Gibidl.dll est introuvable

Bonjour,
dès que je démarre mon ordinateur ce message s'affiche:
Cette application n'a pas pu démarrer car gibidl.dll est introuvable.
La réinstallation de cette application peut corriger ce problème.

j'aimerais savoir comment faire pour qu'il ne s'affiche plus, j'ai lu dans le forum qu'il fallait ouvrir son propre topic pour résoudre le problème. j'attends votre aide merci
Configuration: Windows XP  firefox 3.6

23 réponses

  1. Contributeur sécurité
    as tu toujours ce message de zone alarme ?
    0
    1. voila jai fait ce qui à été demandé. si ya autre dis moi en tout cas merci pour tout
      0
      1. voila jai fait ce qui à été demandé. si ya autre dis moi en tout cas merci pour tout
        0
        1. voici le rapport

          Kill'em by g3n-h@ckm@n 1.2.1.3

          User : Abbassi (Administrateurs)
          Update on 01/02/2010 by g3n-h@ckm@n ::::: 20.20
          Start at: 17:35:47 | 02/02/2010
          Contact : g3n-h@ckm@n sur CCM

          AMD Athlon(tm) XP 2700+
          Microsoft Windows XP Édition familiale (5.1.2600 32-bit) # Service Pack 3
          Internet Explorer 8.0.6001.18702
          Windows Firewall Status : Disabled
          AV : AntiVir Desktop 9.0.1.32 [ Enabled | Updated ]
          FW : ZoneAlarm Firewall[ Enabled ]8.0.298.000

          A:\ -> Lecteur de disquettes 3 ½ pouces
          C:\ -> Disque fixe local | 145,04 Go (40,69 Go free) [HDD] | NTFS
          D:\ -> Disque CD-ROM
          E:\ -> Disque CD-ROM
          I:\ -> Disque amovible
          J:\ -> Disque amovible

          ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Processes running

          C:\WINDOWS\System32\smss.exe
          C:\WINDOWS\system32\csrss.exe
          C:\WINDOWS\system32\winlogon.exe
          C:\WINDOWS\system32\services.exe
          C:\WINDOWS\system32\lsass.exe
          C:\WINDOWS\system32\Ati2evxx.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\system32\Ati2evxx.exe
          C:\WINDOWS\Explorer.EXE
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\system32\ZoneLabs\vsmon.exe
          C:\WINDOWS\system32\spoolsv.exe
          C:\Program Files\Avira\AntiVir Desktop\sched.exe
          C:\WINDOWS\System32\svchost.exe
          C:\Program Files\Avira\AntiVir Desktop\avguard.exe
          C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
          C:\Program Files\Bonjour\mDNSResponder.exe
          C:\Program Files\Java\jre6\bin\jqs.exe
          C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
          C:\WINDOWS\SOUNDMAN.EXE
          C:\apps\ABoard\ABoard.exe
          C:\apps\ABoard\AOSD.exe
          C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
          C:\WINDOWS\system32\slserv.exe
          C:\WINDOWS\System32\svchost.exe
          C:\Program Files\Virtual CD v4 SDK\system\vcssecs.exe
          C:\WINDOWS\wanmpsvc.exe
          C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
          C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
          C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
          C:\Program Files\QuickTime\QTTask.exe
          C:\Program Files\iTunes\iTunesHelper.exe
          C:\WINDOWS\system32\ctfmon.exe
          C:\Program Files\Microsoft ActiveSync\wcescomm.exe
          C:\Program Files\Messenger\msmsgs.exe
          C:\Program Files\SAGEM WiFi manager\WLANUTL.exe
          C:\PROGRA~1\MICROS~4\rapimgr.exe
          C:\WINDOWS\System32\alg.exe
          C:\Program Files\iPod\bin\iPodService.exe
          C:\WINDOWS\System32\wbem\wmiapsrv.exe
          C:\Program Files\Mozilla Firefox\firefox.exe
          C:\Program Files\Windows Live\Messenger\msnmsgr.exe
          C:\Program Files\Windows Live\Contacts\wlcomm.exe
          C:\Program Files\Internet Explorer\IEXPLORE.EXE
          C:\Program Files\Internet Explorer\IEXPLORE.EXE
          C:\Program Files\Windows Live\Toolbar\wltuser.exe
          C:\WINDOWS\System32\svchost.exe
          C:\Program Files\Internet Explorer\IEXPLORE.EXE
          C:\Program Files\List_Kill'em\List_Kill'em.scr
          C:\WINDOWS\system32\cmd.exe
          C:\WINDOWS\system32\wbem\wmiprvse.exe
          C:\Documents and Settings\Abbassi\Local Settings\temp\E0.tmp\pv.exe

          Detections :
          ==========

          ¤¤¤¤¤¤¤¤¤¤ Files/folders :

          Quarantined & Deleted !! : C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
          Quarantined & Deleted !! : C:\Program Files\AskBarDis
          Quarantined & Deleted !! : C:\Program Files\Fast Browser Search
          Quarantined & Deleted !! : C:\Program Files\Mozilla FireFox\Components\AskHPRFF.js
          Quarantined & Deleted !! : C:\WINDOWS\002156_.tmp
          Quarantined & Deleted !! : C:\WINDOWS\005299_.tmp
          Quarantined & Deleted !! : C:\WINDOWS\DUMP666a.tmp

          Quarantined & Deleted !! : C:\WINDOWS\system32\x3daudio1_0.dll
          Quarantined & Deleted !! : C:\WINDOWS\system32\x3daudio1_1.dll
          Quarantined & Deleted !! : C:\WINDOWS\system32\X3DAudio1_2.dll
          Quarantined & Deleted !! : C:\WINDOWS\system32\X3DAudio1_3.dll
          Quarantined & Deleted !! : C:\WINDOWS\system32\X3DAudio1_4.dll
          Quarantined & Deleted !! : C:\WINDOWS\system32\xinput9_1_0.dll
          Quarantined & Deleted !! : C:\WINDOWS\System32\drivers\etc\hosts.msn
          Quarantined & Deleted !! : C:\WINDOWS\System32\netwbix32.dll
          Quarantined & Deleted !! : C:\WINDOWS\System32\SET1A.tmp
          Quarantined & Deleted !! : C:\WINDOWS\System32\SET23.tmp
          Quarantined & Deleted !! : C:\WINDOWS\System32\SET2B.tmp
          Quarantined & Deleted !! : C:\WINDOWS\System32\SETB4.tmp
          Quarantined & Deleted !! : C:\WINDOWS\System32\SETBB.tmp
          Quarantined & Deleted !! : C:\WINDOWS\System32\SETC7.tmp
          Quarantined & Deleted !! : C:\Documents and Settings\Abbassi\Application Data\GDIPFONTCACHEV1.DAT

          ==============
          host file OK !
          ==============

          ========
          Registry
          ========
          Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{66886C4D-B307-4ECA-A228-52CA9B9851A4}
          Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\{0E5CBF21-D15F-11D0-8301-00AA005B4383}
          Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\{3041d03e-fd4b-44e0-b742-2d9b88305f98}
          Deleted : "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Install.exe"
          Deleted : "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Setup.exe"
          Deleted : HKCR\CLSID\{0702a2b6-13aa-4090-9e01-bcdc85dd933f}
          Deleted : HKCR\CLSID\{b0de3308-5d5a-470d-81b9-634fc078393b}
          Deleted : HKCU\Software\AppDataLow\AskBarDis
          Deleted : HKLM\Software\Classes\CLSID\{622fd888-4e91-4d68-84d4-7262fd0811bf}
          Deleted : HKLM\Software\Classes\TypeLib\{4B1C1E16-6B34-430E-B074-5928ECA4C150}
          Deleted : "HKLM\software\Poker 770"
          Deleted : HKLM\SYSTEM\ControlSet001\Services\winsvc
          Deleted : HKLM\SYSTEM\ControlSet003\Services\winsvc

          ============
          Disk Cleaned
          ============

          ================
          Prefetch cleaned
          ================

          ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤( EOF )¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
          0
          1. Contributeur sécurité
            ▶ Relance List&Kill'em avec le raccourci sur ton bureau ,

            mais cette fois-ci :

            ▶ choisis l'option 2 = Mode Suppression

            laisse travailler l'outil.

            en fin de scan un rapport s'ouvre

            ▶ colle le contenu dans ta reponse

            Tu peux le désinstaller ensuite

            ................................

            Cherches et cliques sur C:\Program Files\trend micro\Abbassi.exe
            Au menu principal, choisir do a scan only, puis cocher la case devant les lignes suivantes à corriger et cliquer en bas sur Fix Checked (s’il manque des lignes…pas grave)

            C:\WINDOWS\SOUNDMAN.EXE
            R3 - Default URLSearchHook is missing
            O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
            O3 - Toolbar: (no name) - {66886C4D-B307-4ECA-A228-52CA9B9851A4} - (no file)
            O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
            O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
            O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
            O4 - Global Startup: Utilitaire réseau pour SAGEM Wi-Fi 11g USB adapter.lnk =
            O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
            O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
            O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
            O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
            O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
            O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
            O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe



            0
            1. voici le rapport demander

              List'em by g3n-h@ckm@n 1.2.1.3
              User : Abbassi (Administrateurs)
              Update on 01/02/2010 by g3n-h@ckm@n ::::: 20.20
              Start at: 15:58:01 | 02/02/2010
              Contact : g3n-h@ckm@n sur CCM

              AMD Athlon(tm) XP 2700+
              Microsoft Windows XP Édition familiale (5.1.2600 32-bit) # Service Pack 3
              Internet Explorer 8.0.6001.18702
              Windows Firewall Status : Disabled
              AV : AntiVir Desktop 9.0.1.32 [ Enabled | Updated ]
              FW : ZoneAlarm Firewall[ Enabled ]8.0.298.000

              A:\ -> Lecteur de disquettes 3 ½ pouces
              C:\ -> Disque fixe local | 145,04 Go (40,68 Go free) [HDD] | NTFS
              D:\ -> Disque CD-ROM
              E:\ -> Disque CD-ROM
              I:\ -> Disque amovible
              J:\ -> Disque amovible

              ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Processes running

              C:\WINDOWS\System32\smss.exe
              C:\WINDOWS\system32\csrss.exe
              C:\WINDOWS\system32\winlogon.exe
              C:\WINDOWS\system32\services.exe
              C:\WINDOWS\system32\lsass.exe
              C:\WINDOWS\system32\Ati2evxx.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\System32\svchost.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\System32\svchost.exe
              C:\WINDOWS\system32\Ati2evxx.exe
              C:\WINDOWS\Explorer.EXE
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\system32\ZoneLabs\vsmon.exe
              C:\WINDOWS\system32\spoolsv.exe
              C:\Program Files\Avira\AntiVir Desktop\sched.exe
              C:\WINDOWS\System32\svchost.exe
              C:\Program Files\Avira\AntiVir Desktop\avguard.exe
              C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
              C:\Program Files\Bonjour\mDNSResponder.exe
              C:\Program Files\Java\jre6\bin\jqs.exe
              C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
              C:\WINDOWS\SOUNDMAN.EXE
              C:\apps\ABoard\ABoard.exe
              C:\apps\ABoard\AOSD.exe
              C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
              C:\WINDOWS\system32\slserv.exe
              C:\WINDOWS\System32\svchost.exe
              C:\Program Files\Virtual CD v4 SDK\system\vcssecs.exe
              C:\WINDOWS\wanmpsvc.exe
              C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
              C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
              C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
              C:\Program Files\QuickTime\QTTask.exe
              C:\Program Files\iTunes\iTunesHelper.exe
              C:\WINDOWS\system32\ctfmon.exe
              C:\Program Files\Microsoft ActiveSync\wcescomm.exe
              C:\Program Files\Messenger\msmsgs.exe
              C:\Program Files\SAGEM WiFi manager\WLANUTL.exe
              C:\PROGRA~1\MICROS~4\rapimgr.exe
              C:\WINDOWS\System32\alg.exe
              C:\Program Files\iPod\bin\iPodService.exe
              C:\WINDOWS\System32\wbem\wmiapsrv.exe
              C:\Program Files\Mozilla Firefox\firefox.exe
              C:\Program Files\Windows Live\Messenger\msnmsgr.exe
              C:\Program Files\Windows Live\Contacts\wlcomm.exe
              C:\Program Files\Internet Explorer\IEXPLORE.EXE
              C:\Program Files\Internet Explorer\IEXPLORE.EXE
              C:\Program Files\Windows Live\Toolbar\wltuser.exe
              C:\Program Files\Internet Explorer\IEXPLORE.EXE
              C:\Program Files\List_Kill'em\List_Kill'em.scr
              C:\WINDOWS\system32\cmd.exe
              C:\WINDOWS\system32\wbem\wmiprvse.exe
              C:\Documents and Settings\Abbassi\Local Settings\temp\19.tmp\pv.exe

              ======================
              Keys "Run"
              ======================
              [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
              WOOKIT REG_SZ C:\PROGRA~1\Wanadoo\Shell.exe appLaunchClientZone.shl|DEFAULT=cnx|PARAM=
              ctfmon.exe REG_SZ C:\WINDOWS\system32\ctfmon.exe
              H/PC Connection Agent REG_SZ "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
              MSMSGS REG_SZ "C:\Program Files\Messenger\msmsgs.exe" /background

              [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
              SoundMan REG_SZ SOUNDMAN.EXE
              ACTIVBOARD REG_SZ c:\apps\ABoard\ABoard.exe
              ATIPTA REG_SZ C:\ATI Technologies\ATI Control Panel\atiptaxx.exe
              Adobe Reader Speed Launcher REG_SZ "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
              KernelFaultCheck REG_EXPAND_SZ %systemroot%\system32\dumprep 0 -k
              TkBellExe REG_SZ "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
              avgnt REG_SZ "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
              ZoneAlarm Client REG_SZ "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
              QuickTime Task REG_SZ "C:\Program Files\QuickTime\QTTask.exe" -atboottime
              iTunesHelper REG_SZ "C:\Program Files\iTunes\iTunesHelper.exe"
              VTTimer REG_SZ VTTimer.exe

              [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices]

              [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]

              =====================
              Other Keys
              =====================
              [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
              dontdisplaylastusername REG_DWORD 0 (0x0)
              legalnoticecaption REG_SZ
              legalnoticetext REG_SZ
              shutdownwithoutlogon REG_DWORD 1 (0x1)
              undockwithoutlogon REG_DWORD 1 (0x1)

              ===============
              [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
              NoDriveAutoRun REG_DWORD 128 (0x80)
              NoDriveTypeAutoRun REG_DWORD 128 (0x80)
              HonorAutoRunSetting REG_DWORD 0 (0x0)

              ===============
              [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
              NoDriveAutoRun REG_DWORD 128 (0x80)
              NoCDBurning REG_DWORD 0 (0x0)
              NoDriveTypeAutoRun REG_DWORD 128 (0x80)
              HonorAutoRunSetting REG_DWORD 0 (0x0)

              ===============
              [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]

              ===============
              [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
              AutoRestartShell REG_DWORD 1 (0x1)
              DefaultDomainName REG_SZ SN401381390009
              DefaultUserName REG_SZ Abbassi
              LegalNoticeCaption REG_SZ
              LegalNoticeText REG_SZ
              PowerdownAfterShutdown REG_SZ 0
              ReportBootOk REG_SZ 1
              Shell REG_SZ explorer.exe
              ShutdownWithoutLogon REG_SZ 0
              System REG_SZ
              Userinit REG_SZ C:\WINDOWS\system32\userinit.exe,
              VmApplet REG_SZ rundll32 shell32,Control_RunDLL "sysdm.cpl"
              SfcQuota REG_DWORD -1 (0xffffffff)
              allocatecdroms REG_SZ 0
              allocatedasd REG_SZ 0
              allocatefloppies REG_SZ 0
              cachedlogonscount REG_SZ 10
              forceunlocklogon REG_DWORD 0 (0x0)
              passwordexpirywarning REG_DWORD 14 (0xe)
              scremoveoption REG_SZ 0
              AllowMultipleTSSessions REG_DWORD 1 (0x1)
              UIHost REG_EXPAND_SZ logonui.exe
              LogonType REG_DWORD 1 (0x1)
              Background REG_SZ 0 0 0
              DebugServerCommand REG_SZ no
              SFCDisable REG_DWORD 0 (0x0)
              WinStationsDisabled REG_SZ 0
              HibernationPreviouslyEnabled REG_DWORD 1 (0x1)
              ShowLogonOptions REG_DWORD 0 (0x0)
              AltDefaultUserName REG_SZ Abbassi
              AltDefaultDomainName REG_SZ SN401381390009
              ChangePasswordUseKerberos REG_DWORD 1 (0x1)

              ===============
              [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\AtiExtEvent]
              [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\crypt32chain]
              [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\cryptnet]
              [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\cscdll]
              [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\dimsntfy]
              [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ScCertProp]
              [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\Schedule]
              [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\sclgntfy]
              [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\SensLogn]
              [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\termsrv]
              [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\WgaLogon]
              [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\wlballoon]

              ===============
              [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
              {AEB6717E-7E19-11d0-97EE-00C04FD91972} REG_SZ

              ===============
              [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
              %windir%\system32\sessmgr.exe REG_SZ %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019
              C:\WINDOWS\system32\rtcshare.exe REG_SZ C:\WINDOWS\system32\rtcshare.exe:*:Disabled:Partage de l'application RTC
              %windir%\Network Diagnostic\xpnetdiag.exe REG_SZ %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000
              C:\Program Files\Messenger\msmsgs.exe REG_SZ C:\Program Files\Messenger\msmsgs.exe:*:Enabled:Windows Messenger
              C:\WINDOWS\SOUNDMAN.EXE REG_SZ C:\WINDOWS\SOUNDMAN.EXE:*:Enabled:SOUNDMAN
              C:\Program Files\Windows Live\Messenger\usnsvc.exe REG_SZ C:\Program Files\Windows Live\Messenger\usnsvc.exe:*:Enabled:usnsvc
              C:\Program Files\SAGEM WiFi manager\WLANUTL.EXE REG_SZ C:\Program Files\SAGEM WiFi manager\WLANUTL.EXE:*:Enabled:WLANUTL
              C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe REG_SZ C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe:*:Enabled:realsched
              C:\Program Files\QuickTime\qttask.exe REG_SZ C:\Program Files\QuickTime\qttask.exe:*:Enabled:qttask
              C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe REG_SZ C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe:*:Enabled:avgnt
              C:\WINDOWS\system32\ati2evxx.exe REG_SZ C:\WINDOWS\system32\ati2evxx.exe:*:Enabled:Ati2evxx
              C:\APPS\ABoard\AOSD.EXE REG_SZ C:\APPS\ABoard\AOSD.EXE:*:Enabled:AOSD
              C:\Program Files\Avira\AntiVir PersonalEdition Classic\guardgui.exe REG_SZ C:\Program Files\Avira\AntiVir PersonalEdition Classic\guardgui.exe:*:Enabled:GUARDGUI
              C:\Program Files\Skype\Phone\Skype.exe REG_SZ C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype
              C:\Program Files\Kyodai Mahjongg 2006\kmj.exe REG_SZ C:\Program Files\Kyodai Mahjongg 2006\kmj.exe:*:Disabled:Kyodai Mahjongg
              C:\Program Files\Microsoft ActiveSync\rapimgr.exe REG_SZ C:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
              C:\Program Files\Microsoft ActiveSync\wcescomm.exe REG_SZ C:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
              C:\Program Files\Microsoft ActiveSync\WCESMgr.exe REG_SZ C:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
              C:\Documents and Settings\Abbassi\Mes documents\WM_Abbassi Mes documents\FM2008\fm.exe REG_SZ C:\Documents and Settings\Abbassi\Mes documents\WM_Abbassi Mes documents\FM2008\fm.exe:*:Enabled:Football Manager 2008
              C:\Program Files\Windows Live\Messenger\wlcsdk.exe REG_SZ C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call
              C:\Program Files\Sports Interactive\Football Manager 2008\fm.exe REG_SZ C:\Program Files\Sports Interactive\Football Manager 2008\fm.exe:*:Disabled:Football Manager 2008
              C:\Program Files\Sports Interactive\Football Manager 2009\fm.exe REG_SZ C:\Program Files\Sports Interactive\Football Manager 2009\fm.exe:*:Disabled:Football Manager 2009
              C:\Program Files\Windows Live\Messenger\msnmsgr.exe REG_SZ C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger
              C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe REG_SZ C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe:*:Enabled:Windows Live FolderShare
              C:\Program Files\Bonjour\mDNSResponder.exe REG_SZ C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour
              C:\Program Files\iTunes\iTunes.exe REG_SZ C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes

              [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
              %windir%\system32\sessmgr.exe REG_SZ %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019
              %windir%\Network Diagnostic\xpnetdiag.exe REG_SZ %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000
              C:\Program Files\Lexmark 1400 Series\app4r.exe REG_SZ C:\Program Files\Lexmark 1400 Series\App4R.exe:*:Enabled:Lexmark Imaging Studio
              C:\Program Files\Microsoft ActiveSync\rapimgr.exe REG_SZ C:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
              C:\Program Files\Microsoft ActiveSync\wcescomm.exe REG_SZ C:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
              C:\Program Files\Microsoft ActiveSync\WCESMgr.exe REG_SZ C:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
              C:\Program Files\Windows Live\Messenger\wlcsdk.exe REG_SZ C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call
              C:\Program Files\Windows Live\Messenger\msnmsgr.exe REG_SZ C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger
              C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe REG_SZ C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe:*:Enabled:Windows Live FolderShare

              ===============
              ActivX controls
              ===============
              HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\DirectAnimation Java Classes
              HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\Microsoft XML Parser for Java
              HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{00B71CFB-6864-4346-A978-C0A14556272C}
              HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{20A60F0D-9AFA-4515-A0FD-83BD84642501}
              HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{2917297F-F02B-4B9D-81DF-494B6333150B}
              HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{5D6F45B3-9043-443D-A792-115447494D24}
              HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{67DABFBF-D0AB-41FA-9C46-CC0F21721616}
              HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{80B626D6-BC34-4BCF-B5A1-7149E4FD9CFA}
              HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{8AD9C840-044E-11D1-B3E9-00805F499D93}
              HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{8E0D4DE5-3180-4024-A327-4DFAD1796A8D}
              HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}
              HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{B8BE5E93-A60C-4D26-A2DC-220313175592}
              HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{C3F79A2B-B9B4-4A66-B012-3EE46475B072}
              HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}
              HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
              HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{D27CDB6E-AE6D-11CF-96B8-444553540000}
              HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{F6BF0D00-0B2A-4A75-BF7B-F385591623AF}

              ===============
              HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\<{12d0ed0d-0ee0-4f90-8827-78cefb8f4988}
              HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}
              HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{26923b43-4d38-484f-9b9e-de460746276c}
              HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}
              HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{CB58DED6-4AF3-4080-9DF1-DEE72075169F}
              HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{03F998B2-0E00-11D3-A498-00104B6EB52E}
              HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{08B0E5C0-4FCB-11CF-AAA5-00401C608500}
              HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{08B0E5C0-4FCB-11CF-AAA5-00401C608555}
              HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10072CEC-8CC1-11D1-986E-00A0C955B42F}
              HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{1325db73-d9f1-48f8-8895-6d814ec58889}
              HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{166B1BCA-3F9C-11CF-8075-444553540000}
              HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{1B00725B-C455-4DE6-BFB6-AD540AD427CD}
              HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{2179C5D3-EBFF-11CF-B6FD-00AA00B4E220}
              HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{22d6f312-b0f6-11d0-94ab-0080c74c7e95}
              HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{283807B5-2C60-11D0-A31D-00AA00B92C03}
              HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{2A202491-F00D-11cf-87CC-0020AFEECF20}
              HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}
              HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{36f8ec70-c29a-11d1-b5c7-0000f8051515}
              HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{3af36230-a269-11d1-b5bf-0000f8051515}
              HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{3bf42070-b3b1-11d1-b5c5-0000f8051515}
              HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{411EDCF7-755D-414E-A74B-3DCD6583F589}
              HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{4278c270-a269-11d1-b5bf-0000f8051515}
              HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}
              HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA842-CC51-11CF-AAFA-00AA00B6015B}
              HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA848-CC51-11CF-AAFA-00AA00B6015C}
              HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}
              HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA855-CC51-11CF-AAFA-00AA00B6015F}
              HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{45ea75a0-a269-11d1-b5bf-0000f8051515}
              HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{4f216970-c90c-11d1-b5c7-0000f8051515}
              HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{4f645220-306d-11d2-995d-00c04f98bbc9}
              HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{5945c046-1e7d-11d1-bc44-00c04fd912be}
              HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{5A8D6EE0-3E18-11D0-821E-444553540000}
              HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{5fd399c0-a70a-11d1-9948-00c04f98bbc9}
              HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{630b1da0-b465-11d1-9948-00c04f98bbc9}
              HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}
              HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{6fab99d0-bab8-11d1-994a-00c04f98bbc9}
              HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{7131646D-CD3C-40F4-97B9-CD9E4E6262EF}
              HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{73FA19D0-2D75-11D2-995D-00C04F98BBC9}
              HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{7790769C-0471-11d2-AF11-00C04FA35D02}
              HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{89820200-ECBD-11cf-8B85-00AA005B4340}
              HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{89820200-ECBD-11cf-8B85-00AA005B4383}
              HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{89B4C1CD-B018-4511-B0A1-5476DBF70820}
              HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{9381D8F2-0288-11D0-9501-00AA00B911A5}
              HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{B508B3F1-A24A-32C0-B310-85786919EF28}
              HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}
              HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{C9E9A340-D1F1-11D0-821E-444553540600}
              HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
              HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{CC2A9BA0-3BDD-11D0-821E-444553540000}
              HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{CDD7975E-60F8-41d5-8149-19E51D6F71D0}
              HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{D27CDB6E-AE6D-11cf-96B8-444553540000}
              HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{DAA94A2A-2A8D-4D3B-9DB8-56FBECED082D}
              HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{de5aed00-a4bf-11d1-9948-00c04f98bbc9}
              HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{E92B03AB-B707-11d2-9CBD-0000F87A369E}
              HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{F5776D81-AE53-4935-8E84-B0B283D8BCEF}

              ==============
              BHO :
              ======
              [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
              [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{53707962-6F74-2D53-2644-206D7942484F}]
              [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{5C255C8A-E604-49b4-9D64-90988571CECB}]
              [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{6EBF7485-159F-4bff-A14F-B9E3AAC4465B}]
              [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
              [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
              [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
              [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{E15A8DC0-8516-42A1-81EA-DC94EC1ACF10}]

              ================
              Internet Explorer :
              ================
              [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
              Start Page REG_SZ https://www.msn.com/fr-fr/

              [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
              Start Page REG_SZ http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome

              ========
              Services
              ========
              [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services]

              Ndisuio : 0x3
              EapHost : 0x3
              SharedAccess : 0x2
              wuauserv : 0x2

              =========
              Atapi.sys
              =========

              %%%% HASHDEEP-1.0
              %%%% size,md5,sha256,filename
              ## Invoked from: C:\Documents and Settings\Abbassi\Local Settings\temp\19.tmp
              ## C:\> hashdeep C:\WINDOWS\System32\Drivers\atapi.sys
              ##
              95360,cdfe4411a69c224bd1d11b2da92dac51,0e6b23a80f171550575bebc56f7500cd87a5cf03b2b9fdc49bc3de96282cd69d,C:\WINDOWS\System32\Drivers\atapi.sys

              Sources
              =======

              C:\WINDOWS\$NtServicePackUninstall$\atapi.sys
              C:\WINDOWS\$NtUninstallQ331060$\atapi.sys
              C:\WINDOWS\ServicePackFiles\i386\atapi.sys
              C:\WINDOWS\system32\drivers\atapi.sys

              Référence :
              ==========

              Win XP_32b : a64013e98426e1877cb653685c5c0009
              Win XP_SP2_32b : CDFE4411A69C224BD1D11B2DA92DAC51
              Win XP_SP3_32b : 9F3A2F5AA6875C72BF062C712CFA2674
              Vista_32b : e03e8c99d15d0381e02743c36afc7c6f
              Vista_SP1_32b : 2d9c903dc76a66813d350a562de40ed9
              Vista_SP2_32b : 1F05B78AB91C9075565A9D8A4B880BC4
              Vista_SP2_64b : 1898FAE8E07D97F2F6C2D5326C633FAC
              Windows 7_32b : 80C40F7FDFC376E4C5FEEC28B41C119E
              Windows 7_64b : 02062C0B390B7729EDC9E69C680A6F3C

              =======
              Drive :
              =======

              D‚fragmenteur de disque Windows
              Copyright (c) 2001 Microsoft Corp. et Executive Software International Inc.

              Rapport d'analyse
              145 Go total, 40,69 Go libre (28%), 20% fragment‚ (fragmentation du fichier 39%)

              Vous devriez d‚fragmenter ce volume.

              ¤¤¤¤¤¤¤¤¤¤ Files/folders :

              Present !! : C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
              Present !! : C:\Program Files\AskBarDis
              Present !! : C:\Program Files\Fast Browser Search
              Present !! : C:\Program Files\Mozilla FireFox\Components\AskHPRFF.js
              Present !! : C:\WINDOWS\002156_.tmp
              Present !! : C:\WINDOWS\005299_.tmp
              Present !! : C:\WINDOWS\DUMP666a.tmp
              Present !! : C:\WINDOWS\system32\x3daudio1_0.dll
              Present !! : C:\WINDOWS\system32\x3daudio1_1.dll
              Present !! : C:\WINDOWS\system32\X3DAudio1_2.dll
              Present !! : C:\WINDOWS\system32\X3DAudio1_3.dll
              Present !! : C:\WINDOWS\system32\X3DAudio1_4.dll
              Present !! : C:\WINDOWS\system32\xinput9_1_0.dll
              Present !! : C:\WINDOWS\System32\drivers\etc\hosts.msn
              Present !! : C:\WINDOWS\System32\netwbix32.dll
              Present !! : C:\WINDOWS\System32\SET1A.tmp
              Present !! : C:\WINDOWS\System32\SET23.tmp
              Present !! : C:\WINDOWS\System32\SET2B.tmp
              Present !! : C:\WINDOWS\System32\SETB4.tmp
              Present !! : C:\WINDOWS\System32\SETBB.tmp
              Present !! : C:\WINDOWS\System32\SETC7.tmp
              Present !! : C:\Documents and Settings\Abbassi\Application Data\GDIPFONTCACHEV1.DAT
              Present !! : C:\Documents and Settings\Abbassi\Application Data\GDIPFONTCACHEV1.DAT

              ¤¤¤¤¤¤¤¤¤¤ Keys :

              Present !! : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{66886C4D-B307-4ECA-A228-52CA9B9851A4}
              Present !! : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\{0E5CBF21-D15F-11D0-8301-00AA005B4383}
              Present !! : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\{3041d03e-fd4b-44e0-b742-2d9b88305f98}
              Present !! : "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Install.exe"
              Present !! : "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Setup.exe"
              Present !! : HKCR\CLSID\{0702a2b6-13aa-4090-9e01-bcdc85dd933f}
              Present !! : HKCR\CLSID\{b0de3308-5d5a-470d-81b9-634fc078393b}
              Present !! : HKCU\Software\AppDataLow\AskBarDis
              Present !! : HKLM\Software\Classes\CLSID\{0702a2b6-13aa-4090-9e01-bcdc85dd933f}
              Present !! : HKLM\Software\Classes\CLSID\{622fd888-4e91-4d68-84d4-7262fd0811bf}
              Present !! : HKLM\Software\Classes\CLSID\{b0de3308-5d5a-470d-81b9-634fc078393b}
              Present !! : HKLM\Software\Classes\TypeLib\{4B1C1E16-6B34-430E-B074-5928ECA4C150}
              Present !! : "HKLM\software\Poker 770"
              Present !! : HKLM\SYSTEM\ControlSet001\Services\winsvc
              Present !! : HKLM\SYSTEM\ControlSet003\Services\winsvc
              Present !! : HKLM\SYSTEM\CurrentControlSet\Services\winsvc

              ============

              catchme 0.3.1398.3 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
              Rootkit scan 2010-02-02 16:18:09
              Windows 5.1.2600 Service Pack 3 NTFS

              scanning hidden processes ...

              scanning hidden services & system hive ...

              scanning hidden registry entries ...

              scanning hidden files ...

              scan completed successfully
              hidden processes: 0
              hidden services: 0
              hidden files: 0

              Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

              device: opened successfully
              user: MBR read successfully
              kernel: MBR read successfully
              user & kernel MBR OK

              ==========
              Programs
              ==========

              Adobe
              AOL 8.0
              AOL Compagnon
              Apple Software Update
              Ask & Record Toolbar
              AskBardis
              ATI Technologies
              Avira
              AviSynth 2.5
              BitComet
              BitDefender
              Bonjour
              CCleaner
              ComPlus Applications
              DivX
              DVDVideoSoft
              eMule
              Fast Browser Search
              Fichiers communs
              Full Tilt Poker
              Futuremark
              Hewlett-Packard
              InstallShield Installation Information
              Internet Explorer
              iPod
              iTunes
              IVCsoft
              Java
              Kyodai Mahjongg 2006
              List_Kill'em
              lx_cats
              Malwarebytes' Anti-Malware
              Messenger
              Microsoft
              Microsoft ActiveSync
              microsoft frontpage
              Microsoft Office
              Microsoft Silverlight
              Microsoft SQL Server Compact Edition
              Microsoft Sync Framework
              Microsoft Visual Studio
              Movie Maker
              Mozilla Firefox
              MSBuild
              MSN
              MSN Gaming Zone
              MSXML 4.0
              Navilog1
              NetMeeting
              Neuf
              Nullsoft
              OpenOffice.org 2.1
              Orange HSS
              OrangeHSS
              outlook express
              PhotoFiltre
              PokerStars
              QuickTime
              Real
              Red Kawa
              Reference Assemblies
              SAGEM WiFi manager
              Saxo
              Services en ligne
              Skype
              Softwin
              Sonic
              Sports Interactive
              Spybot - Search & Destroy
              Teamspeak2_RC2
              Trend Micro
              Uninstall Information
              VideoLAN
              Viewpoint
              Virtual CD v4 SDK
              Wanadoo
              Webteh
              Windows Live
              Windows Live SkyDrive
              Windows Media Connect 2
              Windows Media Player
              Windows Mobile Device Handbook
              Windows NT
              WindowsUpdate
              WinRAR
              xerox
              Zero G Registry
              Zone Labs
              Zylom Games

              ============
              Drive C:
              ============

              7c5a66d565c941291cdd5b706c
              ACTIVDOC
              adfa85de6e96f8079cbb80ffc3c8
              APPS
              ASLog.txt
              ATI
              ATI Technologies
              autorun.inf
              b3226cfb5c6da86c8837fc4b
              bazooka
              BOOT.BAK
              BOOT.INI
              Bootfont.bin
              cleannavi.txt
              cmdcons
              cmldr
              Config.Msi
              DIVTOOLS
              Documents and Settings
              Downloads
              DRIVERS
              DSCF1024.JPG
              DWNLOG.TXT
              e9c087ecd9dad8bba69f
              ExtractLog.txt
              FLIPART.MSNFix
              GETDRIVE.MSNFix
              HighLogging.log
              IO.SYS
              IPH.PH
              JavaRa.log
              Kill'em
              List'em.txt
              logs
              lxdj.log
              MicroGaming
              MSDOS.SYS
              My Music
              NTDETECT.COM
              ntldr
              OEMCUST
              pagefile.sys
              PNP
              Poker
              Program Files
              realquas.TAG
              RECYCLER
              rsit
              SAUVE
              Setup.log
              System Volume Information
              TB.txt
              TCleaner.txt
              ToolBar SD
              UsbFix
              UsbFix.txt
              UsbFix_Upload_Me
              UsbFix_Upload_Me_SN401381390009.zip
              VProRecovery
              WINDOWS

              ¤¤¤¤¤¤¤¤¤¤ Cracks | Keygens | Serials

              C:\Documents and Settings\Abbassi\Mes documents\divers\Cl‚ USB HaGeR\Microsoft Office 2007\Serial.txt
              C:\Documents and Settings\Abbassi\Mes documents\divers\Nouveau dossier (8)\DoSSieR HaGeR\Microsoft Office 2007\Serial.txt
              C:\Documents and Settings\Abbassi\Mes documents\divers\Nouveau dossier (8)\musik\Microsoft Office 2007\Serial.txt
              C:\Documents and Settings\Abbassi\Mes documents\divers\Nouveau dossier (8)\Nouveau dossier (7)\Microsoft Office 2007\Serial.txt
              C:\Program Files\AOL 8.0\Patchw32.dll
              C:\WINDOWS\system32\Macromed\Download\Install.exe

              ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤( EOF )¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
              0
              1. Contributeur sécurité
                ok

                Desactive ton antivirus le temps de la manip ainsi que ton parefeu si présent(car il est detecté a tort comme infection)

                ▶ Télécharge et installe List&Kill'em et enregistre le sur ton bureau
                http://sd-1.archive-host.com/membres/up/829108531491024/List_Killem_Install.exe

                double clique ( clic droit "executer en tant qu'administrateur" pour Vista/7 ) sur le raccourci sur ton bureau pour lancer l'installation

                coche la case "creer une icone sur le bureau"

                une fois terminée , clic sur "terminer" et le programme se lancer seul

                choisis la langue puis choisis l'option 1 = Mode Recherche

                ▶ laisse travailler l'outil

                à l'apparition de la fenetre blanche , c'est un peu long , c'est normal , le programme n'est pas bloqué.

                un rapport du nom de catchme apparait sur ton bureau , ignore-le,ne le poste pas , mais ne le supprime pas pour l instant, le scan n'est pas fini.

                ▶ Poste le contenu du rapport qui s'ouvre aux 100 % du scan à l'ecran "COMPLETED"

                tu peux supprimer le rapport catchme.log de ton bureau maintenant.
                0
                1. jai un truc que menerve c un message sur zone alarm qui met met generic host process for win32. si je met deny jai pas internet avant javais pas ce message mais a part ca tout va bien
                  0
                  1. Contributeur sécurité
                    tu ne m'as dit si tu avais toujours des problèmes...
                    0
                    1. voila le rapport

                      Logfile of random's system information tool 1.06 (written by random/random)
                      Run by Abbassi at 2010-02-01 19:38:21
                      Microsoft Windows XP Édition familiale Service Pack 3
                      System drive C: has 41 GB (28%) free of 149 GB
                      Total RAM: 1023 MB (46% free)

                      Logfile of Trend Micro HijackThis v2.0.2
                      Scan saved at 19:38:47, on 01/02/2010
                      Platform: Windows XP SP3 (WinNT 5.01.2600)
                      MSIE: Internet Explorer v8.00 (8.00.6001.18702)
                      Boot mode: Normal

                      Running processes:
                      C:\WINDOWS\System32\smss.exe
                      C:\WINDOWS\system32\winlogon.exe
                      C:\WINDOWS\system32\services.exe
                      C:\WINDOWS\system32\lsass.exe
                      C:\WINDOWS\system32\Ati2evxx.exe
                      C:\WINDOWS\system32\svchost.exe
                      C:\WINDOWS\System32\svchost.exe
                      C:\WINDOWS\system32\svchost.exe
                      C:\WINDOWS\system32\Ati2evxx.exe
                      C:\WINDOWS\Explorer.EXE
                      C:\WINDOWS\system32\ZoneLabs\vsmon.exe
                      C:\WINDOWS\system32\spoolsv.exe
                      C:\Program Files\Avira\AntiVir Desktop\sched.exe
                      C:\Program Files\Avira\AntiVir Desktop\avguard.exe
                      C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                      C:\Program Files\Bonjour\mDNSResponder.exe
                      C:\Program Files\Java\jre6\bin\jqs.exe
                      C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
                      C:\WINDOWS\SOUNDMAN.EXE
                      C:\apps\ABoard\ABoard.exe
                      C:\apps\ABoard\AOSD.exe
                      C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
                      C:\WINDOWS\system32\slserv.exe
                      C:\WINDOWS\System32\svchost.exe
                      C:\Program Files\Virtual CD v4 SDK\system\vcssecs.exe
                      C:\WINDOWS\wanmpsvc.exe
                      C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
                      C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
                      C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
                      C:\Program Files\QuickTime\QTTask.exe
                      C:\Program Files\iTunes\iTunesHelper.exe
                      C:\WINDOWS\system32\ctfmon.exe
                      C:\Program Files\Microsoft ActiveSync\wcescomm.exe
                      C:\Program Files\Messenger\msmsgs.exe
                      C:\Program Files\SAGEM WiFi manager\WLANUTL.exe
                      C:\PROGRA~1\MICROS~4\rapimgr.exe
                      C:\WINDOWS\System32\wbem\wmiapsrv.exe
                      C:\Program Files\iPod\bin\iPodService.exe
                      C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                      C:\WINDOWS\system32\wuauclt.exe
                      C:\Program Files\Windows Live\Contacts\wlcomm.exe
                      C:\WINDOWS\System32\svchost.exe
                      C:\Program Files\Mozilla Firefox\firefox.exe
                      C:\Documents and Settings\Abbassi\Bureau\RSIT.exe
                      C:\Program Files\trend micro\Abbassi.exe

                      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer
                      R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
                      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                      R3 - Default URLSearchHook is missing
                      O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
                      O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                      O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
                      O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
                      O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
                      O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                      O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
                      O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
                      O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
                      O3 - Toolbar: (no name) - {66886C4D-B307-4ECA-A228-52CA9B9851A4} - (no file)
                      O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
                      O4 - HKLM\..\Run: [ACTIVBOARD] c:\apps\ABoard\ABoard.exe
                      O4 - HKLM\..\Run: [ATIPTA] C:\ATI Technologies\ATI Control Panel\atiptaxx.exe
                      O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
                      O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
                      O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
                      O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
                      O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
                      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
                      O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
                      O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
                      O4 - HKCU\..\Run: [WOOKIT] C:\PROGRA~1\Wanadoo\Shell.exe appLaunchClientZone.shl|DEFAULT=cnx|PARAM=
                      O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                      O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
                      O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
                      O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
                      O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\FICHIE~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
                      O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
                      O4 - Global Startup: Utilitaire réseau pour SAGEM Wi-Fi 11g USB adapter.lnk = ?
                      O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
                      O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
                      O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~4\INetRepl.dll
                      O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~4\INetRepl.dll
                      O9 - Extra 'Tools' menuitem: Créer un Favori de l'appareil mobile... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~4\INetRepl.dll
                      O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
                      O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                      O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                      O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                      O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                      O14 - IERESET.INF: START_PAGE_URL=file://C:\APPS\IE\offline\fr.htm
                      O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
                      O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
                      O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab
                      O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.cab
                      O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - http://download.divx.com/webplayer/stage6/windows/AutoDLDivXWebPlayerInstaller.cab
                      O16 - DPF: {80B626D6-BC34-4BCF-B5A1-7149E4FD9CFA} (UnoCtrl Class) - http://zone.msn.com/bingame/zpagames/GAME_UNO1.cab60096.cab
                      O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
                      O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/ZPAFramework.cab102118.cab
                      O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
                      O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
                      O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab31267.cab
                      O23 - Service: Avira AntiVir Planificateur (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
                      O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
                      O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                      O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
                      O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
                      O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
                      O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1150\Intel 32\IDriverT.exe
                      O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
                      O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
                      O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe
                      O23 - Service: Virtual CD v4 Security service (SDK - Version) (VCSSecS) - H+H Software GmbH - C:\Program Files\Virtual CD v4 SDK\system\vcssecs.exe
                      O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
                      O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
                      O23 - Service: Gestionnaire de mise à jour Winsudate (WinSvc) - Unknown owner - C:\Program Files\Winsudate\gibsvc.exe (file missing)
                      0
                      1. Contributeur sécurité
                        ok

                        comment va le pc ?

                        relances RSIT et poste le rapport log stp
                        0
                        1. voici le dernier rapport

                          Malwarebytes' Anti-Malware 1.44
                          Version de la base de données: 3672
                          Windows 5.1.2600 Service Pack 3
                          Internet Explorer 8.0.6001.18702

                          01/02/2010 18:26:12
                          mbam-log-2010-02-01 (18-26-12).txt

                          Type de recherche: Examen complet (A:\|C:\|D:\|E:\|I:\|J:\|)
                          Eléments examinés: 214675
                          Temps écoulé: 2 hour(s), 5 minute(s), 51 second(s)

                          Processus mémoire infecté(s): 0
                          Module(s) mémoire infecté(s): 0
                          Clé(s) du Registre infectée(s): 0
                          Valeur(s) du Registre infectée(s): 1
                          Elément(s) de données du Registre infecté(s): 0
                          Dossier(s) infecté(s): 1
                          Fichier(s) infecté(s): 2

                          Processus mémoire infecté(s):
                          (Aucun élément nuisible détecté)

                          Module(s) mémoire infecté(s):
                          (Aucun élément nuisible détecté)

                          Clé(s) du Registre infectée(s):
                          (Aucun élément nuisible détecté)

                          Valeur(s) du Registre infectée(s):
                          HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\winusr (Adware.Gibmedia) -> Quarantined and deleted successfully.

                          Elément(s) de données du Registre infecté(s):
                          (Aucun élément nuisible détecté)

                          Dossier(s) infecté(s):
                          C:\Program Files\Winsudate (Adware.Gibmedia) -> Quarantined and deleted successfully.

                          Fichier(s) infecté(s):
                          C:\Program Files\Winsudate\gibupt.exe (Adware.Gibmedia) -> Quarantined and deleted successfully.
                          C:\UsbFix\Quarantine\C\RECYCLER\S-1-5-21-3046840070-1875883765-231225164-8348\rundll32.exe.UsbFix (Worm.Autorun.B) -> Quarantined and deleted successfully.
                          0
                          1. Contributeur sécurité
                            bien

                            ==> MBAM donc, c'est un peu plus long..
                            0
                            1. voici le rapport cleannavi.txt

                              Fix Navipromo version 4.0.6 commencé le 01/02/2010 15:50:19,43

                              !!! Attention,ce rapport peut indiquer des fichiers/programmes légitimes!!!
                              !!! Postez ce rapport sur le forum pour le faire analyser !!!

                              Outil exécuté depuis C:\Program Files\navilog1

                              Mise à jour le 03.01.2010 à 11h00 par IL-MAFIOSO

                              Microsoft Windows XP Édition familiale ( v5.1.2600 ) Service Pack 3
                              X86-based PC ( Uniprocessor Free : AMD Athlon(tm) XP 2700+ )
                              BIOS : Phoenix - AwardBIOS v6.00PG
                              USER : Abbassi ( Administrator )
                              BOOT : Normal boot

                              Antivirus : AntiVir Desktop 9.0.1.32 (Activated)
                              Firewall : ZoneAlarm Firewall 8.0.298.000 (Activated)

                              A:\ (USB)
                              C:\ (Local Disk) - NTFS - Total:145 Go (Free:40 Go)
                              D:\ (CD or DVD)
                              E:\ (CD or DVD)
                              I:\ (USB)
                              J:\ (USB)

                              Recherche executée en mode normal

                              Nettoyage exécuté au redémarrage de l'ordinateur

                              C:\WINDOWS\system32\jyqzcmm.dat supprimé !
                              C:\WINDOWS\system32\ygqeq.dat.bd.ren supprimé !
                              C:\WINDOWS\system32\ygqeq_nav.dat.bd.ren supprimé !
                              C:\WINDOWS\system32\ygqeq_navps.dat.bd.ren supprimé !
                              C:\WINDOWS\system32\ygqeq_navup.dat.bd.ren supprimé !
                              c:\docume~1\abbassi\locals~1\applic~1\aifzg_nav.dat supprimé !
                              c:\docume~1\abbassi\locals~1\applic~1\aifzg_navps.dat supprimé !

                              Nettoyage contenu C:\WINDOWS\Temp effectué !
                              Nettoyage contenu C:\Documents and Settings\Abbassi\locals~1\Temp effectué !

                              *** Sauvegarde du Registre vers dossier Safebackup ***

                              sauvegarde du Registre réalisée avec succès !

                              *** Nettoyage Registre ***

                              Nettoyage Registre Ok

                              Certificat OOO-Favorit supprimé !

                              *** Scan terminé 01/02/2010 15:54:35,06 ***
                              0
                              1. Contributeur sécurité
                                vu

                                attends avant de lancer MBAM

                                fais ceci avant

                                Infection Navipromo….Pour info :

                                Il s'installe via certains programmes, dont ceux-ci qu'il faut éviter à tout prix:
                                * Funky Emoticons
                                * go-astro
                                * Games Attack
                                * GoRecord
                                * HotTVPlayer / HotTVPlayer & Paris Hilton
                                * Live-Player
                                * MailSkinner
                                * Messenger Skinner
                                * Instant Access
                                * InternetGameBox
                                * Officiale Emule (Version d'Emule modifiée)
                                * Original Solitaire
                                * SuperSexPlayer
                                * Speed Downloading
                                * Sudoplanet
                                * Webmediaplayer

                                il faudrait télécharge navilog1 sur le bureau :
                                http://perso.orange.fr/il.mafioso/Navifix/Navilog1.exe

                                Certaines infections bloquent les téléchargements d' outils de désinfection utilisez ce lien alternatif:
                                http://ww38.toofiles.com/fr/oip/documents/exe/yop3.html

                                1°Double-clique sur navilog1.exe présent sur ton bureau
                                2°Sélectionnez la langue désirée dans le menu puis valide le choix par la touche « entrer »
                                3°Petit message d’avertissement, appuyez sur une touche pour passe à la suite
                                4°un nouveau avertissement, appuie sur une touche pour suivre
                                5°Vérification de l’installation de Navilog1 : si tout est bon, appuyez sur une touche pour continuer
                                6°Choisir option 1 : recherche/désinfection automatique
                                7°La recherche va se lancer automatiquement et peut durée quelques minutes, patientez
                                8°Une fois l’analyse terminé, fermez et enregistrez votre travail en cours, puis appuiez sur une touche pour que votre pc puisse démarrer
                                9°Au redémarrage du pc, Navilog va supprimer ce qu’il a trouvé, patientez quelques instants.

                                Un rapport est gèneré par l'outil. Il se trouve à cette emplacement :
                                XP : demarrer/poste de travail/c:/cleannavi.txt
                                0
                                1. voici le rapport TB.txt

                                  -----------\\ ToolBar S&D 1.2.9 XP/Vista

                                  Microsoft Windows XP Édition familiale ( v5.1.2600 ) Service Pack 3
                                  X86-based PC ( Uniprocessor Free : AMD Athlon(tm) XP 2700+ )
                                  BIOS : Phoenix - AwardBIOS v6.00PG
                                  USER : Abbassi ( Administrator )
                                  BOOT : Normal boot
                                  Antivirus : AntiVir Desktop 9.0.1.32 (Activated)
                                  Firewall : ZoneAlarm Firewall 8.0.298.000 (Activated)
                                  A:\ (USB)
                                  C:\ (Local Disk) - NTFS - Total:145 Go (Free:40 Go)
                                  D:\ (CD or DVD)
                                  E:\ (CD or DVD)
                                  I:\ (USB)
                                  J:\ (USB)

                                  "C:\ToolBar SD" ( MAJ : 22-08-2009|18:42 )
                                  Option : [2] ( 01/02/2010|15:40 )

                                  -----------\\ SUPPRESSION

                                  Supprime! - C:\Program Files\AskBarDis\bar
                                  Supprime! - C:\Program Files\AskBarDis\unins00.exe
                                  Supprime! - C:\Program Files\AskBarDis\unins000.dat
                                  Supprime! - C:\Program Files\AskBarDis\unins000.exe
                                  Supprime! - C:\Program Files\AskBarDis\zonealarm.ico
                                  Supprime! - C:\Program Files\Multi_Media_France\INSTALL.LOG
                                  Supprime! - C:\Program Files\AskBarDis
                                  Supprime! - C:\Program Files\Multi_Media_France

                                  -----------\\ Recherche de Fichiers / Dossiers ...

                                  -----------\\ Extensions

                                  (Abbassi) - {3112ca9c-de6d-4884-a869-9855de68056c} => google-toolbar
                                  (Abbassi) - {635abd67-4fe9-1b23-4f01-e679fa7484c1} => ytoolbar
                                  (Abbassi) - {b9db16a4-6edc-47ec-a1f4-b86292ed211d} => dwhelper
                                  (Abbassi) - {b9db16a4-6edc-47ec-a1f4-b86292ed211d} => dwhelper
                                  (Abbassi) - {C2DCA7EB-22D2-4FD2-86A9-F99FCC8122BB} => fbstoolbar
                                  (Abbassi) - {E9A1DEE0-C623-4439-8932-001E7D17607D} => ajtoolbar

                                  -----------\\ [..\Internet Explorer\Main]

                                  [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
                                  "Local Page"="C:\\WINDOWS\\system32\\blank.htm"
                                  "Search Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"
                                  "Start Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome"
                                  "Default_Page_URL"="https://www.msn.com/fr-fr/?ocid=iehp"

                                  [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
                                  "Default_Page_URL"="https://www.msn.com/fr-fr/?ocid=iehp"
                                  "Default_Search_URL"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
                                  "Search Page"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
                                  "Local Page"="C:\\WINDOWS\\system32\\blank.htm"
                                  "Start Page"="https://www.msn.com/fr-fr/"

                                  --------------------\\ Recherche d'autres infections

                                  C:\DOCUME~1\Abbassi\LOCALS~1\APPLIC~1\aifzg_nav.dat
                                  C:\DOCUME~1\Abbassi\LOCALS~1\APPLIC~1\aifzg_navps.dat
                                  C:\WINDOWS\System32\ygqeq.dat.bd.ren
                                  C:\WINDOWS\System32\ygqeq_nav.dat.bd.ren
                                  C:\WINDOWS\System32\ygqeq_navps.dat.bd.ren
                                  C:\WINDOWS\System32\ygqeq_navup.dat.bd.ren
                                  [b]==> EGDACCESS <==/b

                                  --------------------\\ Cracks & Keygens ..

                                  C:\DOCUME~1\Abbassi\Bureau\iphone\club\Eminem - Crack A Bottle [Feat Dr Dre & 50 Cent]lyrics.mp3
                                  C:\DOCUME~1\Abbassi\Mes documents\divers\4757\Eminem - Crack A Bottle [Feat Dr Dre & 50 Cent]lyrics.mp3
                                  C:\DOCUME~1\Abbassi\Mes documents\divers\cd clio\Eminem - Crack A Bottle [Feat Dr Dre & 50 Cent]lyrics.mp3
                                  C:\DOCUME~1\Abbassi\Mes documents\divers\Cl‚ USB HaGeR\son de la mort\Eminem - Crack A Bottle [Feat Dr Dre & 50 Cent]lyrics.mp3
                                  C:\DOCUME~1\Abbassi\Mes documents\DVDVideoSoft\FreeYouTubeToMP3Converter\Eminem - Crack A Bottle [Feat Dr Dre & 50 Cent]lyrics.mp3

                                  1 - "C:\ToolBar SD\TB_1.txt" - 01/02/2010|15:42 - Option : [2]

                                  -----------\\ Fin du rapport a 15:42:24,92
                                  0
                                  1. voici le rapport usbfix.txt

                                    ############################## | UsbFix V6.084 |

                                    User : Abbassi (Administrateurs) # SN401381390009
                                    Update on 01/02/2010 by El Desaparecido , C_XX & Chimay8
                                    Start at: 15:21:07 | 01/02/2010
                                    Website : http://pagesperso-orange.fr/NosTools/index.html
                                    Contact : FindyKill.Contact@gmail.com

                                    AMD Athlon(tm) XP 2700+
                                    Microsoft Windows XP Édition familiale (5.1.2600 32-bit) # Service Pack 3
                                    Internet Explorer 8.0.6001.18702
                                    Windows Firewall Status : Enabled
                                    AV : AntiVir Desktop 9.0.1.32 [ Enabled | Updated ]
                                    FW : ZoneAlarm Firewall[ Enabled ]8.0.298.000

                                    A:\ -> Lecteur de disquettes 3 ½ pouces
                                    C:\ -> Disque fixe local # 145,04 Go (40,66 Go free) [HDD] # NTFS
                                    D:\ -> Disque CD-ROM
                                    E:\ -> Disque CD-ROM
                                    I:\ -> Disque amovible
                                    J:\ -> Disque amovible

                                    ############################## | Processus actifs |

                                    C:\WINDOWS\System32\smss.exe
                                    C:\WINDOWS\system32\csrss.exe
                                    C:\WINDOWS\system32\winlogon.exe
                                    C:\WINDOWS\system32\services.exe
                                    C:\WINDOWS\system32\lsass.exe
                                    C:\WINDOWS\system32\Ati2evxx.exe
                                    C:\WINDOWS\system32\svchost.exe
                                    C:\WINDOWS\system32\svchost.exe
                                    C:\WINDOWS\System32\svchost.exe
                                    C:\WINDOWS\system32\svchost.exe
                                    C:\WINDOWS\System32\svchost.exe
                                    C:\WINDOWS\system32\Ati2evxx.exe
                                    C:\WINDOWS\system32\svchost.exe
                                    C:\WINDOWS\Explorer.EXE
                                    C:\WINDOWS\system32\ZoneLabs\vsmon.exe
                                    C:\WINDOWS\system32\spoolsv.exe
                                    C:\Program Files\Avira\AntiVir Desktop\sched.exe
                                    C:\WINDOWS\System32\svchost.exe
                                    C:\Program Files\Avira\AntiVir Desktop\avguard.exe
                                    C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                                    C:\Program Files\Bonjour\mDNSResponder.exe
                                    C:\Program Files\Java\jre6\bin\jqs.exe
                                    C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
                                    C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
                                    C:\WINDOWS\system32\slserv.exe
                                    C:\WINDOWS\System32\svchost.exe
                                    C:\Program Files\Virtual CD v4 SDK\system\vcssecs.exe
                                    C:\WINDOWS\wanmpsvc.exe
                                    C:\Program Files\Winsudate\gibsvc.exe
                                    C:\WINDOWS\system32\wuauclt.exe
                                    C:\WINDOWS\system32\wbem\wmiprvse.exe
                                    C:\WINDOWS\system32\wbem\wmiprvse.exe
                                    C:\WINDOWS\System32\alg.exe

                                    ################## | Elements infectieux |

                                    Supprimé ! C:\GETBOOTD.BAT
                                    Supprimé ! C:\Recycler\S-1-5-21-3046840070-1875883765-231225164-8348\rundll32.exe
                                    Supprimé ! C:\Recycler\S-1-5-21-3046840070-1875883765-231225164-8348\Desktop.ini
                                    Supprimé ! C:\Recycler\S-1-5-21-3046840070-1875883765-231225164-8348
                                    Supprimé ! C:\Recycler\S-1-5-18
                                    Supprimé ! C:\Recycler\S-1-5-21-482117970-2289595660-1097813078-1007

                                    ################## | Registre |

                                    Supprimé ! [HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer] "NoDrives"
                                    Supprimé ! [HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer] "NoDrives"

                                    ################## | Mountpoints2 |

                                    Supprimé ! HKCU\...\Explorer\MountPoints2\{211a69ec-3343-11dd-954a-00038a000015}\Shell\AutoRun\Command
                                    Supprimé ! HKCU\...\Explorer\MountPoints2\{319ce751-60f6-11de-97ad-00038a000015}\Shell\AutoRun\Command
                                    Supprimé ! HKCU\...\Explorer\MountPoints2\{b53bdca2-9c10-11dc-9454-00038a000015}\Shell\AutoRun\Command
                                    Supprimé ! HKCU\...\Explorer\MountPoints2\{d1bf4046-94a0-11de-9820-00038a000015}\Shell\AutoRun\Command
                                    Supprimé ! HKCU\...\Explorer\MountPoints2\{e3c06d06-3bfb-11de-9758-00038a000015}\Shell\AutoRun\Command

                                    ################## | Listing des fichiers présent |

                                    [05/01/2010 00:46|--a------|33958] C:\ASLog.txt
                                    [11/11/2003 02:06|-rahs----|193] C:\BOOT.BAK
                                    [23/07/2006 13:34|-rahs----|291] C:\BOOT.INI
                                    [30/08/2002 13:00|-rahs----|4952] C:\Bootfont.bin
                                    [30/08/2002 13:00|-rahs----|249136] C:\cmldr
                                    [09/12/2008 18:14|--a------|2669858] C:\DSCF1024.JPG
                                    [11/11/2003 02:55|--a------|6238] C:\DWNLOG.TXT
                                    [15/02/2007 21:22|--a------|446067] C:\ExtractLog.txt
                                    [09/03/2000 09:06|--a------|28680] C:\FLIPART.MSNFix
                                    [29/08/2002 15:03|--a------|6384] C:\GETDRIVE.MSNFix
                                    [12/08/2008 11:04|--a------|752] C:\HighLogging.log
                                    [04/07/2006 19:02|-rahs----|0] C:\IO.SYS
                                    [11/11/2003 02:12|--ah-----|456] C:\IPH.PH
                                    [30/12/2008 02:38|--a------|6018] C:\JavaRa.log
                                    [29/12/2008 19:35|--a------|15244] C:\lxdj.log
                                    [04/07/2006 19:02|-rahs----|0] C:\MSDOS.SYS
                                    [04/07/2006 18:45|-rahs----|47564] C:\NTDETECT.COM
                                    [31/12/2008 00:40|-rahs----|252240] C:\ntldr
                                    [?|?|?] C:\pagefile.sys
                                    [11/11/2003 02:02|--a------|20] C:\realquas.TAG
                                    [29/09/2006 14:05|--a------|90] C:\Setup.log
                                    [30/12/2008 23:04|--a------|1782] C:\TCleaner.txt
                                    [01/02/2010 15:26|--a------|4472] C:\UsbFix.txt

                                    ################## | Vaccination |

                                    # C:\autorun.inf -> Dossier créé par UsbFix.
                                    0
                                    1. Contributeur sécurité
                                      ok

                                      plusieurs infections

                                      à faire dans cet ordre et poster les rapports au fur et à mesure

                                      1)
                                      Téléchargez USBFIX de El Desaparecido, C_xx

                                      http://pagesperso-orange.fr/NosTools/Chiquitine29/UsbFix.exe
                                      ou
                                      https://www.ionos.fr/?affiliate_id=77097

                                      /!\ Utilisateur de vista et windows 7 :
                                      ne pas oublier de désactiver Le contrôle des comptes utilisateurs
                                      https://www.commentcamarche.net/faq/8343-vista-desactiver-l-uac

                                      /!\ Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) susceptible d'avoir été infectées sans les ouvrir

                                      • Double clic sur le raccourci UsbFix présent sur le bureau .

                                      • Choisir l'option2 suppression
                                      (d’autres options disponibles, voir le tutoriel).
                                      • Laissez travailler l'outil.
                                      Le menu démarrer et les icônes vont disparaître.. c'est normal.

                                      Si un message te demande de redémarrer l'ordinateur fais le ...

                                      ● Au redémarrage, le fix se relance... laisses l'opération s'effectuer.

                                      ● Le bloc note s'ouvre avec un rapport, envoies le dans la prochaine réponse

                                      • Note : Le rapport UsbFix.txt est sauvegardé a la racine du disque. ( C:\UsbFix.txt )

                                      ( CTRL+A Pour tout sélectionner , CTRL+C pour copier et CTRL+V pour coller )

                                      • Note : "Process.exe", une composante de l'outil, est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool.
                                      Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.
                                      Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall...) d'où l'alerte émise par ces antivirus.

                                      • Tuto : http://pagesperso-orange.fr/NosTools/usbfix.html

                                      UsbFix peut te demander d'uploader un dossier compressé à cette adresse : https://www.ionos.fr/?affiliate_id=77097

                                      Il est enregistré sur ton bureau.

                                      Merci de l'envoyer à l'adresse indiquée afin d'aider l'auteur de UsbFix dans ses recherches.

                                      .....................

                                      2)
                                      Téléchargez Toolbar-S&D ( Merci à Eric_71, Angel Dark, Sham_Rock et XmichouX ) sur le Bureau

                                      https://77b4795d-a-62cb3a1a-s-sites.googlegroups.com/site/eric71mespages/ToolBarSD.exe?attachauth=ANoY7cpVobGk5bHnxrhQ4yaoEUDJvOYNnEGyYjgqHZz5GqZLfutR3fMFPlsC3-CGIilfupPAguYATNyua3csodN_frdMK8sSzUpit10Yac-QJCOkMqJKkbdKcP6ySs8trWPgoNVIq4TGGWCe6o0txXQv-ZueJF9vZzw3RXsGwFYIqN2lvF2LPdQzS8mE1d5kWOVOz6EMzQuE5-lClSJM869uq3oc7-t7yg%3D%3D&attredirects=3

                                      Lancez l'installation du programme en exécutant le fichier téléchargé.
                                      Double-cliquez maintenant sur le raccourci de Toolbar-S&D.
                                      Sélectionnez la langue souhaitée en tapant la lettre de ton choix puis en validant avec la touche Entrée.
                                      Choisir maintenant l'option 2 suppression
                                      Patientez jusqu'à la fin de la recherche.
                                      Postez le rapport généré. (C:\TB.txt)

                                      Tuto: https://sites.google.com/site/toolbarsd/aideenimages

                                      ........................

                                      3)

                                      Téléchargez MalwareByte's Anti-Malware

                                      http://www.malwarebytes.org/mbam/program/mbam-setup.exe

                                      . Enregistres le sur le bureau
                                      . Double cliques sur le fichier téléchargé pour lancer le processus d'installation.
                                      . Dans l'onglet "mise à jour", cliques sur le bouton Recherche de mise à jour
                                      . Si le pare-feu demande l'autorisation de se connecter pour malwarebytes, accepte
                                      . Une fois la mise à jour terminé
                                      . Rend-toi dans l'onglet, Recherche
                                      . Sélectionnes Exécuter un examen complet (examen assez long)
                                      . Cliques sur Rechercher
                                      . Le scan démarre.
                                      . A la fin de l'analyse, un message s'affiche : L'examen s'est terminé normalement. Cliquez sur 'Afficher les résultats' pour afficher tous les objets trouvés.
                                      . Cliques sur Ok pour poursuivre.
                                      . Si des malwares ont été détectés, clique sur Afficher les résultats
                                      . Sélectionnes tout (ou laisses cochés) et cliques sur Supprimer la sélection Malwarebytes va détruire les fichiers et clés de registre et en mettre une copie dans la quarantaine.
                                      . Malwarebytes va ouvrir le bloc-notes et y copier le rapport d'analyse.
                                      . Rends toi dans l'onglet rapport/log
                                      . Tu cliques dessus pour l'afficher, une fois affiché
                                      . Tu cliques sur edition en haut du boc notes, et puis sur sélectionner tous
                                      . Tu recliques sur edition et puis sur copier et tu reviens sur le forum et dans ta réponse
                                      . tu cliques droit dans le cadre de la reponse et coller

                                      Si tu as besoin d'aide regarde ces tutoriels :
                                      Aide: https://www.malekal.com/tutoriel-malwarebyte-anti-malware/
                                      http://www.infos-du-net.com/forum/278396-11-tuto-malwarebytes-anti-malware-mbam

                                      0
                                      1. voici le rapport info:

                                        info.txt logfile of random's system information tool 1.06 2010-02-01 11:24:12

                                        ======Uninstall list======

                                        -->C:\PROGRA~1\FICHIE~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{09B44E78-A988-4BC0-962F-63ECD3333708} /l1036
                                        -->C:\Program Files\Fichiers communs\aolshare\Aolunins_fr.exe
                                        -->C:\Program Files\Fichiers communs\Real\Update_OB\rnuninst.exe RealNetworks|RealPlayer|6.0
                                        -->C:\Program Files\Fichiers communs\Real\Update_OB\rnuninst.exe RealNetworks|RealPlayer|6.0
                                        -->C:\WINDOWS\IsUn040c.exe -fC:\WINDOWS\orun32.isu
                                        -->C:\WINDOWS\Modio\SLAMR2KO\Setup.exe /Remove
                                        -->C:\WINDOWS\System32\\MSIEXEC.EXE /x {9541FED0-327F-4df0-8B96-EF57EF622F19}
                                        -->C:\WINDOWS\unvise32qt.exe C:\WINDOWS\System32\QuickTime\Uninstall.log
                                        -->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{0BEDBD4E-2D34-47B5-9973-57E62B29307C}\setup.exe"
                                        -->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{2637C347-9DAD-11D6-9EA2-00055D0CA761}\Setup.EXE" -uninstall
                                        -->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{B7A0CE06-068E-11D6-97FD-0050BACBF861}\SETUP.EXE" -uninstall
                                        -->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
                                        Adobe Flash Player 10 ActiveX-->C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
                                        Adobe Flash Player 10 Plugin-->C:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe
                                        Adobe Reader 9.1.3 - Français-->MsiExec.exe /I{AC76BA86-7AD7-1036-7B44-A91000000001}
                                        Apple Application Support-->MsiExec.exe /I{3FA365DF-2D68-45ED-8F83-8C8A33E65143}
                                        Apple Mobile Device Support-->MsiExec.exe /I{AADEA55D-C834-4BCB-98A3-4B8D1C18F4EE}
                                        Apple Software Update-->MsiExec.exe /I{6956856F-B6B3-4BE0-BA0B-8F495BE32033}
                                        Archiveur WinRAR-->C:\Program Files\WinRAR\uninstall.exe
                                        Ask Toolbar-->"C:\Program Files\AskBarDis\unins000.exe"
                                        Assistant de connexion Windows Live-->MsiExec.exe /I{D3116CC7-24DC-4CA3-9CE1-23FED836E9F2}
                                        ATI - Software Uninstall Utility-->C:\Program Files\ATI Technologies\UninstallAll\AtiCimUn.exe
                                        ATI Display Driver-->rundll32 C:\WINDOWS\system32\atiiiexx.dll,_InfEngUnInstallINFFile_RunDLL@16 -force_restart -flags:0x2010001 -inf_class:DISPLAY -clean
                                        Avira AntiVir Personal - Free Antivirus-->C:\Program Files\Avira\AntiVir Desktop\setup.exe /REMOVE
                                        AviSynth 2.5-->"C:\Program Files\AviSynth 2.5\Uninstall.exe"
                                        Bonjour-->MsiExec.exe /I{07287123-B8AC-41CE-8346-3D777245C35B}
                                        CCleaner (remove only)-->"C:\Program Files\CCleaner\uninst.exe"
                                        Correctif pour Lecteur Windows Media 11 (KB939683)-->"C:\WINDOWS\$NtUninstallKB939683$\spuninst\spuninst.exe"
                                        Correctif pour Windows Internet Explorer 7 (KB947864)-->"C:\WINDOWS\ie7updates\KB947864-IE7\spuninst\spuninst.exe"
                                        Correctif pour Windows XP (KB952287)-->"C:\WINDOWS\$NtUninstallKB952287$\spuninst\spuninst.exe"
                                        Correctif pour Windows XP (KB961118)-->"C:\WINDOWS\$NtUninstallKB961118$\spuninst\spuninst.exe"
                                        Correctif pour Windows XP (KB970653-v3)-->"C:\WINDOWS\$NtUninstallKB970653-v3$\spuninst\spuninst.exe"
                                        Correctif pour Windows XP (KB976098-v2)-->"C:\WINDOWS\$NtUninstallKB976098-v2$\spuninst\spuninst.exe"
                                        DivX Content Uploader-->C:\Program Files\DivX\DivXContentUploaderUninstall.exe /CUPLOADER
                                        Full Tilt Poker-->"C:\Program Files\InstallShield Installation Information\{D4C9692E-4EFA-4DA0-8B7F-9439466D9E31}\setup.exe" -runfromtemp -l0x040c -removeonly
                                        Galerie de photos Windows Live-->MsiExec.exe /X{B131E59D-202C-43C6-84C9-68F0C37541F1}
                                        HijackThis 2.0.2-->"C:\Program Files\trend micro\HijackThis.exe" /uninstall
                                        Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)-->C:\WINDOWS\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall /qb+ REBOOTPROMPT=""
                                        Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)-->C:\WINDOWS\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {A7EEA2F2-BFCD-4A54-A575-7B81A786E658} /qb+ REBOOTPROMPT=""
                                        Hotfix for Windows Media Format 11 SDK (KB929399)-->"C:\WINDOWS\$NtUninstallKB929399$\spuninst\spuninst.exe"
                                        Installation Windows Live-->C:\Program Files\Windows Live\Installer\wlarp.exe
                                        Installation Windows Live-->MsiExec.exe /I{46ABBC54-1872-4AA3-95E2-F2C063A63F31}
                                        iTunes-->MsiExec.exe /I{A6FDF86A-F541-4E7B-AEA0-8849A2A700D5}
                                        Java(TM) 6 Update 11-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216011FF}
                                        Junk Mail filter update-->MsiExec.exe /I{E2DFE069-083E-4631-9B6C-43C48E991DE5}
                                        Lecteur Windows Media 11-->"C:\Program Files\Windows Media Player\Setup_wm.exe" /Uninstall
                                        Livebox-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{FC7DDAAE-7F2B-4270-9BFD-5A130B667E9E}\Setup.exe" -l0x40c
                                        Malwarebytes' Anti-Malware-->"C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
                                        Manuel de l'appareil Windows Mobile®-->C:\Program Files\Windows Mobile Device Handbook\Windows Mobile Device Handbook\Bin\DHUninstall.exe
                                        Microsoft .NET Framework 1.1 Security Update (KB953297)-->"C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\hotfix.exe" "C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\M953297\M953297Uninstall.msp"
                                        Microsoft .NET Framework 1.1-->msiexec.exe /X {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
                                        Microsoft .NET Framework 1.1-->MsiExec.exe /X{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
                                        Microsoft .NET Framework 2.0 Service Pack 2-->MsiExec.exe /I{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}
                                        Microsoft .NET Framework 3.0 Service Pack 2-->MsiExec.exe /I{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}
                                        Microsoft .NET Framework 3.5 SP1-->C:\WINDOWS\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setup.exe
                                        Microsoft .NET Framework 3.5 SP1-->MsiExec.exe /I{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}
                                        Microsoft ActiveSync-->MsiExec.exe /I{99052DB7-9592-4522-A558-5417BBAD48EE}
                                        Microsoft Choice Guard-->MsiExec.exe /X{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}
                                        Microsoft Compression Client Pack 1.0 for Windows XP-->"C:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe"
                                        Microsoft Internationalized Domain Names Mitigation APIs-->"C:\WINDOWS\$NtServicePackUninstallIDNMitigationAPIs$\spuninst\spuninst.exe"
                                        Microsoft National Language Support Downlevel APIs-->"C:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$\spuninst\spuninst.exe"
                                        Microsoft Office Live Add-in 1.3-->MsiExec.exe /I{57F0ED40-8F11-41AA-B926-4A66D0D1A9CC}
                                        Microsoft Office PowerPoint Viewer 2003-->MsiExec.exe /X{90AF040C-6000-11D3-8CFE-0150048383C9}
                                        Microsoft Search Enhancement Pack-->MsiExec.exe /X{4CBA3D4C-8F51-4D60-B27E-F6B641C571E7}
                                        Microsoft Silverlight-->MsiExec.exe /X{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
                                        Microsoft SQL Server 2005 Compact Edition [ENU]-->MsiExec.exe /I{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}
                                        Microsoft Sync Framework Runtime Native v1.0 (x86)-->MsiExec.exe /I{8A74E887-8F0F-4017-AF53-CBA42211AAA5}
                                        Microsoft Sync Framework Services Native v1.0 (x86)-->MsiExec.exe /I{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}
                                        Microsoft User-Mode Driver Framework Feature Pack 1.0-->"C:\WINDOWS\$NtUninstallWudf01000$\spuninst\spuninst.exe"
                                        Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148-->MsiExec.exe /X{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}
                                        Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17-->MsiExec.exe /X{9A25302D-30C0-39D9-BD6F-21E6EC160475}
                                        Microsoft Word 2002-->MsiExec.exe /I{911B040C-6000-11D3-8CFE-0050048383C9}
                                        Mise à jour critique pour Lecteur Windows Media 11 (KB959772)-->"C:\WINDOWS\$NtUninstallKB959772_WM11$\spuninst\spuninst.exe"
                                        Mise à jour de sécurité pour Lecteur Windows Media (KB954155)-->"C:\WINDOWS\$NtUninstallKB954155_WM9$\spuninst\spuninst.exe"
                                        Mise à jour de sécurité pour Lecteur Windows Media (KB968816)-->"C:\WINDOWS\$NtUninstallKB968816_WM9$\spuninst\spuninst.exe"
                                        Mise à jour de sécurité pour Lecteur Windows Media (KB973540)-->"C:\WINDOWS\$NtUninstallKB973540_WM9$\spuninst\spuninst.exe"
                                        Mise à jour de sécurité pour Lecteur Windows Media 10 (KB917734)-->"C:\WINDOWS\$NtUninstallKB917734_WMP10$\spuninst\spuninst.exe"
                                        Mise à jour de sécurité pour Lecteur Windows Media 11 (KB936782)-->"C:\WINDOWS\$NtUninstallKB936782_WMP11$\spuninst\spuninst.exe"
                                        Mise à jour de sécurité pour Lecteur Windows Media 11 (KB954154)-->"C:\WINDOWS\$NtUninstallKB954154_WM11$\spuninst\spuninst.exe"
                                        Mise à jour de sécurité pour Step by Step Interactive Training (KB898458)-->"C:\WINDOWS\$NtUninstallKB898458$\spuninst\spuninst.exe"
                                        Mise à jour de sécurité pour Step by Step Interactive Training (KB923723)-->"C:\WINDOWS\$NtUninstallKB923723$\spuninst\spuninst.exe"
                                        Mise à jour de sécurité pour Windows Internet Explorer 7 (KB928090)-->"C:\WINDOWS\ie7updates\KB928090-IE7\spuninst\spuninst.exe"
                                        Mise à jour de sécurité pour Windows Internet Explorer 7 (KB929969)-->"C:\WINDOWS\ie7updates\KB929969\spuninst\spuninst.exe"
                                        Mise à jour de sécurité pour Windows Internet Explorer 7 (KB931768)-->"C:\WINDOWS\ie7updates\KB931768-IE7\spuninst\spuninst.exe"
                                        Mise à jour de sécurité pour Windows Internet Explorer 7 (KB933566)-->"C:\WINDOWS\ie7updates\KB933566-IE7\spuninst\spuninst.exe"
                                        Mise à jour de sécurité pour Windows Internet Explorer 7 (KB937143)-->"C:\WINDOWS\ie7updates\KB937143-IE7\spuninst\spuninst.exe"
                                        Mise à jour de sécurité pour Windows Internet Explorer 7 (KB938127)-->"C:\WINDOWS\ie7updates\KB938127-IE7\spuninst\spuninst.exe"
                                        Mise à jour de sécurité pour Windows Internet Explorer 7 (KB939653)-->"C:\WINDOWS\ie7updates\KB939653-IE7\spuninst\spuninst.exe"
                                        Mise à jour de sécurité pour Windows Internet Explorer 7 (KB942615)-->"C:\WINDOWS\ie7updates\KB942615-IE7\spuninst\spuninst.exe"
                                        Mise à jour de sécurité pour Windows Internet Explorer 7 (KB944533)-->"C:\WINDOWS\ie7updates\KB944533-IE7\spuninst\spuninst.exe"
                                        Mise à jour de sécurité pour Windows Internet Explorer 7 (KB950759)-->"C:\WINDOWS\ie7updates\KB950759-IE7\spuninst\spuninst.exe"
                                        Mise à jour de sécurité pour Windows Internet Explorer 7 (KB953838)-->"C:\WINDOWS\ie7updates\KB953838-IE7\spuninst\spuninst.exe"
                                        Mise à jour de sécurité pour Windows Internet Explorer 7 (KB956390)-->"C:\WINDOWS\ie7updates\KB956390-IE7\spuninst\spuninst.exe"
                                        Mise à jour de sécurité pour Windows Internet Explorer 7 (KB961260)-->"C:\WINDOWS\ie7updates\KB961260-IE7\spuninst\spuninst.exe"
                                        Mise à jour de sécurité pour Windows Internet Explorer 7 (KB963027)-->"C:\WINDOWS\ie7updates\KB963027-IE7\spuninst\spuninst.exe"
                                        Mise à jour de sécurité pour Windows Internet Explorer 7 (KB969897)-->"C:\WINDOWS\ie7updates\KB969897-IE7\spuninst\spuninst.exe"
                                        Mise à jour de sécurité pour Windows Internet Explorer 8 (KB969897)-->"C:\WINDOWS\ie8updates\KB969897-IE8\spuninst\spuninst.exe"
                                        Mise à jour de sécurité pour Windows Internet Explorer 8 (KB971961)-->"C:\WINDOWS\ie8updates\KB971961-IE8\spuninst\spuninst.exe"
                                        Mise à jour de sécurité pour Windows Internet Explorer 8 (KB972260)-->"C:\WINDOWS\ie8updates\KB972260-IE8\spuninst\spuninst.exe"
                                        Mise à jour de sécurité pour Windows Internet Explorer 8 (KB974455)-->"C:\WINDOWS\ie8updates\KB974455-IE8\spuninst\spuninst.exe"
                                        Mise à jour de sécurité pour Windows Internet Explorer 8 (KB976325)-->"C:\WINDOWS\ie8updates\KB976325-IE8\spuninst\spuninst.exe"
                                        Mise à jour de sécurité pour Windows Internet Explorer 8 (KB978207)-->"C:\WINDOWS\ie8updates\KB978207-IE8\spuninst\spuninst.exe"
                                        Mise à jour de sécurité pour Windows XP (KB913433)-->C:\WINDOWS\system32\MacroMed\Flash\genuinst.exe C:\WINDOWS\system32\MacroMed\Flash\KB913433.inf
                                        Mise à jour de sécurité pour Windows XP (KB923561)-->"C:\WINDOWS\$NtUninstallKB923561$\spuninst\spuninst.exe"
                                        Mise à jour de sécurité pour Windows XP (KB938464)-->"C:\WINDOWS\$NtUninstallKB938464$\spuninst\spuninst.exe"
                                        Mise à jour de sécurité pour Windows XP (KB938464-v2)-->"C:\WINDOWS\$NtUninstallKB938464-v2$\spuninst\spuninst.exe"
                                        Mise à jour de sécurité pour Windows XP (KB941569)-->"C:\WINDOWS\$NtUninstallKB941569$\spuninst\spuninst.exe"
                                        Mise à jour de sécurité pour Windows XP (KB946648)-->"C:\WINDOWS\$NtUninstallKB946648$\spuninst\spuninst.exe"
                                        Mise à jour de sécurité pour Windows XP (KB950760)-->"C:\WINDOWS\$NtUninstallKB950760$\spuninst\spuninst.exe"
                                        Mise à jour de sécurité pour Windows XP (KB950762)-->"C:\WINDOWS\$NtUninstallKB950762$\spuninst\spuninst.exe"
                                        Mise à jour de sécurité pour Windows XP (KB950974)-->"C:\WINDOWS\$NtUninstallKB950974$\spuninst\spuninst.exe"
                                        Mise à jour de sécurité pour Windows XP (KB951066)-->"C:\WINDOWS\$NtUninstallKB951066$\spuninst\spuninst.exe"
                                        Mise à jour de sécurité pour Windows XP (KB951376)-->"C:\WINDOWS\$NtUninstallKB951376$\spuninst\spuninst.exe"
                                        Mise à jour de sécurité pour Windows XP (KB951376-v2)-->"C:\WINDOWS\$NtUninstallKB951376-v2$\spuninst\spuninst.exe"
                                        Mise à jour de sécurité pour Windows XP (KB951698)-->"C:\WINDOWS\$NtUninstallKB951698$\spuninst\spuninst.exe"
                                        Mise à jour de sécurité pour Windows XP (KB951748)-->"C:\WINDOWS\$NtUninstallKB951748$\spuninst\spuninst.exe"
                                        Mise à jour de sécurité pour Windows XP (KB952004)-->"C:\WINDOWS\$NtUninstallKB952004$\spuninst\spuninst.exe"
                                        Mise à jour de sécurité pour Windows XP (KB952954)-->"C:\WINDOWS\$NtUninstallKB952954$\spuninst\spuninst.exe"
                                        Mise à jour de sécurité pour Windows XP (KB953839)-->"C:\WINDOWS\$NtUninstallKB953839$\spuninst\spuninst.exe"
                                        Mise à jour de sécurité pour Windows XP (KB954211)-->"C:\WINDOWS\$NtUninstallKB954211$\spuninst\spuninst.exe"
                                        Mise à jour de sécurité pour Windows XP (KB954459)-->"C:\WINDOWS\$NtUninstallKB954459$\spuninst\spuninst.exe"
                                        Mise à jour de sécurité pour Windows XP (KB954600)-->"C:\WINDOWS\$NtUninstallKB954600$\spuninst\spuninst.exe"
                                        Mise à jour de sécurité pour Windows XP (KB955069)-->"C:\WINDOWS\$NtUninstallKB955069$\spuninst\spuninst.exe"
                                        Mise à jour de sécurité pour Windows XP (KB956391)-->"C:\WINDOWS\$NtUninstallKB956391$\spuninst\spuninst.exe"
                                        Mise à jour de sécurité pour Windows XP (KB956572)-->"C:\WINDOWS\$NtUninstallKB956572$\spuninst\spuninst.exe"
                                        Mise à jour de sécurité pour Windows XP (KB956744)-->"C:\WINDOWS\$NtUninstallKB956744$\spuninst\spuninst.exe"
                                        Mise à jour de sécurité pour Windows XP (KB956802)-->"C:\WINDOWS\$NtUninstallKB956802$\spuninst\spuninst.exe"
                                        Mise à jour de sécurité pour Windows XP (KB956803)-->"C:\WINDOWS\$NtUninstallKB956803$\spuninst\spuninst.exe"
                                        Mise à jour de sécurité pour Windows XP (KB956841)-->"C:\WINDOWS\$NtUninstallKB956841$\spuninst\spuninst.exe"
                                        Mise à jour de sécurité pour Windows XP (KB956844)-->"C:\WINDOWS\$NtUninstallKB956844$\spuninst\spuninst.exe"
                                        Mise à jour de sécurité pour Windows XP (KB957095)-->"C:\WINDOWS\$NtUninstallKB957095$\spuninst\spuninst.exe"
                                        Mise à jour de sécurité pour Windows XP (KB957097)-->"C:\WINDOWS\$NtUninstallKB957097$\spuninst\spuninst.exe"
                                        Mise à jour de sécurité pour Windows XP (KB958644)-->"C:\WINDOWS\$NtUninstallKB958644$\spuninst\spuninst.exe"
                                        Mise à jour de sécurité pour Windows XP (KB958687)-->"C:\WINDOWS\$NtUninstallKB958687$\spuninst\spuninst.exe"
                                        Mise à jour de sécurité pour Windows XP (KB958690)-->"C:\WINDOWS\$NtUninstallKB958690$\spuninst\spuninst.exe"
                                        Mise à jour de sécurité pour Windows XP (KB958869)-->"C:\WINDOWS\$NtUninstallKB958869$\spuninst\spuninst.exe"
                                        Mise à jour de sécurité pour Windows XP (KB959426)-->"C:\WINDOWS\$NtUninstallKB959426$\spuninst\spuninst.exe"
                                        Mise à jour de sécurité pour Windows XP (KB960225)-->"C:\WINDOWS\$NtUninstallKB960225$\spuninst\spuninst.exe"
                                        Mise à jour de sécurité pour Windows XP (KB960715)-->"C:\WINDOWS\$NtUninstallKB960715$\spuninst\spuninst.exe"
                                        Mise à jour de sécurité pour Windows XP (KB960803)-->"C:\WINDOWS\$NtUninstallKB960803$\spuninst\spuninst.exe"
                                        Mise à jour de sécurité pour Windows XP (KB960859)-->"C:\WINDOWS\$NtUninstallKB960859$\spuninst\spuninst.exe"
                                        Mise à jour de sécurité pour Windows XP (KB961371)-->"C:\WINDOWS\$NtUninstallKB961371$\spuninst\spuninst.exe"
                                        Mise à jour de sécurité pour Windows XP (KB961373)-->"C:\WINDOWS\$NtUninstallKB961373$\spuninst\spuninst.exe"
                                        Mise à jour de sécurité pour Windows XP (KB961501)-->"C:\WINDOWS\$NtUninstallKB961501$\spuninst\spuninst.exe"
                                        Mise à jour de sécurité pour Windows XP (KB968537)-->"C:\WINDOWS\$NtUninstallKB968537$\spuninst\spuninst.exe"
                                        Mise à jour de sécurité pour Windows XP (KB969059)-->"C:\WINDOWS\$NtUninstallKB969059$\spuninst\spuninst.exe"
                                        Mise à jour de sécurité pour Windows XP (KB969898)-->"C:\WINDOWS\$NtUninstallKB969898$\spuninst\spuninst.exe"
                                        Mise à jour de sécurité pour Windows XP (KB969947)-->"C:\WINDOWS\$NtUninstallKB969947$\spuninst\spuninst.exe"
                                        Mise à jour de sécurité pour Windows XP (KB970238)-->"C:\WINDOWS\$NtUninstallKB970238$\spuninst\spuninst.exe"
                                        Mise à jour de sécurité pour Windows XP (KB970430)-->"C:\WINDOWS\$NtUninstallKB970430$\spuninst\spuninst.exe"
                                        Mise à jour de sécurité pour Windows XP (KB971486)-->"C:\WINDOWS\$NtUninstallKB971486$\spuninst\spuninst.exe"
                                        Mise à jour de sécurité pour Windows XP (KB971557)-->"C:\WINDOWS\$NtUninstallKB971557$\spuninst\spuninst.exe"
                                        Mise à jour de sécurité pour Windows XP (KB971633)-->"C:\WINDOWS\$NtUninstallKB971633$\spuninst\spuninst.exe"
                                        Mise à jour de sécurité pour Windows XP (KB971657)-->"C:\WINDOWS\$NtUninstallKB971657$\spuninst\spuninst.exe"
                                        Mise à jour de sécurité pour Windows XP (KB972270)-->"C:\WINDOWS\$NtUninstallKB972270$\spuninst\spuninst.exe"
                                        Mise à jour de sécurité pour Windows XP (KB973346)-->"C:\WINDOWS\$NtUninstallKB973346$\spuninst\spuninst.exe"
                                        Mise à jour de sécurité pour Windows XP (KB973507)-->"C:\WINDOWS\$NtUninstallKB973507$\spuninst\spuninst.exe"
                                        Mise à jour de sécurité pour Windows XP (KB973525)-->"C:\WINDOWS\$NtUninstallKB973525$\spuninst\spuninst.exe"
                                        Mise à jour de sécurité pour Windows XP (KB973869)-->"C:\WINDOWS\$NtUninstallKB973869$\spuninst\spuninst.exe"
                                        Mise à jour de sécurité pour Windows XP (KB973904)-->"C:\WINDOWS\$NtUninstallKB973904$\spuninst\spuninst.exe"
                                        Mise à jour de sécurité pour Windows XP (KB974112)-->"C:\WINDOWS\$NtUninstallKB974112$\spuninst\spuninst.exe"
                                        Mise à jour de sécurité pour Windows XP (KB974318)-->"C:\WINDOWS\$NtUninstallKB974318$\spuninst\spuninst.exe"
                                        Mise à jour de sécurité pour Windows XP (KB974392)-->"C:\WINDOWS\$NtUninstallKB974392$\spuninst\spuninst.exe"
                                        Mise à jour de sécurité pour Windows XP (KB974571)-->"C:\WINDOWS\$NtUninstallKB974571$\spuninst\spuninst.exe"
                                        Mise à jour de sécurité pour Windows XP (KB975025)-->"C:\WINDOWS\$NtUninstallKB975025$\spuninst\spuninst.exe"
                                        Mise à jour de sécurité pour Windows XP (KB975467)-->"C:\WINDOWS\$NtUninstallKB975467$\spuninst\spuninst.exe"
                                        Mise à jour pour Windows Internet Explorer 8 (KB971180)-->"C:\WINDOWS\ie8updates\KB971180-IE8\spuninst\spuninst.exe"
                                        Mise à jour pour Windows Internet Explorer 8 (KB976749)-->"C:\WINDOWS\ie8updates\KB976749-IE8\spuninst\spuninst.exe"
                                        Mise à jour pour Windows XP (KB951072-v2)-->"C:\WINDOWS\$NtUninstallKB951072-v2$\spuninst\spuninst.exe"
                                        Mise à jour pour Windows XP (KB951978)-->"C:\WINDOWS\$NtUninstallKB951978$\spuninst\spuninst.exe"
                                        Mise à jour pour Windows XP (KB955759)-->"C:\WINDOWS\$NtUninstallKB955759$\spuninst\spuninst.exe"
                                        Mise à jour pour Windows XP (KB961503)-->"C:\WINDOWS\$NtUninstallKB961503$\spuninst\spuninst.exe"
                                        Mise à jour pour Windows XP (KB967715)-->"C:\WINDOWS\$NtUninstallKB967715$\spuninst\spuninst.exe"
                                        Mise à jour pour Windows XP (KB968389)-->"C:\WINDOWS\$NtUninstallKB968389$\spuninst\spuninst.exe"
                                        Mise à jour pour Windows XP (KB971737)-->"C:\WINDOWS\$NtUninstallKB971737$\spuninst\spuninst.exe"
                                        Mise à jour pour Windows XP (KB973687)-->"C:\WINDOWS\$NtUninstallKB973687$\spuninst\spuninst.exe"
                                        Mise à jour pour Windows XP (KB973815)-->"C:\WINDOWS\$NtUninstallKB973815$\spuninst\spuninst.exe"
                                        Mozilla Firefox (3.5.7)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
                                        MSVCRT-->MsiExec.exe /I{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}
                                        MSXML 4.0 SP2 (KB927978)-->MsiExec.exe /I{37477865-A3F1-4772-AD43-AAFC6BCFF99F}
                                        MSXML 4.0 SP2 (KB936181)-->MsiExec.exe /I{C04E32E0-0416-434D-AFB9-6969D703A9EF}
                                        MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
                                        MSXML 4.0 SP2 (KB973688)-->MsiExec.exe /I{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}
                                        Neuf - Kit de connexion-->C:\Program Files\Neuf\Kit\uninstall.exe
                                        Outil de téléchargement Windows Live-->MsiExec.exe /I{205C6BDD-7B73-42DE-8505-9A093F35A238}
                                        PhotoFiltre-->"C:\Program Files\PhotoFiltre\Uninst.exe"
                                        QuickTime-->MsiExec.exe /I{1451DE6B-ABE1-4F62-BE9A-B363A17588A2}
                                        S3 S3Display-->vtuninst.exe -reg 5 'HKLM\Software\S3\VT\S3Uninst\S3Display'
                                        S3 S3Gamma2-->vtuninst.exe -reg 5 'HKLM\Software\S3\VT\S3Uninst\S3Gamma2'
                                        S3 S3Info2-->vtuninst.exe -reg 5 'HKLM\Software\S3\VT\S3Uninst\S3Info2'
                                        S3 S3Overlay-->vtuninst.exe -reg 5 'HKLM\Software\S3\VT\S3Uninst\S3Overlay'
                                        Sagem Wi-Fi 11g USB adapter (driver)-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{2ED60C17-4568-4CD5-830A-03C4688B09A1}\setup.exe" -l0x40c
                                        Sagem Wi-Fi 11g USB adapter (utility)-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{AAFD22B6-A6C7-4134-AF4E-080BCBCD3493}\setup.exe" -l0x40c
                                        Segoe UI-->MsiExec.exe /I{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}
                                        Skype 2.5-->"C:\Program Files\Skype\Phone\unins000.exe"
                                        Sonic RecordNow!-->MsiExec.exe /I{9541FED0-327F-4DF0-8B96-EF57EF622F19}
                                        Spelling Dictionaries Support For Adobe Reader 9-->MsiExec.exe /I{AC76BA86-7AD7-5464-3428-900000000004}
                                        Spybot - Search & Destroy 1.4-->"C:\Program Files\Spybot - Search & Destroy\unins000.exe"
                                        Spybot - Search & Destroy-->"C:\Program Files\Spybot - Search & Destroy\unins001.exe"
                                        TeamSpeak 2 RC2-->"C:\Program Files\Teamspeak2_RC2\unins000.exe"
                                        Uninstall 1.0.0.1-->"C:\Program Files\Fichiers communs\DVDVideoSoft\unins000.exe"
                                        Update for Microsoft .NET Framework 3.5 SP1 (KB963707)-->C:\WINDOWS\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {B2AE9C82-DC7B-3641-BFC8-87275C4F3607} /qb+ REBOOTPROMPT=""
                                        VC 9.0 Runtime-->MsiExec.exe /I{02E89EFC-7B07-4D5A-AA03-9EC0902914EE}
                                        VideoLAN VLC media player 0.8.6c-->C:\Program Files\VideoLAN\VLC\uninstall.exe
                                        Viewpoint Media Player-->C:\Program Files\Viewpoint\Viewpoint Experience Technology\mtsAxInstaller.exe /u
                                        Windows Internet Explorer 8-->"C:\WINDOWS\ie8\spuninst\spuninst.exe"
                                        Windows Live Call-->MsiExec.exe /I{82C7B308-0BDD-49D8-8EA5-9CD3A3F9DF41}
                                        Windows Live Communications Platform-->MsiExec.exe /I{3B4E636E-9D65-4D67-BA61-189800823F52}
                                        Windows Live Contrôle parental-->MsiExec.exe /X{D5D81435-B8DE-4CAF-867F-7998F2B92CFC}
                                        Windows Live FolderShare-->MsiExec.exe /X{2075CB0A-D26F-4DAA-B424-5079296B43BA}
                                        Windows Live Mail-->MsiExec.exe /I{5DD76286-9BE7-4894-A990-E905E91AC818}
                                        Windows Live Messenger-->MsiExec.exe /X{770F1BEC-2871-4E70-B837-FB8525FFA3B1}
                                        Windows Live Toolbar-->MsiExec.exe /X{F7D27C70-90F5-49B9-B188-0A133C0CE353}
                                        Windows Live Writer-->MsiExec.exe /X{4634B21A-CC07-4396-890C-2B8168661FEA}
                                        Windows Media Format 11 runtime-->"C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll
                                        Windows Media Format 11 runtime-->"C:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe"
                                        Windows Media Player 11-->"C:\WINDOWS\$NtUninstallwmp11$\spuninst\spuninst.exe"
                                        Windows XP Service Pack 3-->"C:\WINDOWS\$NtServicePackUninstall$\spuninst\spuninst.exe"
                                        ZoneAlarm-->C:\Program Files\Zone Labs\ZoneAlarm\zauninst.exe

                                        ======Hosts File======

                                        127.0.0.1 www.007guard.com
                                        127.0.0.1 007guard.com
                                        127.0.0.1 008i.com
                                        127.0.0.1 www.008k.com
                                        127.0.0.1 008k.com
                                        127.0.0.1 www.00hq.com
                                        127.0.0.1 00hq.com
                                        127.0.0.1 010402.com
                                        127.0.0.1 www.032439.com
                                        127.0.0.1 032439.com

                                        ======Security center information======

                                        AV: AntiVir Desktop
                                        FW: ZoneAlarm Firewall

                                        ======System event log======

                                        Computer Name: SN401381390009
                                        Event Code: 26
                                        Message: Application popup :  : Machine Check:

                                        Record Number: 2035
                                        Source Name: Application Popup
                                        Time Written: 20100125144736.000000+060
                                        Event Type: Informations
                                        User:

                                        Computer Name: SN401381390009
                                        Event Code: 10
                                        Message: Ce lecteur ne semble pas prendre en charge la lecture audio numérique.

                                        Record Number: 2034
                                        Source Name: redbook
                                        Time Written: 20100125144736.000000+060
                                        Event Type: Informations
                                        User:

                                        Computer Name: SN401381390009
                                        Event Code: 10
                                        Message: Ce lecteur ne semble pas prendre en charge la lecture audio numérique.

                                        Record Number: 2033
                                        Source Name: redbook
                                        Time Written: 20100125144736.000000+060
                                        Event Type: Informations
                                        User:

                                        Computer Name: SN401381390009
                                        Event Code: 10
                                        Message: Ce lecteur ne semble pas prendre en charge la lecture audio numérique.

                                        Record Number: 2032
                                        Source Name: redbook
                                        Time Written: 20100125144736.000000+060
                                        Event Type: Informations
                                        User:

                                        Computer Name: SN401381390009
                                        Event Code: 6005
                                        Message: Le service d'Enregistrement d'événement a démarré.

                                        Record Number: 2031
                                        Source Name: EventLog
                                        Time Written: 20100125144727.000000+060
                                        Event Type: Informations
                                        User:

                                        =====Application event log=====

                                        Computer Name: SN401381390009
                                        Event Code: 0
                                        Message: Service started

                                        Record Number: 23415
                                        Source Name: SeaPort
                                        Time Written: 20091110154602.000000+060
                                        Event Type: Informations
                                        User:

                                        Computer Name: SN401381390009
                                        Event Code: 8
                                        Message: Échec de la récupération de la mise à jour automatique du numéro de séquence de la liste racine tierce partie à partir de : <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt> avec l'erreur : Cette opération s'est terminée car le délai d'attente a expiré.

                                        Record Number: 23414
                                        Source Name: crypt32
                                        Time Written: 20091110154602.000000+060
                                        Event Type: erreur
                                        User:

                                        Computer Name: SN401381390009
                                        Event Code: 105
                                        Message: The service was started.

                                        Record Number: 23413
                                        Source Name: ATI Smart
                                        Time Written: 20091110154551.000000+060
                                        Event Type: Informations
                                        User:

                                        Computer Name: SN401381390009
                                        Event Code: 0
                                        Message:
                                        Record Number: 23412
                                        Source Name: NOSSO(R)
                                        Time Written: 20091109193734.000000+060
                                        Event Type: erreur
                                        User:

                                        Computer Name: SN401381390009
                                        Event Code: 2002
                                        Message: Le service EAPOL a été arrêté correctement.

                                        Record Number: 23411
                                        Source Name: EAPOL
                                        Time Written: 20091109133610.000000+060
                                        Event Type: Informations
                                        User:

                                        ======Environment variables======

                                        "ComSpec"=%SystemRoot%\system32\cmd.exe
                                        "Path"=%systemroot%\system32;%systemroot%;%systemroot%\system32\wbem;C:\ATI Technologies\ATI Control Panel;C:\PROGRA~1\FICHIE~1\TVNAVI~1;C:\Program Files\Fichiers communs\Teleca Shared;C:\Program Files\QuickTime\QTSystem\
                                        "windir"=%SystemRoot%
                                        "OS"=Windows_NT
                                        "PROCESSOR_ARCHITECTURE"=x86
                                        "PROCESSOR_LEVEL"=6
                                        "PROCESSOR_IDENTIFIER"=x86 Family 6 Model 8 Stepping 1, AuthenticAMD
                                        "PROCESSOR_REVISION"=0801
                                        "NUMBER_OF_PROCESSORS"=1
                                        "PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
                                        "TEMP"=%SystemRoot%\TEMP
                                        "TMP"=%SystemRoot%\TEMP
                                        "CLASSPATH"=.;"i\QTJava.zip";C:\Program Files\Java\jre6\lib\ext\QTJava.zip
                                        "QTJAVA"=C:\Program Files\Java\jre6\lib\ext\QTJava.zip
                                        "FP_NO_HOST_CHECK"=NO
                                        "tvdumpflags"=8

                                        -----------------EOF-----------------
                                        0
                                        1. voici le rapport log:

                                          Logfile of random's system information tool 1.06 (written by random/random)
                                          Run by Abbassi at 2010-02-01 14:44:00
                                          Microsoft Windows XP Édition familiale Service Pack 3
                                          System drive C: has 42 GB (28%) free of 149 GB
                                          Total RAM: 1023 MB (14% free)

                                          Logfile of Trend Micro HijackThis v2.0.2
                                          Scan saved at 14:44:39, on 01/02/2010
                                          Platform: Windows XP SP3 (WinNT 5.01.2600)
                                          MSIE: Internet Explorer v8.00 (8.00.6001.18702)
                                          Boot mode: Normal

                                          Running processes:
                                          C:\WINDOWS\System32\smss.exe
                                          C:\WINDOWS\system32\winlogon.exe
                                          C:\WINDOWS\system32\services.exe
                                          C:\WINDOWS\system32\lsass.exe
                                          C:\WINDOWS\system32\Ati2evxx.exe
                                          C:\WINDOWS\system32\svchost.exe
                                          C:\WINDOWS\System32\svchost.exe
                                          C:\WINDOWS\system32\svchost.exe
                                          C:\WINDOWS\system32\Ati2evxx.exe
                                          C:\WINDOWS\Explorer.EXE
                                          C:\WINDOWS\system32\ZoneLabs\vsmon.exe
                                          C:\WINDOWS\system32\spoolsv.exe
                                          C:\Program Files\Avira\AntiVir Desktop\sched.exe
                                          C:\Program Files\Avira\AntiVir Desktop\avguard.exe
                                          C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                                          C:\Program Files\Bonjour\mDNSResponder.exe
                                          C:\Program Files\Java\jre6\bin\jqs.exe
                                          C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
                                          C:\WINDOWS\SOUNDMAN.EXE
                                          C:\apps\ABoard\ABoard.exe
                                          C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
                                          C:\apps\ABoard\AOSD.exe
                                          C:\WINDOWS\System32\svchost.exe
                                          C:\Program Files\Virtual CD v4 SDK\system\vcssecs.exe
                                          C:\WINDOWS\wanmpsvc.exe
                                          C:\Program Files\Winsudate\gibsvc.exe
                                          C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
                                          C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
                                          C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
                                          C:\Program Files\QuickTime\QTTask.exe
                                          C:\Program Files\iTunes\iTunesHelper.exe
                                          C:\WINDOWS\system32\ctfmon.exe
                                          C:\Program Files\Microsoft ActiveSync\wcescomm.exe
                                          C:\Program Files\Messenger\msmsgs.exe
                                          C:\PROGRA~1\MICROS~4\rapimgr.exe
                                          C:\Program Files\SAGEM WiFi manager\WLANUTL.exe
                                          C:\WINDOWS\System32\wbem\wmiapsrv.exe
                                          C:\Program Files\iPod\bin\iPodService.exe
                                          C:\WINDOWS\system32\wuauclt.exe
                                          C:\Program Files\Mozilla Firefox\firefox.exe
                                          C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                                          C:\Program Files\Windows Live\Contacts\wlcomm.exe
                                          C:\WINDOWS\System32\svchost.exe
                                          C:\Program Files\Internet Explorer\IEXPLORE.EXE
                                          C:\Program Files\Windows Live\Toolbar\wltuser.exe
                                          C:\Program Files\Internet Explorer\IEXPLORE.EXE
                                          C:\Program Files\Windows Media Player\wmplayer.exe
                                          C:\Documents and Settings\Abbassi\Bureau\RSIT.exe
                                          C:\Program Files\trend micro\Abbassi.exe

                                          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                                          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.hugedomains.com/domain_profile.cfm?d=wibeez&e=com
                                          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                                          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                                          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                                          R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
                                          R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
                                          R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                                          O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
                                          O2 - BHO: AskBar BHO - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files\AskBarDis\bar\bin\askBar.dll
                                          O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                                          O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
                                          O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
                                          O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
                                          O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                                          O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
                                          O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
                                          O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
                                          O3 - Toolbar: Ask Toolbar - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll
                                          O3 - Toolbar: (no name) - {66886C4D-B307-4ECA-A228-52CA9B9851A4} - (no file)
                                          O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
                                          O4 - HKLM\..\Run: [ACTIVBOARD] c:\apps\ABoard\ABoard.exe
                                          O4 - HKLM\..\Run: [ATIPTA] C:\ATI Technologies\ATI Control Panel\atiptaxx.exe
                                          O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
                                          O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
                                          O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
                                          O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
                                          O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
                                          O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
                                          O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
                                          O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
                                          O4 - HKCU\..\Run: [WOOKIT] C:\PROGRA~1\Wanadoo\Shell.exe appLaunchClientZone.shl|DEFAULT=cnx|PARAM=
                                          O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                                          O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
                                          O4 - HKCU\..\Run: [WinUsr] C:\Program Files\Winsudate\gibusr.exe
                                          O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
                                          O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
                                          O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\FICHIE~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
                                          O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
                                          O4 - Global Startup: Utilitaire réseau pour SAGEM Wi-Fi 11g USB adapter.lnk = ?
                                          O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
                                          O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
                                          O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~4\INetRepl.dll
                                          O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~4\INetRepl.dll
                                          O9 - Extra 'Tools' menuitem: Créer un Favori de l'appareil mobile... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~4\INetRepl.dll
                                          O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
                                          O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                                          O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                                          O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                                          O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                                          O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                                          O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                                          O14 - IERESET.INF: START_PAGE_URL=file://C:\APPS\IE\offline\fr.htm
                                          O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
                                          O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
                                          O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab
                                          O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.cab
                                          O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - http://download.divx.com/webplayer/stage6/windows/AutoDLDivXWebPlayerInstaller.cab
                                          O16 - DPF: {80B626D6-BC34-4BCF-B5A1-7149E4FD9CFA} (UnoCtrl Class) - http://zone.msn.com/bingame/zpagames/GAME_UNO1.cab60096.cab
                                          O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
                                          O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/ZPAFramework.cab102118.cab
                                          O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
                                          O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
                                          O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab31267.cab
                                          O23 - Service: Avira AntiVir Planificateur (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
                                          O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
                                          O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                                          O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
                                          O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
                                          O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
                                          O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1150\Intel 32\IDriverT.exe
                                          O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
                                          O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
                                          O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe
                                          O23 - Service: Virtual CD v4 Security service (SDK - Version) (VCSSecS) - H+H Software GmbH - C:\Program Files\Virtual CD v4 SDK\system\vcssecs.exe
                                          O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
                                          O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
                                          O23 - Service: Gestionnaire de mise à jour Winsudate (WinSvc) - Unknown owner - C:\Program Files\Winsudate\gibsvc.exe
                                          0
                                          • 1
                                          • 2