISE.EXE C:\PROGRA~1\CPQ\INSTALL.LOG
              Conexant AC-Link Audio-->CIAunwdm.exe
              Correctif pour Lecteur Windows Media 11 (KB939683)-->"C:\WINDOWS\$NtUninstallKB939683$\spuninst\spuninst.exe"
              Correctif pour Windows Internet Explorer 7 (KB947864)-->"C:\WINDOWS\ie7updates\KB947864-IE7\spuninst\spuninst.exe"
              Correctif pour Windows XP (KB952287)-->"C:\WINDOWS\$NtUninstallKB952287$\spuninst\spuninst.exe"
              Correctif pour Windows XP (KB970653-v3)-->"C:\WINDOWS\$NtUninstallKB970653-v3$\spuninst\spuninst.exe"
              Correctif pour Windows XP (KB976098-v2)-->"C:\WINDOWS\$NtUninstallKB976098-v2$\spuninst\spuninst.exe"
              Data Fax SoftModem with SmartCP-->C:\Program Files\CONEXANT\CNXT_MODEM_PCI_VEN_1002&DEV_4378&SUBSYS_3085103C\HXFSETUP.EXE -U -Icpl30855.inf
              Easy-WebPrint-->C:\WINDOWS\IsUn040c.exe -f"C:\Program Files\Canon\Easy-WebPrint\Uninst.isu"
              Enregistrement utilisateur de Canon MP160-->C:\Program Files\Canon\IJEREG\MP160\UNINST.EXE
              Google Toolbar for Internet Explorer-->regsvr32 /u /s "c:\program files\google\googletoolbar3.dll"
              HijackThis 2.0.2-->"C:\Program Files\trend micro\HijackThis.exe" /uninstall
              Hotfix for Windows Media Format 11 SDK (KB929399)-->"C:\WINDOWS\$NtUninstallKB929399$\spuninst\spuninst.exe"
              HP Help and Support-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\10\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{A93C4E94-1005-489D-BEAA-B873C1AA6CFC}\setup.exe" -l0x40c -removeonly
              HP Software Update-->MsiExec.exe /X{15EE79F4-4ED1-4267-9B0F-351009325D7D}
              HP Wireless Assistant 1.01 A3-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{4302B2DD-D958-40E3-BAF3-B07FFE1978CE}\setup.exe" -l0x40c hpquninst
              Indeo® software-->C:\WINDOWS\IsUninst.exe -f"C:\Program Files\Intel\Indeo\Uninst.isu" -c"C:\Program Files\Intel\Indeo\SavedSystemFiles\indounin.dll"
              InterVideo WinDVD-->"C:\Program Files\InstallShield Installation Information\{91810AFC-A4F8-4EBA-A5AA-B198BBC81144}\setup.exe" REMOVEALL
              iTunes-->MsiExec.exe /I{885894A5-BA0A-460E-AB4C-96C5C9B2C5E2}
              J2SE Runtime Environment 5.0 Update 2-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0150020}
              L&H TTS3000 Français-->RunDll32 advpack.dll,LaunchINFSection C:\WINDOWS\INF\LHTTSFRF.inf, Uninstall
              Lecteur Windows Media 11-->"C:\Program Files\Windows Media Player\Setup_wm.exe" /Uninstall
              LiveUpdate 3.0 (Symantec Corporation)-->"C:\Program Files\Symantec\LiveUpdate\LSETUP.EXE" /U
              Macromedia Shockwave Player-->C:\WINDOWS\system32\Macromed\SHOCKW~1\UNWISE.EXE C:\WINDOWS\system32\Macromed\SHOCKW~1\Install.log
              Malwarebytes' Anti-Malware-->"C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
              Microsoft .NET Framework 1.1 French Language Pack-->MsiExec.exe /X{9A394342-4A68-4EBA-85A6-55B559F4E700}
              Microsoft .NET Framework 1.1 Security Update (KB953297)-->"C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\hotfix.exe" "C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\M953297\M953297Uninstall.msp"
              Microsoft .NET Framework 1.1-->msiexec.exe /X {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
              Microsoft .NET Framework 1.1-->MsiExec.exe /X{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
              Microsoft Compression Client Pack 1.0 for Windows XP-->"C:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe"
              Microsoft Internationalized Domain Names Mitigation APIs-->"C:\WINDOWS\$NtServicePackUninstallIDNMitigationAPIs$\spuninst\spuninst.exe"
              Microsoft National Language Support Downlevel APIs-->"C:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$\spuninst\spuninst.exe"
              Microsoft Office 2000 Premium-->MsiExec.exe /I{0000040C-78E1-11D2-B60F-006097C998E7}
              Microsoft Office Standard Edition 2003-->MsiExec.exe /I{9012040C-6000-11D3-8CFE-0150048383C9}
              Microsoft User-Mode Driver Framework Feature Pack 1.0-->"C:\WINDOWS\$NtUninstallWudf01000$\spuninst\spuninst.exe"
              Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053-->MsiExec.exe /X{770657D0-A123-3C07-8E44-1C83EC895118}
              Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
              Mise à jour critique pour Lecteur Windows Media 11 (KB959772)-->"C:\WINDOWS\$NtUninstallKB959772_WM11$\spuninst\spuninst.exe"
              Mise à jour de sécurité pour Lecteur Windows Media (KB952069)-->"C:\WINDOWS\$NtUninstallKB952069_WM9$\spuninst\spuninst.exe"
              Mise à jour de sécurité pour Lecteur Windows Media (KB954155)-->"C:\WINDOWS\$NtUninstallKB954155_WM9$\spuninst\spuninst.exe"
              Mise à jour de sécurité pour Lecteur Windows Media (KB968816)-->"C:\WINDOWS\$NtUninstallKB968816_WM9$\spuninst\spuninst.exe"
              Mise à jour de sécurité pour Lecteur Windows Media (KB973540)-->"C:\WINDOWS\$NtUninstallKB973540_WM9$\spuninst\spuninst.exe"
              Mise à jour de sécurité pour Lecteur Windows Media 10 (KB917734)-->"C:\WINDOWS\$NtUninstallKB917734_WMP10$\spuninst\spuninst.exe"
              Mise à jour de sécurité pour Lecteur Windows Media 11 (KB936782)-->"C:\WINDOWS\$NtUninstallKB936782_WMP11$\spuninst\spuninst.exe"
              Mise à jour de sécurité pour Lecteur Windows Media 11 (KB954154)-->"C:\WINDOWS\$NtUninstallKB954154_WM11$\spuninst\spuninst.exe"
              Mise à jour de sécurité pour Step by Step Interactive Training (KB898458)-->"C:\WINDOWS\$NtUninstallKB898458$\spuninst\spuninst.exe"
              Mise à jour de sécurité pour Step by Step Interactive Training (KB923723)-->"C:\WINDOWS\$NtUninstallKB923723$\spuninst\spuninst.exe"
              Mise à jour de sécurité pour Windows Internet Explorer 7 (KB928090)-->"C:\WINDOWS\ie7updates\KB928090-IE7\spuninst\spuninst.exe"
              Mise à jour de sécurité pour Windows Internet Explorer 7 (KB929969)-->"C:\WINDOWS\ie7updates\KB929969\spuninst\spuninst.exe"
              Mise à jour de sécurité pour Windows Internet Explorer 7 (KB931768)-->"C:\WINDOWS\ie7updates\KB931768-IE7\spuninst\spuninst.exe"
              Mise à jour de sécurité pour Windows Internet Explorer 7 (KB933566)-->"C:\WINDOWS\ie7updates\KB933566-IE7\spuninst\spuninst.exe"
              Mise à jour de sécurité pour Windows Internet Explorer 7 (KB937143)-->"C:\WINDOWS\ie7updates\KB937143-IE7\spuninst\spuninst.exe"
              Mise à jour de sécurité pour Windows Internet Explorer 7 (KB938127)-->"C:\WINDOWS\ie7updates\KB938127-IE7\spuninst\spuninst.exe"
              Mise à jour de sécurité pour Windows Internet Explorer 7 (KB939653)-->"C:\WINDOWS\ie7updates\KB939653-IE7\spuninst\spuninst.exe"
              Mise à jour de sécurité pour Windows Internet Explorer 7 (KB942615)-->"C:\WINDOWS\ie7updates\KB942615-IE7\spuninst\spuninst.exe"
              Mise à jour de sécurité pour Windows Internet Explorer 7 (KB944533)-->"C:\WINDOWS\ie7updates\KB944533-IE7\spuninst\spuninst.exe"
              Mise à jour de sécurité pour Windows Internet Explorer 7 (KB950759)-->"C:\WINDOWS\ie7updates\KB950759-IE7\spuninst\spuninst.exe"
              Mise à jour de sécurité pour Windows Internet Explorer 7 (KB953838)-->"C:\WINDOWS\ie7updates\KB953838-IE7\spuninst\spuninst.exe"
              Mise à jour de sécurité pour Windows Internet Explorer 7 (KB956390)-->"C:\WINDOWS\ie7updates\KB956390-IE7\spuninst\spuninst.exe"
              Mise à jour de sécurité pour Windows Internet Explorer 7 (KB963027)-->"C:\WINDOWS\ie7updates\KB963027-IE7\spuninst\spuninst.exe"
              Mise à jour de sécurité pour Windows Internet Explorer 7 (KB969897)-->"C:\WINDOWS\ie7updates\KB969897-IE7\spuninst\spuninst.exe"
              Mise à jour de sécurité pour Windows Internet Explorer 7 (KB972260)-->"C:\WINDOWS\ie7updates\KB972260-IE7\spuninst\spuninst.exe"
              Mise à jour de sécurité pour Windows Internet Explorer 7 (KB974455)-->"C:\WINDOWS\ie7updates\KB974455-IE7\spuninst\spuninst.exe"
              Mise à jour de sécurité pour Windows Internet Explorer 8 (KB971961)-->"C:\WINDOWS\ie8updates\KB971961-IE8\spuninst\spuninst.exe"
              Mise à jour de sécurité pour Windows Internet Explorer 8 (KB974455)-->"C:\WINDOWS\ie8updates\KB974455-IE8\spuninst\spuninst.exe"
              Mise à jour de sécurité pour Windows Internet Explorer 8 (KB976325)-->"C:\WINDOWS\ie8updates\KB976325-IE8\spuninst\spuninst.exe"
              Mise à jour de sécurité pour Windows XP (KB923561)-->"C:\WINDOWS\$NtUninstallKB923561$\spuninst\spuninst.exe"
              Mise à jour de sécurité pour Windows XP (KB938464)-->"C:\WINDOWS\$NtUninstallKB938464$\spuninst\spuninst.exe"
              Mise à jour de sécurité pour Windows XP (KB938464-v2)-->"C:\WINDOWS\$NtUninstallKB938464-v2$\spuninst\spuninst.exe"
              Mise à jour de sécurité pour Windows XP (KB941569)-->"C:\WINDOWS\$NtUninstallKB941569$\spuninst\spuninst.exe"
              Mise à jour de sécurité pour Windows XP (KB946648)-->"C:\WINDOWS\$NtUninstallKB946648$\spuninst\spuninst.exe"
              Mise à jour de sécurité pour Windows XP (KB950760)-->"C:\WINDOWS\$NtUninstallKB950760$\spuninst\spuninst.exe"
              Mise à jour de sécurité pour Windows XP (KB950762)-->"C:\WINDOWS\$NtUninstallKB950762$\spuninst\spuninst.exe"
              Mise à jour de sécurité pour Windows XP (KB950974)-->"C:\WINDOWS\$NtUninstallKB950974$\spuninst\spuninst.exe"
              Mise à jour de sécurité pour Windows XP (KB951066)-->"C:\WINDOWS\$NtUninstallKB951066$\spuninst\spuninst.exe"
              Mise à jour de sécurité pour Windows XP (KB951376-v2)-->"C:\WINDOWS\$NtUninstallKB951376-v2$\spuninst\spuninst.exe"
              Mise à jour de sécurité pour Windows XP (KB951698)-->"C:\WINDOWS\$NtUninstallKB951698$\spuninst\spuninst.exe"
              Mise à jour de sécurité pour Windows XP (KB951748)-->"C:\WINDOWS\$NtUninstallKB951748$\spuninst\spuninst.exe"
              Mise à jour de sécurité pour Windows XP (KB952004)-->"C:\WINDOWS\$NtUninstallKB952004$\spuninst\spuninst.exe"
              Mise à jour de sécurité pour Windows XP (KB952954)-->"C:\WINDOWS\$NtUninstallKB952954$\spuninst\spuninst.exe"
              Mise à jour de sécurité pour Windows XP (KB953839)-->"C:\WINDOWS\$NtUninstallKB953839$\spuninst\spuninst.exe"
              Mise à jour de sécurité pour Windows XP (KB954211)-->"C:\WINDOWS\$NtUninstallKB954211$\spuninst\spuninst.exe"
              Mise à jour de sécurité pour Windows XP (KB954459)-->"C:\WINDOWS\$NtUninstallKB954459$\spuninst\spuninst.exe"
              Mise à jour de sécurité pour Windows XP (KB954600)-->"C:\WINDOWS\$NtUninstallKB954600$\spuninst\spuninst.exe"
              Mise à jour de sécurité pour Windows XP (KB955069)-->"C:\WINDOWS\$NtUninstallKB955069$\spuninst\spuninst.exe"
              Mise à jour de sécurité pour Windows XP (KB956391)-->"C:\WINDOWS\$NtUninstallKB956391$\spuninst\spuninst.exe"
              Mise à jour de sécurité pour Windows XP (KB956572)-->"C:\WINDOWS\$NtUninstallKB956572$\spuninst\spuninst.exe"
              Mise à jour de sécurité pour Windows XP (KB956744)-->"C:\WINDOWS\$NtUninstallKB956744$\spuninst\spuninst.exe"
              Mise à jour de sécurité pour Windows XP (KB956802)-->"C:\WINDOWS\$NtUninstallKB956802$\spuninst\spuninst.exe"
              Mise à jour de sécurité pour Windows XP (KB956803)-->"C:\WINDOWS\$NtUninstallKB956803$\spuninst\spuninst.exe"
              Mise à jour de sécurité pour Windows XP (KB956841)-->"C:\WINDOWS\$NtUninstallKB956841$\spuninst\spuninst.exe"
              Mise à jour de sécurité pour Windows XP (KB956844)-->"C:\WINDOWS\$NtUninstallKB956844$\spuninst\spuninst.exe"
              Mise à jour de sécurité pour Windows XP (KB957095)-->"C:\WINDOWS\$NtUninstallKB957095$\spuninst\spuninst.exe"
              Mise à jour de sécurité pour Windows XP (KB957097)-->"C:\WINDOWS\$NtUninstallKB957097$\spuninst\spuninst.exe"
              Mise à jour de sécurité pour Windows XP (KB958644)-->"C:\WINDOWS\$NtUninstallKB958644$\spuninst\spuninst.exe"
              Mise à jour de sécurité pour Windows XP (KB958687)-->"C:\WINDOWS\$NtUninstallKB958687$\spuninst\spuninst.exe"
              Mise à jour de sécurité pour Windows XP (KB958690)-->"C:\WINDOWS\$NtUninstallKB958690$\spuninst\spuninst.exe"
              Mise à jour de sécurité pour Windows XP (KB958869)-->"C:\WINDOWS\$NtUninstallKB958869$\spuninst\spuninst.exe"
              Mise à jour de sécurité pour Windows XP (KB959426)-->"C:\WINDOWS\$NtUninstallKB959426$\spuninst\spuninst.exe"
              Mise à jour de sécurité pour Windows XP (KB960225)-->"C:\WINDOWS\$NtUninstallKB960225$\spuninst\spuninst.exe"
              Mise à jour de sécurité pour Windows XP (KB960715)-->"C:\WINDOWS\$NtUninstallKB960715$\spuninst\spuninst.exe"
              Mise à jour de sécurité pour Windows XP (KB960803)-->"C:\WINDOWS\$NtUninstallKB960803$\spuninst\spuninst.exe"
              Mise à jour de sécurité pour Windows XP (KB960859)-->"C:\WINDOWS\$NtUninstallKB960859$\spuninst\spuninst.exe"
              Mise à jour de sécurité pour Windows XP (KB961371-v2)-->"C:\WINDOWS\$NtUninstallKB961371-v2$\spuninst\spuninst.exe"
              Mise à jour de sécurité pour Windows XP (KB961373)-->"C:\WINDOWS\$NtUninstallKB961373$\spuninst\spuninst.exe"
              Mise à jour de sécurité pour Windows XP (KB961501)-->"C:\WINDOWS\$NtUninstallKB961501$\spuninst\spuninst.exe"
              Mise à jour de sécurité pour Windows XP (KB968537)-->"C:\WINDOWS\$NtUninstallKB968537$\spuninst\spuninst.exe"
              Mise à jour de sécurité pour Windows XP (KB969059)-->"C:\WINDOWS\$NtUninstallKB969059$\spuninst\spuninst.exe"
              Mise à jour de sécurité pour Windows XP (KB969898)-->"C:\WINDOWS\$NtUninstallKB969898$\spuninst\spuninst.exe"
              Mise à jour de sécurité pour Windows XP (KB969947)-->"C:\WINDOWS\$NtUninstallKB969947$\spuninst\spuninst.exe"
              Mise à jour de sécurité pour Windows XP (KB970238)-->"C:\WINDOWS\$NtUninstallKB970238$\spuninst\spuninst.exe"
              Mise à jour de sécurité pour Windows XP (KB970430)-->"C:\WINDOWS\$NtUninstallKB970430$\spuninst\spuninst.exe"
              Mise à jour de sécurité pour Windows XP (KB971486)-->"C:\WINDOWS\$NtUninstallKB971486$\spuninst\spuninst.exe"
              Mise à jour de sécurité pour Windows XP (KB971557)-->"C:\WINDOWS\$NtUninstallKB971557$\spuninst\spuninst.exe"
              Mise à jour de sécurité pour Windows XP (KB971633)-->"C:\WINDOWS\$NtUninstallKB971633$\spuninst\spuninst.exe"
              Mise à jour de sécurité pour Windows XP (KB971657)-->"C:\WINDOWS\$NtUninstallKB971657$\spuninst\spuninst.exe"
              Mise à jour de sécurité pour Windows XP (KB971961)-->"C:\WINDOWS\$NtUninstallKB971961$\spuninst\spuninst.exe"
              Mise à jour de sécurité pour Windows XP (KB973346)-->"C:\WINDOWS\$NtUninstallKB973346$\spuninst\spuninst.exe"
              Mise à jour de sécurité pour Windows XP (KB973354)-->"C:\WINDOWS\$NtUninstallKB973354$\spuninst\spuninst.exe"
              Mise à jour de sécurité pour Windows XP (KB973507)-->"C:\WINDOWS\$NtUninstallKB973507$\spuninst\spuninst.exe"
              Mise à jour de sécurité pour Windows XP (KB973525)-->"C:\WINDOWS\$NtUninstallKB973525$\spuninst\spuninst.exe"
              Mise à jour de sécurité pour Windows XP (KB973869)-->"C:\WINDOWS\$NtUninstallKB973869$\spuninst\spuninst.exe"
              Mise à jour de sécurité pour Windows XP (KB973904)-->"C:\WINDOWS\$NtUninstallKB973904$\spuninst\spuninst.exe"
              Mise à jour de sécurité pour Windows XP (KB974112)-->"C:\WINDOWS\$NtUninstallKB974112$\spuninst\spuninst.exe"
              Mise à jour de sécurité pour Windows XP (KB974318)-->"C:\WINDOWS\$NtUninstallKB974318$\spuninst\spuninst.exe"
              Mise à jour de sécurité pour Windows XP (KB974392)-->"C:\WINDOWS\$NtUninstallKB974392$\spuninst\spuninst.exe"
              Mise à jour de sécurité pour Windows XP (KB974571)-->"C:\WINDOWS\$NtUninstallKB974571$\spuninst\spuninst.exe"
              Mise à jour de sécurité pour Windows XP (KB975025)-->"C:\WINDOWS\$NtUninstallKB975025$\spuninst\spuninst.exe"
              Mise à jour de sécurité pour Windows XP (KB975467)-->"C:\WINDOWS\$NtUninstallKB975467$\spuninst\spuninst.exe"
              Mise à jour pour Windows Internet Explorer 8 (KB973874)-->"C:\WINDOWS\ie8updates\KB973874-IE8\spuninst\spuninst.exe"
              Mise à jour pour Windows Internet Explorer 8 (KB976749)-->"C:\WINDOWS\ie8updates\KB976749-IE8\spuninst\spuninst.exe"
              Mise à jour pour Windows XP (KB951072-v2)-->"C:\WINDOWS\$NtUninstallKB951072-v2$\spuninst\spuninst.exe"
              Mise à jour pour Windows XP (KB951978)-->"C:\WINDOWS\$NtUninstallKB951978$\spuninst\spuninst.exe"
              Mise à jour pour Windows XP (KB955839)-->"C:\WINDOWS\$NtUninstallKB955839$\spuninst\spuninst.exe"
              Mise à jour pour Windows XP (KB967715)-->"C:\WINDOWS\$NtUninstallKB967715$\spuninst\spuninst.exe"
              Mise à jour pour Windows XP (KB968389)-->"C:\WINDOWS\$NtUninstallKB968389$\spuninst\spuninst.exe"
              Mise à jour pour Windows XP (KB971737)-->"C:\WINDOWS\$NtUninstallKB971737$\spuninst\spuninst.exe"
              Mise à jour pour Windows XP (KB973687)-->"C:\WINDOWS\$NtUninstallKB973687$\spuninst\spuninst.exe"
              Mise à jour pour Windows XP (KB973815)-->"C:\WINDOWS\$NtUninstallKB973815$\spuninst\spuninst.exe"
              Mozilla Firefox (3.0.17)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
              MSXML 4.0 SP2 (KB927978)-->MsiExec.exe /I{37477865-A3F1-4772-AD43-AAFC6BCFF99F}
              MSXML 4.0 SP2 (KB936181)-->MsiExec.exe /I{C04E32E0-0416-434D-AFB9-6969D703A9EF}
              MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
              MSXML 4.0 SP2 (KB973688)-->MsiExec.exe /I{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}
              Nero 7 Demo-->MsiExec.exe /I{C985153C-3801-EB63-1432-088E71801036}
              Quick Launch Buttons 5.10 B3-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{CEB326EC-8F40-47B2-BA22-BB092565D66F}\setup.exe" -l0x40c -uninst
              QuickTime-->MsiExec.exe /I{F07B861C-72B9-40A4-8B1A-AAED4C06A7E8}
              ScanSoft OmniPage SE 4.0-->MsiExec.exe /I{C1E693A4-B1D5-4DCD-B68D-2087835B7184}
              Security Update for CAPICOM (KB931906)-->MsiExec.exe /I{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
              Security Update for CAPICOM (KB931906)-->MsiExec.exe /X{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
              Shockwave-->C:\WINDOWS\system32\Macromed\SHOCKW~2\UNWISE.EXE C:\WINDOWS\system32\Macromed\SHOCKW~2\Install.log
              Sonic Audio Module-->MsiExec.exe /I{AB708C9B-97C8-4AC9-899B-DBF226AC9382}
              Sonic Copy Module-->MsiExec.exe /I{B12665F4-4E93-4AB4-B7FC-37053B524629}
              Sonic Data Module-->MsiExec.exe /I{075473F5-846A-448B-BCB3-104AA1760205}
              Sonic Express Labeler-->MsiExec.exe /I{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}
              Sonic Update Manager-->MsiExec.exe /I{30465B6C-B53F-49A1-9EBA-A3F187AD502E}
              Spybot - Search & Destroy-->"C:\Program Files\Spybot - Search & Destroy\unins001.exe"
              Synaptics Pointing Device Driver-->rundll32.exe "C:\Program Files\Synaptics\SynTP\SynISDLL.dll",standAloneUninstall
              Ulead VideoStudio 8.0 SE VCD-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{4F1DA6BF-3614-48A1-9970-9E90F646789E}\Setup.exe" -l0x40c
              UserGuides-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\10\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{02E22217-0E96-4C3F-B831-83AA942B7715}\setup.exe" -l0x40c
              Windows Internet Explorer 8-->"C:\WINDOWS\ie8\spuninst\spuninst.exe"
              Windows Live installer-->MsiExec.exe /X{FD44E544-E7D0-4DBA-9FA0-8AE1A1300390}
              Windows Live Messenger-->MsiExec.exe /X{BADF6744-3787-48F6-B8C9-4C4995401D65}
              Windows Media Format 11 runtime-->"C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll
              Windows Media Format 11 runtime-->"C:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe"
              Windows Media Player 11-->"C:\WINDOWS\$NtUninstallwmp11$\spuninst\spuninst.exe"
              Windows Media Player Firefox Plugin-->MsiExec.exe /I{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}
              Windows XP Service Pack 3-->"C:\WINDOWS\$NtServicePackUninstall$\spuninst\spuninst.exe"

              ======Security center information======

              AV: avast! antivirus 4.8.1368 [VPS 100113-0]

              ======System event log======

              Computer Name: DELPHINE
              Event Code: 7036
              Message: Le service Windows Installer est entré dans l'état : arrêté.

              Record Number: 45096
              Source Name: Service Control Manager
              Time Written: 20100110144209.000000+060
              Event Type: Informations
              User:

              Computer Name: DELPHINE
              Event Code: 7036
              Message: Le service LiveUpdate est entré dans l'état : arrêté.

              Record Number: 45095
              Source Name: Service Control Manager
              Time Written: 20100110143459.000000+060
              Event Type: Informations
              User:

              Computer Name: DELPHINE
              Event Code: 7036
              Message: Le service LiveUpdate est entré dans l'état : en cours d'exécution.

              Record Number: 45094
              Source Name: Service Control Manager
              Time Written: 20100110143435.000000+060
              Event Type: Informations
              User:

              Computer Name: DELPHINE
              Event Code: 7035
              Message: Un contrôle Démarrer a correctement été envoyé au service LiveUpdate.

              Record Number: 45093
              Source Name: Service Control Manager
              Time Written: 20100110143435.000000+060
              Event Type: Informations
              User: AUTORITE NT\SYSTEM

              Computer Name: DELPHINE
              Event Code: 7036
              Message: Le service avast! Mail Scanner est entré dans l'état : en cours d'exécution.

              Record Number: 45092
              Source Name: Service Control Manager
              Time Written: 20100110143209.000000+060
              Event Type: Informations
              User:

              =====Application event log=====

              Computer Name: DELPHINE
              Event Code: 101
              Message: Niveau d'information : success

              Le Planificateur a lancé LiveUpdate automatique.

              Record Number: 27339
              Source Name: Automatic LiveUpdate Scheduler
              Time Written: 20091113205444.000000+060
              Event Type: Informations
              User: AUTORITE NT\SYSTEM

              Computer Name: DELPHINE
              Event Code: 101
              Message: Niveau d'information : success

              L'exécution suivante a été planifiée pour intervenir approximativement à 8:54 PM.

              Record Number: 27338
              Source Name: Automatic LiveUpdate Scheduler
              Time Written: 20091113163054.000000+060
              Event Type: Informations
              User: AUTORITE NT\SYSTEM

              Computer Name: DELPHINE
              Event Code: 101
              Message: Niveau d'information : success

              LiveUpdate automatique a terminé.

              Record Number: 27337
              Source Name: Automatic LiveUpdate Scheduler
              Time Written: 20091113163054.000000+060
              Event Type: Informations
              User: AUTORITE NT\SYSTEM

              Computer Name: DELPHINE
              Event Code: 101
              Message: Niveau d'information : success

              Le Planificateur a lancé LiveUpdate automatique.

              Record Number: 27336
              Source Name: Automatic LiveUpdate Scheduler
              Time Written: 20091113163008.000000+060
              Event Type: Informations
              User: AUTORITE NT\SYSTEM

              Computer Name: DELPHINE
              Event Code: 101
              Message: Niveau d'information : success

              L'exécution suivante a été planifiée pour intervenir approximativement à 4:30 PM.

              Record Number: 27335
              Source Name: Automatic LiveUpdate Scheduler
              Time Written: 20091113123901.000000+060
              Event Type: Informations
              User: AUTORITE NT\SYSTEM

              ======Environment variables======

              "ComSpec"=%SystemRoot%\system32\cmd.exe
              "Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\system32\wbem;C:\Program Files\ATI Technologies\ATI Control Panel;C:\Program Files\QuickTime\QTSystem;C:\Program Files\Fichiers communs\Ulead Systems\MPEG;C:\Program Files\Fichiers communs\Ulead Systems\DVD
              "windir"=%SystemRoot%
              "FP_NO_HOST_CHECK"=NO
              "OS"=Windows_NT
              "PROCESSOR_ARCHITECTURE"=x86
              "PROCESSOR_LEVEL"=15
              "PROCESSOR_IDENTIFIER"=x86 Family 15 Model 47 Stepping 2, AuthenticAMD
              "PROCESSOR_REVISION"=2f02
              "NUMBER_OF_PROCESSORS"=1
              "PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
              "TEMP"=%SystemRoot%\TEMP
              "TMP"=%SystemRoot%\TEMP
              "SonicCentral"=C:\Program Files\Fichiers communs\Sonic Shared\Sonic Central\
              "CLASSPATH"=.;C:\Program Files\Java\jre1.5.0_02\lib\ext\QTJava.zip
              "QTJAVA"=C:\Program Files\Java\jre1.5.0_02\lib\ext\QTJava.zip

              -----------------EOF-----------------
              0
            2. @labilledelordiet voilà le deuxième rapport :

              Logfile of random's system information tool 1.06 (written by random/random)
              Run by Delphine at 2010-01-13 21:33:26
              Microsoft Windows XP Édition familiale Service Pack 3
              System drive C: has 17 GB (29%) free of 57 GB
              Total RAM: 382 MB (28% free)

              Logfile of Trend Micro HijackThis v2.0.2
              Scan saved at 21:34:09, on 13/01/2010
              Platform: Windows XP SP3 (WinNT 5.01.2600)
              MSIE: Internet Explorer v8.00 (8.00.6001.18702)
              Boot mode: Normal

              Running processes:
              C:\WINDOWS\System32\smss.exe
              C:\WINDOWS\system32\winlogon.exe
              C:\WINDOWS\system32\services.exe
              C:\WINDOWS\system32\lsass.exe
              C:\WINDOWS\system32\Ati2evxx.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\System32\svchost.exe
              C:\WINDOWS\system32\svchost.exe
              C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
              C:\Program Files\Alwil Software\Avast4\ashServ.exe
              C:\WINDOWS\system32\Ati2evxx.exe
              C:\WINDOWS\Explorer.EXE
              C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
              C:\Program Files\QuickTime\qttask.exe
              C:\Documents and Settings\Delphine\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
              C:\Program Files\uTorrent\uTorrent.exe
              C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
              C:\WINDOWS\system32\ctfmon.exe
              C:\WINDOWS\system32\spoolsv.exe
              C:\WINDOWS\system32\DRIVERS\CDANTSRV.EXE
              C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
              C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
              C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
              C:\WINDOWS\system32\HPZipm12.exe
              C:\WINDOWS\system32\svchost.exe
              C:\Program Files\Fichiers communs\Ulead Systems\DVD\ULCDRSvr.exe
              C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
              C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
              C:\WINDOWS\system32\wuauclt.exe
              C:\Program Files\Internet Explorer\iexplore.exe
              C:\Program Files\Internet Explorer\iexplore.exe
              C:\Documents and Settings\Delphine\Bureau\RSIT.exe
              C:\Program Files\trend micro\Delphine.exe

              R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ask.com?o=13170&l=dis
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
              R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.duxet.com/
              R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
              O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
              O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
              O2 - BHO: Canon Easy Web Print Helper - {68F9551E-0411-48E4-9AAF-4BC42A6A46BE} - C:\Program Files\Canon\Easy-WebPrint\EWPBrowseLoader.dll
              O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
              O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
              O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll
              O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
              O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
              O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
              O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
              O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Delphine\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
              O4 - HKCU\..\Run: [uTorrent] "C:\Program Files\uTorrent\uTorrent.exe"
              O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
              O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
              O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
              O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\FICHIE~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
              O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
              O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
              O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
              O8 - Extra context menu item: Easy-WebPrint Ajouter à la liste d'impressions - res://C:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_AddToList.html
              O8 - Extra context menu item: Easy-WebPrint Impression rapide - res://C:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_HSPrint.html
              O8 - Extra context menu item: Easy-WebPrint Imprimer - res://C:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_Print.html
              O8 - Extra context menu item: Easy-WebPrint Prévisualiser - res://C:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_Preview.html
              O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
              O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
              O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
              O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
              O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
              O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
              O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
              O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
              O14 - IERESET.INF: START_PAGE_URL=http://ie.redirect.hp.com/...
              O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
              O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
              O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/...
              O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} (CamImage Class) - http://198.165.90.20/activex/AxisCamControl.cab
              O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
              O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
              O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
              O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
              O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
              O23 - Service: C-DillaSrv - C-Dilla Ltd - C:\WINDOWS\system32\DRIVERS\CDANTSRV.EXE
              O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
              O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Program Files\HPQ\SHARED\HPQWMI.exe
              O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
              O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Unknown owner - C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
              O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
              O23 - Service: Planificateur LiveUpdate automatique - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
              O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
              O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - c:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
              O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Fichiers communs\Ulead Systems\DVD\ULCDRSvr.exe
              0
          3. et voilà pour le rapport malware, sachant que 5 virus n'ont pas pu être mis en quarantaine ni supprimés, du coup je sais pas où ils sont!

            Malwarebytes' Anti-Malware 1.44
            Version de la base de données: 3554
            Windows 5.1.2600 Service Pack 3
            Internet Explorer 8.0.6001.18702

            13/01/2010 21:06:32
            mbam-log-2010-01-13 (21-06-32).txt

            Type de recherche: Examen complet (C:\|D:\|E:\|F:\|G:\|H:\|)
            Eléments examinés: 234719
            Temps écoulé: 2 hour(s), 34 minute(s), 42 second(s)

            Processus mémoire infecté(s): 0
            Module(s) mémoire infecté(s): 0
            Clé(s) du Registre infectée(s): 2
            Valeur(s) du Registre infectée(s): 0
            Elément(s) de données du Registre infecté(s): 0
            Dossier(s) infecté(s): 2
            Fichier(s) infecté(s): 19

            Processus mémoire infecté(s):
            (Aucun élément nuisible détecté)

            Module(s) mémoire infecté(s):
            (Aucun élément nuisible détecté)

            Clé(s) du Registre infectée(s):
            HKEY_CURRENT_USER\SOFTWARE\LEO0WTUNO7 (Trojan.FakeAlert) -> Quarantined and deleted successfully.
            HKEY_LOCAL_MACHINE\System\CurrentControlSet\Servises (Malware.Trace) -> Quarantined and deleted successfully.

            Valeur(s) du Registre infectée(s):
            (Aucun élément nuisible détecté)

            Elément(s) de données du Registre infecté(s):
            (Aucun élément nuisible détecté)

            Dossier(s) infecté(s):
            C:\Documents and Settings\All Users\Menu Démarrer\PersonalSec (Rogue.PersonalSecurity) -> Quarantined and deleted successfully.
            C:\Program Files\Fichiers communs\PersonalSecUninstall (Rogue.PersonalSecurity) -> Quarantined and deleted successfully.

            Fichier(s) infecté(s):
            C:\Qoobox\Quarantine\C\Program Files\PersonalSec\psecurity.exe.vir (Rogue.Multiple) -> Quarantined and deleted successfully.
            C:\Qoobox\Quarantine\C\WINDOWS\system32\win32extension.dll.vir (Trojan.FakeAlert) -> Quarantined and deleted successfully.
            C:\MDG\Combo-Fix.sys (Malware.Trace) -> Quarantined and deleted successfully.
            C:\Documents and Settings\Delphine\Bureau\Setup_257(2).exe (Rogue.Installer) -> Quarantined and deleted successfully.
            C:\Documents and Settings\Delphine\Bureau\Setup_257(3).exe (Rogue.Installer) -> Quarantined and deleted successfully.
            C:\Documents and Settings\Delphine\Bureau\Logiciels\Nero\Keygen\keygen.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
            C:\Documents and Settings\Delphine\Local Settings\Application Data\Mozilla\Firefox\Profiles\iwyp4jk5.default\Cache\9DC9F8E3d01 (Rogue.Installer) -> Quarantined and deleted successfully.
            C:\System Volume Information\_restore{B8687C25-491C-4B92-A950-D228172F494F}\RP520\A0077018.exe (Rogue.Installer) -> Quarantined and deleted successfully.
            C:\System Volume Information\_restore{B8687C25-491C-4B92-A950-D228172F494F}\RP521\A0077127.exe (Rogue.Multiple) -> Quarantined and deleted successfully.
            C:\System Volume Information\_restore{B8687C25-491C-4B92-A950-D228172F494F}\RP521\A0077131.dll (Trojan.FakeAlert) -> Quarantined and deleted successfully.
            C:\System Volume Information\_restore{B8687C25-491C-4B92-A950-D228172F494F}\RP521\A0077165.exe (Rogue.Installer) -> Quarantined and deleted successfully.
            C:\System Volume Information\_restore{B8687C25-491C-4B92-A950-D228172F494F}\RP521\A0077166.exe (Rogue.Installer) -> Quarantined and deleted successfully.
            C:\Documents and Settings\All Users\Menu Démarrer\PersonalSec\Computer Scan.lnk (Rogue.PersonalSecurity) -> Quarantined and deleted successfully.
            C:\Documents and Settings\All Users\Menu Démarrer\PersonalSec\Help.lnk (Rogue.PersonalSecurity) -> Quarantined and deleted successfully.
            C:\Documents and Settings\All Users\Menu Démarrer\PersonalSec\Registration.lnk (Rogue.PersonalSecurity) -> Quarantined and deleted successfully.
            C:\Documents and Settings\All Users\Menu Démarrer\PersonalSec\Settings.lnk (Rogue.PersonalSecurity) -> Quarantined and deleted successfully.
            C:\Documents and Settings\All Users\Menu Démarrer\PersonalSec\Update.lnk (Rogue.PersonalSecurity) -> Quarantined and deleted successfully.
            C:\Program Files\Fichiers communs\PersonalSecUninstall\Uninstall.lnk (Rogue.PersonalSecurity) -> Quarantined and deleted successfully.
            C:\Documents and Settings\Delphine\Application Data\Microsoft\Internet Explorer\Quick Launch\PersonalSec.lnk (Rogue.PersonalSecurity) -> Quarantined and deleted successfully.
            0
            1. Contributeur sécurité
              c'est pas fini

              1)

              Téléchargez USBFIX de El Desaparecido, C_xx

              http://pagesperso-orange.fr/NosTools/Chiquitine29/UsbFix.exe
              ou
              https://www.ionos.fr/?affiliate_id=77097

              /!\ Utilisateur de vista et windows 7 :
              ne pas oublier de désactiver Le contrôle des comptes utilisateurs
              https://www.commentcamarche.net/faq/8343-vista-desactiver-l-uac

              /!\ Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) susceptible d'avoir été infectées sans les ouvrir

              • Double clic sur le raccourci UsbFix présent sur le bureau .

              • Choisir l'option2
              (d’autres options disponibles, voir le tutoriel).
              • Laissez travailler l'outil.
              Le menu démarrer et les icônes vont disparaître.. c'est normal.

              Si un message te demande de redémarrer l'ordinateur fais le ...

              ● Au redémarrage, le fix se relance... laisses l'opération s'effectuer.

              ● Le bloc note s'ouvre avec un rapport, envoies le dans la prochaine réponse

              • Note : Le rapport UsbFix.txt est sauvegardé a la racine du disque. ( C:\UsbFix.txt )

              ( CTRL+A Pour tout sélectionner , CTRL+C pour copier et CTRL+V pour coller )

              • Note : "Process.exe", une composante de l'outil, est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool.
              Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.
              Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall...) d'où l'alerte émise par ces antivirus.

              • Tuto : http://pagesperso-orange.fr/NosTools/usbfix.html

              UsbFix peut te demander d'uploader un dossier compressé à cette adresse : https://www.ionos.fr/?affiliate_id=77097

              Il est enregistré sur ton bureau.

              Merci de l'envoyer à l'adresse indiquée afin d'aider l'auteur de UsbFix dans ses recherches.

              Merci

              ............
              2)

              Lances MalwareByte's Anti-Malware

              . Dans l'onglet "mise à jour", cliques sur le bouton Recherche de mise à jour
              . Si le pare-feu demande l'autorisation de se connecter pour malwarebytes, accepte
              . Une fois la mise à jour terminé
              . Rend-toi dans l'onglet, Recherche
              . Sélectionnes Exécuter un examen complet
              . Cliques sur Rechercher
              . Le scan démarre.
              . A la fin de l'analyse, un message s'affiche : L'examen s'est terminé normalement. Cliquez sur 'Afficher les résultats' pour afficher tous les objets trouvés.
              . Cliques sur Ok pour poursuivre.
              . Si des malwares ont été détectés, clique sur Afficher les résultats
              . Sélectionnes tout (ou laisses cochés) et cliques sur Supprimer la sélection Malwarebytes va détruire les fichiers et clés de registre et en mettre une copie dans la quarantaine.
              . Malwarebytes va ouvrir le bloc-notes et y copier le rapport d'analyse.
              . Rends toi dans l'onglet rapport/log
              . Tu cliques dessus pour l'afficher, une fois affiché
              . Tu cliques sur edition en haut du boc notes, et puis sur sélectionner tous
              . Tu recliques sur edition et puis sur copier et tu reviens sur le forum et dans ta réponse
              . tu cliques droit dans le cadre de la reponse et coller

              Si tu as besoin d'aide regarde ces tutoriels :
              Aide: https://www.malekal.com/tutoriel-malwarebyte-anti-malware/
              http://www.infos-du-net.com/forum/278396-11-tuto-malwarebytes-anti-malware-mbam

              0
              1. voilà déjà pour le usbfix, le rapport :

                ############################## | UsbFix V6.073 |

                User : Delphine (Administrateurs) # DELPHINE
                Update on 09/01/2010 by El Desaparecido , C_XX & Chimay8
                Start at: 17:57:48 | 13/01/2010
                Website : http://pagesperso-orange.fr/NosTools/index.html
                Contact : FindyKill.Contact@gmail.com

                AMD Sempron(tm) Processor 3200+
                Microsoft Windows XP Édition familiale (5.1.2600 32-bit) # Service Pack 3
                Internet Explorer 8.0.6001.18702
                Windows Firewall Status : Enabled
                AV : avast! antivirus 4.8.1368 [VPS 100113-0] 4.8.1368 [ Enabled | Updated ]

                C:\ -> Disque fixe local # 55,88 Go (16,21 Go free) # NTFS
                D:\ -> Disque CD-ROM
                E:\ -> Disque amovible # 3,61 Go (171,28 Mo free) [CLÉ 09-10] # FAT32
                F:\ -> Disque amovible # 1,89 Go (2,16 Mo free) [UDISK 2.0] # FAT
                G:\ -> Disque amovible # 1,88 Go (216,44 Mo free) [CLÉ 08-09] # FAT32
                H:\ -> Disque amovible # 983,72 Mo (245,19 Mo free) [CLÉ 07-08] # FAT

                ############################## | Processus actifs |

                C:\WINDOWS\System32\smss.exe 576
                C:\WINDOWS\system32\csrss.exe 640
                C:\WINDOWS\system32\winlogon.exe 664
                C:\WINDOWS\system32\services.exe 716
                C:\WINDOWS\system32\lsass.exe 728
                C:\WINDOWS\system32\Ati2evxx.exe 876
                C:\WINDOWS\system32\svchost.exe 896
                C:\WINDOWS\system32\svchost.exe 1028
                C:\WINDOWS\System32\svchost.exe 1120
                C:\WINDOWS\system32\svchost.exe 1156
                C:\WINDOWS\system32\svchost.exe 1360
                C:\WINDOWS\system32\svchost.exe 1444
                C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe 1688
                C:\Program Files\Alwil Software\Avast4\ashServ.exe 2036
                C:\WINDOWS\system32\Ati2evxx.exe 248
                C:\WINDOWS\system32\spoolsv.exe 1660
                C:\MDG\CF19501.cfxxe 1512
                C:\WINDOWS\system32\svchost.exe 1588
                C:\WINDOWS\system32\DRIVERS\CDANTSRV.EXE 1868
                C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe 1920
                C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe 136
                C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe 172
                C:\WINDOWS\system32\HPZipm12.exe 972
                C:\WINDOWS\system32\svchost.exe 1104
                C:\Program Files\Fichiers communs\Ulead Systems\DVD\ULCDRSvr.exe 1288
                C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe 1356
                C:\Program Files\QuickTime\qttask.exe 1580
                C:\Documents and Settings\Delphine\Local Settings\Application Data\Google\Update\GoogleUpdate.exe 1632
                C:\Program Files\uTorrent\uTorrent.exe 2120
                C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe 2216
                C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe 3452
                C:\WINDOWS\system32\wuauclt.exe 2292
                C:\WINDOWS\System32\alg.exe 3160
                C:\Program Files\Alwil Software\Avast4\ashWebSv.exe 476
                C:\WINDOWS\explorer.exe 2540
                C:\WINDOWS\system32\notepad.exe 3248
                C:\MDG\handle.cfxxe 1608
                C:\WINDOWS\system32\NOTEPAD.EXE 128
                C:\Program Files\Internet Explorer\iexplore.exe 2456
                C:\WINDOWS\system32\ctfmon.exe 2740
                C:\Program Files\Internet Explorer\iexplore.exe 2904
                C:\Documents and Settings\Delphine\Bureau\mbam-setup.exe 3704
                C:\DOCUME~1\Delphine\LOCALS~1\Temp\is-L2DGT.tmp\mbam-setup.tmp 2956
                C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe 2696
                C:\WINDOWS\system32\wbem\wmiprvse.exe 3700

                ################## | Elements infectieux |

                E:\autorun.inf
                E:\autorun.inf -> fichier appelé : "E:\vtchpk.exe" ( Présent ! )
                F:\autorun.inf
                F:\autorun.inf -> fichier appelé : "F:\vtchpk.exe" ( Présent ! )
                G:\autorun.inf
                G:\autorun.inf -> fichier appelé : "G:\vtchpk.exe" ( Présent ! )

                ################## | Registre |

                [HKCU\SOFTWARE\LEO0WTUNO7]
                [HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System] "DisableRegistryTools"
                [HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer] "NoDrives"
                [HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer] "NoDrives"

                ################## | Mountpoints2 |

                HKCU\..\..\Explorer\MountPoints2\{200a4f58-a024-11db-8a6c-0014a529f1cf}
                Shell\Auto\command =F:\bittorrent.exe e
                Shell\AutoRun\command =C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL bittorrent.exe e

                HKCU\..\..\Explorer\MountPoints2\{246e8b63-f0d0-11db-8a99-0014a529f1cf}
                Shell\Auto\command =bittorrent.exe e
                Shell\AutoRun\command =C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL bittorrent.exe e

                HKCU\..\..\Explorer\MountPoints2\{76b4f276-b653-11dd-8b3a-0014a529f1cf}
                Shell\AutoRun\command =G:\vtchpk.exe
                Shell\explore\Command =G:\vtchpk.exe
                Shell\open\Command =G:\vtchpk.exe

                HKCU\..\..\Explorer\MountPoints2\{7bfe60e6-fe48-11de-8bad-0014a529f1cf}
                Shell\AutoRun\command =G:\vtchpk.exe
                Shell\explore\Command =G:\vtchpk.exe
                Shell\open\Command =G:\vtchpk.exe

                HKCU\..\..\Explorer\MountPoints2\{951de722-dd1c-11de-8b98-0014a529f1cf}
                Shell\AutoRun\command =F:\vtchpk.exe
                Shell\explore\Command =F:\vtchpk.exe
                Shell\open\Command =F:\vtchpk.exe

                HKCU\..\..\Explorer\MountPoints2\{9612e14f-f805-11db-8a9f-0014a529f1cf}
                Shell\Auto\command =G:\bittorrent.exe e
                Shell\AutoRun\command =C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL bittorrent.exe e

                HKCU\..\..\Explorer\MountPoints2\{a22c269e-f3dc-11db-8a9d-0014a529f1cf}
                Shell\Auto\command =F:\bittorrent.exe e
                Shell\AutoRun\command =C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL bittorrent.exe e

                HKCU\..\..\Explorer\MountPoints2\{a4d5d84c-a111-11de-8b55-0014a529f1cf}
                Shell\AutoRun\command =E:\vtchpk.exe
                Shell\explore\Command =E:\vtchpk.exe
                Shell\open\Command =E:\vtchpk.exe

                HKCU\..\..\Explorer\MountPoints2\{d7f2e720-3b7e-11db-9b47-0014a529f1cf}
                Shell\AutoRun\command =F:\setupSNK.exe

                HKCU\..\..\Explorer\MountPoints2\{e68bd072-f9f4-11dc-8b08-0014a529f1cf}
                Shell\AutoRun\command =Autorun.exe /run
                Shell\Shell00\Command =Autorun.exe /run
                Shell\Shell01\Command =Autorun.exe /action
                Shell\Shell02\Command =Autorun.exe /uninstall

                HKCU\..\..\Explorer\MountPoints2\{e88290de-ef17-11db-8a98-0014a529f1cf}
                Shell\Auto\command =F:\AdobeR.exe e
                Shell\AutoRun\command =C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL AdobeR.exe e

                HKCU\..\..\Explorer\MountPoints2\{ec7c3b36-4bbb-11db-9b56-0014a529f1cf}
                Shell\Auto\command =bittorrent.exe e
                Shell\AutoRun\command =C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL bittorrent.exe e

                HKCU\..\..\Explorer\MountPoints2\{f80dde29-e78d-11db-8a90-0014a529f1cf}
                Shell\Auto\command =AdobeR.exe e
                Shell\AutoRun\command =C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL AdobeR.exe e

                ################## | Cracks > Keygens > Serials |

                "C:\Documents and Settings\Delphine\Bureau\Logiciels\Nero\Keygen\keygen.exe"
                29/04/2006 18:02 |Size 208101 |Crc32 a85f05cf |Md5 71904875b96fcd3b7159742daf51a12e

                ################## | ! Fin du rapport # UsbFix V6.073 ! |
                0
            2. ca y est j'ai reussi à lancer combofix en mode sans echec
              il m'a demandé d'installer la conseole de recupération, mais je ne pouvais pas car pas d'accès internet en mode sans echec, il a tout de même poursuivi la procédure et à relancé windows XP et affiché le rapport suivant :

              ComboFix 10-01-12.04 - Administrateur 13/01/2010 16:00:51.1.1 - x86 MINIMAL
              Microsoft Windows XP Édition familiale 5.1.2600.3.1252.33.1036.18.382.203 [GMT 1:00]
              Lancé depuis: c:\documents and settings\Delphine\Bureau\MDG.exe
              AV: avast! antivirus 4.8.1368 [VPS 100112-0] *On-access scanning enabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}

              AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!
              .

              (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
              .

              c:\documents and settings\Delphine\RavMonLog
              C:\khq
              c:\program files\PersonalSec
              c:\program files\PersonalSec\psecurity.exe
              c:\recycler\S-1-5-21-2447047498-3870487543-985515237-1003
              c:\recycler\S-1-5-21-823518204-1958367476-725345543-1003
              c:\windows\patch.exe
              c:\windows\system32\AutoRun.inf
              c:\windows\system32\twain_32.dll
              c:\windows\system32\win32extension.dll
              c:\windows\unins000.dat
              c:\windows\unins000.exe

              .
              ((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
              .

              -------\Legacy_SSHNAS

              ((((((((((((((((((((((((((((( Fichiers créés du 2009-12-13 au 2010-01-13 ))))))))))))))))))))))))))))))))))))
              .

              2010-01-13 14:53 . 2010-01-13 14:53 -------- d-----w- c:\documents and settings\Administrateur\Local Settings\Application Data\Ahead
              2010-01-13 14:44 . 2010-01-13 14:44 60440 ----a-w- c:\documents and settings\Administrateur\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
              2010-01-13 12:56 . 2010-01-13 12:56 -------- d-sh--w- c:\documents and settings\Administrateur\PrivacIE
              2010-01-13 12:53 . 2010-01-13 12:53 -------- d-sh--w- c:\documents and settings\Administrateur\IETldCache
              2010-01-11 00:30 . 2010-01-11 00:30 -------- d-----w- c:\program files\Fichiers communs\PersonalSecUninstall

              .
              (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
              .
              2010-01-13 14:28 . 2009-11-10 00:34 -------- d-----w- c:\documents and settings\Delphine\Application Data\uTorrent
              2010-01-11 22:05 . 2007-12-23 11:02 -------- d-----w- c:\documents and settings\All Users\Application Data\Ulead Systems
              2010-01-11 22:03 . 2007-12-23 11:02 -------- d-----w- c:\program files\Ulead Systems
              2010-01-11 22:02 . 2005-05-18 02:47 -------- d--h--w- c:\program files\InstallShield Installation Information
              2010-01-11 21:51 . 2007-02-24 20:23 -------- d-----w- c:\program files\ArcSoft
              2010-01-11 21:49 . 2007-12-23 11:42 -------- d-----w- c:\documents and settings\Delphine\Application Data\Ulead Systems
              2009-12-09 14:15 . 2004-08-17 09:31 64930 ----a-w- c:\windows\system32\perfc00C.dat
              2009-12-09 14:15 . 2004-08-17 09:31 448428 ----a-w- c:\windows\system32\perfh00C.dat
              2009-11-24 23:54 . 2006-12-25 12:26 1280480 ----a-w- c:\windows\system32\aswBoot.exe
              2009-11-24 23:51 . 2006-12-25 12:26 93424 ----a-w- c:\windows\system32\drivers\aswmon.sys
              2009-11-24 23:50 . 2006-12-25 12:26 94160 ----a-w- c:\windows\system32\drivers\aswmon2.sys
              2009-11-24 23:50 . 2008-04-13 21:48 114768 ----a-w- c:\windows\system32\drivers\aswSP.sys
              2009-11-24 23:50 . 2008-04-13 21:48 20560 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
              2009-11-24 23:49 . 2006-12-25 12:26 48560 ----a-w- c:\windows\system32\drivers\aswTdi.sys
              2009-11-24 23:48 . 2006-12-25 12:26 23120 ----a-w- c:\windows\system32\drivers\aswRdr.sys
              2009-11-24 23:47 . 2006-12-25 12:26 27408 ----a-w- c:\windows\system32\drivers\aavmker4.sys
              2009-11-24 23:47 . 2006-12-25 12:26 97480 ----a-w- c:\windows\system32\AVASTSS.scr
              2009-11-18 14:29 . 2009-11-18 14:05 -------- d-----w- c:\program files\Carnet
              2009-11-11 20:18 . 2006-09-06 19:37 60440 ----a-w- c:\documents and settings\Delphine\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
              2009-10-29 07:42 . 2004-08-05 08:00 916480 ----a-w- c:\windows\system32\wininet.dll
              2009-10-21 05:39 . 2004-08-05 08:00 75776 ----a-w- c:\windows\system32\strmfilt.dll
              2009-10-21 05:39 . 2004-08-05 08:00 25088 ----a-w- c:\windows\system32\httpapi.dll
              2009-10-20 16:20 . 2004-08-05 08:00 265728 ----a-w- c:\windows\system32\drivers\http.sys
              .

              ((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
              .
              .
              *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
              REGEDIT4

              [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
              "Google Update"="c:\documents and settings\Delphine\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2009-10-26 133104]
              "uTorrent"="c:\program files\uTorrent\uTorrent.exe" [2010-01-03 289584]
              "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-13 68856]

              [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
              "avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-11-24 81000]
              "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2006-09-01 282624]

              [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
              "CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
              "DWQueuedReporting"="c:\progra~1\FICHIE~1\MICROS~1\DW\dwtrig20.exe" [2007-03-22 39264]

              [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Microsoft Office.lnk]
              path=c:\documents and settings\All Users\Menu Démarrer\Programmes\Démarrage\Microsoft Office.lnk
              backup=c:\windows\pss\Microsoft Office.lnkCommon Startup

              [HKLM\~\startupfolder\C:^DOCUME~1^ALLUSE~1^Menu Démarrer^Programmes^Démarrage^Post-it® Software Notes Lite.lnk]
              path=c:\docume~1\ALLUSE~1\Menu Démarrer\Programmes\Démarrage\Post-it® Software Notes Lite.lnk
              backup=c:\windows\pss\Post-it® Software Notes Lite.lnkCommon Startup

              [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATIPTA]
              2005-03-22 19:05 339968 ----a-w- c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe

              [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
              2005-10-28 15:25 94208 ----a-w- c:\program files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe

              [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Cpqset]
              2005-02-17 12:01 233534 ----a-w- c:\program files\HPQ\Default Settings\Cpqset.exe

              [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
              2008-04-14 02:33 15360 ------w- c:\windows\system32\ctfmon.exe

              [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\eabconfg.cpl]
              2004-12-03 11:24 290816 ----a-w- c:\program files\HPQ\Quick Launch Buttons\eabservr.exe

              [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
              2005-02-16 21:11 49152 ----a-w- c:\program files\Hp\HP Software Update\hpwuSchd2.exe

              [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\hpWirelessAssistant]
              2005-04-11 13:21 794624 ----a-w- c:\program files\HPQ\HP Wireless Assistant\HP Wireless Assistant.exe

              [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM Startup]
              2004-07-27 14:50 221184 ----a-w- c:\progra~1\FICHIE~1\INSTAL~1\UPDATE~1\ISUSPM.exe

              [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSScheduler]
              2005-02-16 14:15 81920 ----a-w- c:\program files\Fichiers communs\InstallShield\UpdateService\issch.exe

              [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
              2006-09-11 23:58 229952 ----a-w- c:\program files\iTunes\iTunesHelper.exe

              [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
              2008-04-14 02:34 1695232 ----a-w- c:\program files\Messenger\msmsgs.exe

              [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
              2001-07-09 09:50 155648 ----a-w- c:\windows\system32\NeroCheck.exe

              [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OpwareSE4]
              2006-10-11 10:45 75304 ----a-w- c:\program files\ScanSoft\OmniPageSE4.0\OpWareSE4.exe

              [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
              2006-09-01 13:57 282624 ----a-w- c:\program files\QuickTime\qttask.exe

              [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SSBkgdUpdate]
              2006-09-28 11:16 185896 ----a-w- c:\program files\Fichiers communs\ScanSoft Shared\SSBkgdUpdate\SSBkgdUpdate.exe

              [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
              2005-03-04 01:36 36975 ----a-w- c:\program files\Java\jre1.5.0_02\bin\jusched.exe

              [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
              2007-07-13 09:42 68856 ----a-w- c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

              [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Symantec NetDriver Monitor]
              2006-09-06 19:54 100056 ----a-w- c:\progra~1\SYMNET~1\SNDMon.exe

              [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPEnh]
              2005-02-02 12:11 692316 ----a-w- c:\program files\Synaptics\SynTP\SynTPEnh.exe

              [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPLpr]
              2005-02-02 12:12 102492 ----a-w- c:\program files\Synaptics\SynTP\SynTPLpr.exe

              [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
              "%windir%\\system32\\sessmgr.exe"=
              "c:\\Memo\\Memo.exe"=
              "c:\\Program Files\\Messenger\\msmsgs.exe"=
              "c:\\Program Files\\iTunes\\iTunes.exe"=
              "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
              "c:\\Program Files\\NetMeeting\\conf.exe"=
              "c:\\Program Files\\AMD\\eMule\\emule.exe"=
              "c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
              "c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
              "c:\\Program Files\\uTorrent\\uTorrent.exe"=

              [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
              "3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
              "13657:TCP"= 13657:TCP:NortonAV
              "13278:TCP"= 13278:TCP:NortonAV
              "18854:TCP"= 18854:TCP:NortonAV
              "16560:TCP"= 16560:TCP:NortonAV
              "12659:TCP"= 12659:TCP:NortonAV
              "17244:TCP"= 17244:TCP:NortonAV
              "14211:TCP"= 14211:TCP:NortonAV
              "14012:TCP"= 14012:TCP:NortonAV
              "18925:TCP"= 18925:TCP:NortonAV
              "15591:TCP"= 15591:TCP:NortonAV
              "17605:TCP"= 17605:TCP:NortonAV
              "17272:TCP"= 17272:TCP:NortonAV
              "14821:TCP"= 14821:TCP:NortonAV
              "12936:TCP"= 12936:TCP:NortonAV
              "17954:TCP"= 17954:TCP:NortonAV
              "15481:TCP"= 15481:TCP:NortonAV
              "18311:TCP"= 18311:TCP:NortonAV
              "15997:TCP"= 15997:TCP:NortonAV
              "17426:TCP"= 17426:TCP:NortonAV
              "13607:TCP"= 13607:TCP:NortonAV
              "18832:TCP"= 18832:TCP:NortonAV

              S1 aswSP;avast! Self Protection; [x]
              S2 aswFsBlk;aswFsBlk;c:\windows\system32\DRIVERS\aswFsBlk.sys [2009-11-24 20560]
              S3 HSFHWATI;HSFHWATI;c:\windows\system32\DRIVERS\HSFHWATI.sys [2005-03-22 200192]

              [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{200a4f58-a024-11db-8a6c-0014a529f1cf}]
              \Shell\Auto\command - F:\bittorrent.exe e
              \Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL bittorrent.exe e

              [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{246e8b63-f0d0-11db-8a99-0014a529f1cf}]
              \Shell\Auto\command - bittorrent.exe e
              \Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL bittorrent.exe e

              [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{76b4f276-b653-11dd-8b3a-0014a529f1cf}]
              \Shell\AutoRun\command - G:\vtchpk.exe
              \Shell\explore\Command - G:\vtchpk.exe
              \Shell\open\Command - G:\vtchpk.exe

              [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{7bfe60e6-fe48-11de-8bad-0014a529f1cf}]
              \Shell\AutoRun\command - G:\vtchpk.exe
              \Shell\explore\Command - G:\vtchpk.exe
              \Shell\open\Command - G:\vtchpk.exe

              [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{9612e14f-f805-11db-8a9f-0014a529f1cf}]
              \Shell\Auto\command - G:\bittorrent.exe e
              \Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL bittorrent.exe e

              [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a22c269e-f3dc-11db-8a9d-0014a529f1cf}]
              \Shell\Auto\command - F:\bittorrent.exe e
              \Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL bittorrent.exe e

              [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a4d5d84c-a111-11de-8b55-0014a529f1cf}]
              \Shell\AutoRun\command - E:\vtchpk.exe
              \Shell\explore\Command - E:\vtchpk.exe
              \Shell\open\Command - E:\vtchpk.exe

              [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{d7f2e720-3b7e-11db-9b47-0014a529f1cf}]
              \Shell\AutoRun\command - F:\setupSNK.exe

              [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e68bd072-f9f4-11dc-8b08-0014a529f1cf}]
              \Shell\AutoRun\command - Autorun.exe /run
              \Shell\Shell00\Command - Autorun.exe /run
              \Shell\Shell01\Command - Autorun.exe /action
              \Shell\Shell02\Command - Autorun.exe /uninstall

              [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e88290de-ef17-11db-8a98-0014a529f1cf}]
              \Shell\Auto\command - F:\AdobeR.exe e
              \Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL AdobeR.exe e

              [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{ec7c3b36-4bbb-11db-9b56-0014a529f1cf}]
              \Shell\Auto\command - bittorrent.exe e
              \Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL bittorrent.exe e

              [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f80dde29-e78d-11db-8a90-0014a529f1cf}]
              \Shell\Auto\command - AdobeR.exe e
              \Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL AdobeR.exe e
              .
              Contenu du dossier 'Tâches planifiées'

              2010-01-11 c:\windows\Tasks\AppleSoftwareUpdate.job
              - c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 10:34]

              2010-01-11 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2553885343-4160726450-2658981467-1006Core.job
              - c:\documents and settings\Delphine\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-10-26 08:50]

              2010-01-13 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2553885343-4160726450-2658981467-1006UA.job
              - c:\documents and settings\Delphine\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-10-26 08:50]
              .
              .
              ------- Examen supplémentaire -------
              .
              uStart Page = hxxp://www.ask.com?o=13170&l=dis
              uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
              mStart Page = hxxp://www.duxet.com/
              IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office10\EXCEL.EXE/3000
              IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
              IE: Easy-WebPrint Ajouter à la liste d'impressions - c:\program files\Canon\Easy-WebPrint\Toolband.dll/RC_AddToList.html
              IE: Easy-WebPrint Impression rapide - c:\program files\Canon\Easy-WebPrint\Toolband.dll/RC_HSPrint.html
              IE: Easy-WebPrint Imprimer - c:\program files\Canon\Easy-WebPrint\Toolband.dll/RC_Print.html
              IE: Easy-WebPrint Prévisualiser - c:\program files\Canon\Easy-WebPrint\Toolband.dll/RC_Preview.html
              FF - ProfilePath - c:\documents and settings\Delphine\Application Data\Mozilla\Firefox\Profiles\iwyp4jk5.default\
              FF - prefs.js: browser.search.selectedEngine - Google
              FF - prefs.js: browser.startup.homepage - hxxp://www.google.fr/
              FF - prefs.js: keyword.URL -
              FF - plugin: c:\documents and settings\Delphine\Local Settings\Application Data\Google\Update\1.2.183.13\npGoogleOneClick8.dll
              FF - plugin: c:\program files\Java\jre1.5.0_02\bin\NPJava11.dll
              FF - plugin: c:\program files\Java\jre1.5.0_02\bin\NPJava12.dll
              FF - plugin: c:\program files\Java\jre1.5.0_02\bin\NPJava13.dll
              FF - plugin: c:\program files\Java\jre1.5.0_02\bin\NPJava14.dll
              FF - plugin: c:\program files\Java\jre1.5.0_02\bin\NPJava32.dll
              FF - plugin: c:\program files\Java\jre1.5.0_02\bin\NPJPI150_02.dll
              FF - plugin: c:\program files\Java\jre1.5.0_02\bin\NPOJI610.dll
              FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
              .
              - - - - ORPHELINS SUPPRIMES - - - -

              WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
              ShellIconOverlayIdentifiers-{8A4DE897-E609-4670-8E8F-B813B8DF31A3} - (no file)
              HKCU-Run-E06FXLRD_118855750 - c:\program files\Microsoft Encarta\Collection Microsoft Encarta 2006 DVD\EDICT.EXE
              HKCU-Run-J8RPLTROBQ - c:\docume~1\Delphine\LOCALS~1\Temp\c.exe
              HKCU-Run-LEO0WTUNO7 - c:\windows\msa.exe
              HKCU-Run-PersonalSec - c:\program files\PersonalSec\psecurity.exe
              ShellExecuteHooks-{9C15FF95-5E05-4C20-95D0-EA6509AF08FB} - (no file)
              ShellExecuteHooks-{4202332F-1CEA-47D2-8174-15A926DE583B} - (no file)
              SafeBoot-AVG Anti-Spyware Driver
              SafeBoot-AVG Anti-Spyware Guard
              MSConfigStartUp-!AVG Anti-Spyware - c:\program files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
              MSConfigStartUp-AnyDVD - c:\program files\SlySoft\AnyDVD\AnyDVD.exe
              MSConfigStartUp-Bittorrent - c:\windows\bittorrent.exe
              MSConfigStartUp-ccApp - c:\program files\Fichiers communs\Symantec Shared\ccApp.exe
              MSConfigStartUp-Cld2000 - c:\program files\Calendrier\Cld2000.exe
              MSConfigStartUp-CloneCDTray - c:\program files\SlySoft\CloneCD\CloneCDTray.exe
              MSConfigStartUp-Controleur de calendrier pour Ulead Photo Express - c:\program files\Ulead Systems\Ulead Photo Express 5 SE\calcheck.exe
              MSConfigStartUp-E06FXLRD_1041281 - c:\program files\Microsoft Encarta\Collection Microsoft Encarta 2006 DVD\EDICT.EXE
              MSConfigStartUp-E06FXLRD_1447234 - c:\program files\Microsoft Encarta\Collection Microsoft Encarta 2006 DVD\EDICT.EXE
              MSConfigStartUp-E06FXLRD_178064187 - c:\program files\Microsoft Encarta\Collection Microsoft Encarta 2006 DVD\EDICT.EXE
              MSConfigStartUp-E06FXLRD_254046 - c:\program files\Microsoft Encarta\Collection Microsoft Encarta 2006 DVD\EDICT.EXE
              MSConfigStartUp-E06FXLRD_2694968 - c:\program files\Microsoft Encarta\Collection Microsoft Encarta 2006 DVD\EDICT.EXE
              MSConfigStartUp-E06FXLRD_3590593 - c:\program files\Microsoft Encarta\Collection Microsoft Encarta 2006 DVD\EDICT.EXE
              MSConfigStartUp-E06FXLRD_7381359 - c:\program files\Microsoft Encarta\Collection Microsoft Encarta 2006 DVD\EDICT.EXE
              MSConfigStartUp-E06FXLRD_993343 - c:\program files\Microsoft Encarta\Collection Microsoft Encarta 2006 DVD\EDICT.EXE
              MSConfigStartUp-HyperappelPL2003 - c:\program files\Larousse\Petit Larousse 2003\bin\HiPL2002popup.exe
              MSConfigStartUp-Install_BlueDSL - D:\Install.exe
              MSConfigStartUp-LSBWatcher - c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
              MSConfigStartUp-MediaDico - c:\program files\Micro Application\12 DICOS Indispensables\LanceMediaDICO12.exe
              MSConfigStartUp-MsnMsgr - c:\program files\MSN Messenger\msnmsgr.exe
              MSConfigStartUp-Ulead AutoDetector - c:\program files\Ulead Systems\Ulead Photo Explorer 8.0 SE Basic\Monitor.exe
              MSConfigStartUp-VCDPlayer - c:\progra~1\VIRTUA~1\System\VCDPlay.exe
              MSConfigStartUp-VirtualCloneDrive - c:\program files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe
              MSConfigStartUp-Windows Defender - c:\program files\Windows Defender\MSASCui.exe
              MSConfigStartUp-Yahoo! Pager - c:\program files\Yahoo!\Messenger\YahooMessenger.exe
              AddRemove-Spybot - Search & Destroy_is1 - c:\windows\unins000.exe
              AddRemove-PersonalSec - c:\program files\PersonalSec\psecurity.exe

              **************************************************************************

              catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
              Rootkit scan 2010-01-13 16:23
              Windows 5.1.2600 Service Pack 3 NTFS

              Recherche de processus cachés ...

              Recherche d'éléments en démarrage automatique cachés ...

              Recherche de fichiers cachés ...

              Scan terminé avec succès
              Fichiers cachés: 0

              **************************************************************************
              .
              --------------------- CLES DE REGISTRE BLOQUEES ---------------------

              [HKEY_USERS\S-1-5-21-2553885343-4160726450-2658981467-1006\Software\Microsoft\SystemCertificates\AddressBook*]
              @Allowed: (Read) (RestrictedCode)
              @Allowed: (Read) (RestrictedCode)

              [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\Ø•€|ÿÿÿÿ•€|ù•9~*]
              "C040210900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"
              .
              --------------------- DLLs chargées dans les processus actifs ---------------------

              - - - - - - - > 'winlogon.exe'(664)
              c:\windows\system32\Ati2evxx.dll

              - - - - - - - > 'explorer.exe'(2540)
              c:\progra~1\WINDOW~1\wmpband.dll
              c:\windows\system32\eappprxy.dll
              c:\windows\system32\webcheck.dll
              c:\windows\system32\WPDShServiceObj.dll
              c:\windows\system32\PortableDeviceTypes.dll
              c:\windows\system32\PortableDeviceApi.dll
              .
              ------------------------ Autres processus actifs ------------------------
              .
              c:\windows\system32\Ati2evxx.exe
              c:\program files\Alwil Software\Avast4\aswUpdSv.exe
              c:\program files\Alwil Software\Avast4\ashServ.exe
              c:\windows\system32\Ati2evxx.exe
              c:\windows\system32\DRIVERS\CDANTSRV.EXE
              c:\program files\Fichiers communs\LightScribe\LSSrvc.exe
              c:\program files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
              c:\program files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
              c:\windows\system32\HPZipm12.exe
              c:\program files\Fichiers communs\Ulead Systems\DVD\ULCDRSvr.exe
              c:\program files\Alwil Software\Avast4\ashMaiSv.exe
              c:\program files\Alwil Software\Avast4\ashWebSv.exe
              .
              **************************************************************************
              .
              Heure de fin: 2010-01-13 16:39:44 - La machine a redémarré
              ComboFix-quarantined-files.txt 2010-01-13 15:39

              Avant-CF: 12 818 956 288 octets libres
              Après-CF: 17 435 205 632 octets libres

              - - End Of File - - E113B306BA7FF858C45C4BB1DC3C36D8
              0
              1. je viens également d'installer malwarebytes comme antispywares
                et j'ai l'impression que les fichiers que je ne pouvais pas ouvrir marche desormais.

                de quelles precautions dois je me premunir encore?
                0
            3. Contributeur sécurité
              non tu redemarre en mode sans echec, et tu lances ensuite combo (MDG.exe) que tu as déjà telechargé sur le bureau
              0
              1. Contributeur sécurité
                ????????????

                l'avais tu bien renommer AVANT de l'enregistrer sur le bureau

                sinon tentes en mode sans echec
                0
                1. OUI!!! il apparait bien sous MDG.exe ds le bureau

                  pour le mode sans echec, je n'ai pas réussi à me connecté tout à l'heure, même avec un cable ethernet
                  comment dois je faire pour me connecter et télécharger combotfix en mode sans echec?
                  0
              2. Contributeur sécurité
                ce qui te permet de réparer au cas où

                0
                1. Je bloque toujours à la même étape:
                  je clique sur MDG.exe, s'ouvre un fenêtre me demandant executer ou anuler, je clique executer, et rien ne se passe.
                  0
              3. qu'est ce que la console de recupération?
                0
                1. Contributeur sécurité
                  bon ok

                  Attention, avant de commencer, lit attentivement la procédure, et imprime la

                  Télécharge ComboFix de sUBs en le renommant MDG.exe avant de l’enregistrer sur ton Bureau :

                  http://download.bleepingcomputer.com/sUBs/ComboFix.exe

                  /!\ Déconnecte-toi du net et DESACTIVES TOUTES LES DEFENSES, antivirus et antispyware y compris /!\
                  (si tu ne peux pas, continues)

                  ---> Double-clique sur ComboFix.exe
                  Un "pop-up" va apparaître qui dit que ComboFix est utilisé à vos risques et avec aucune garantie... Clique sur oui pour accepter

                  SURTOUT INSTALLES LA CONSOLE DE RECUPERATION
                  (si il te le propose remets provisoirement internet)

                  ---> Mets-le en langue française F
                  Tape sur la touche 1 (Yes) pour démarrer le scan.

                  Ne touche à rien(souris, clavier) tant que le scan n'est pas terminé, car tu risques de planter ton PC

                  En fin de scan, il est possible que ComboFix ait besoin de redémarrer le PC pour finaliser la désinfection, laisse-le faire.

                  Une fois le scan achevé, un rapport va s'afficher : Poste son contenu

                  /!\ Réactive la protection en temps réel de ton antivirus et de ton antispyware avant de te reconnecter à Internet. /!\

                  Note : Le rapport se trouve également là : C:\ComboFix.txt

                  0
                  1. je bloque toujours à la même étape:
                    je clique sur MDG.exe, s'ouvre un fenêtre me demandant executer ou anuler, je clique executer, et rien ne se passe.
                    0
                2. Contributeur sécurité
                  grrrr

                  peux tu faire ceci

                  • Télécharge Random's System Information Tool (RSIT) de Random/Random.

                  http://images.malwareremoval.com/random/RSIT.exe

                  • Enregistre le sur ton Bureau.

                  • Double clique sur RSIT.exe pour lancer l'outil.

                  • Clique sur "Continue" à l'écran Disclaimer.

                  • Si l'outil HijackThis n'est pas présent ou non détecté sur l'ordinateur, RSIT le téléchargera (autorise l'accès dans ton pare-feu s'il te le demande)

                  et tu devras accepter la licence.

                  • Une fois le scan terminé, deux rapports vont apparaître : poste les dans deux messages séparés stp

                  Les rapports se trouvent à cet endroit:
                  C:\rsit\info.txt
                  C:\rsit\log.txt
                  0
                  1. même problème, au moment de faire exécuter, rien ne se passe, une fenêtre s'ouvre indiquant que l'accès n'est pas permis
                    0
                • 1
                • 2