VIRUS

Bonsoir,

J'ai un virus sur mon ordinateur.
Quand je lance ad aware l'ordinateur s éteint

J'ai vraiment besoin d'aide
Configuration: Windows XP
Firefox 3.0.3

52 réponses

Résumé de la discussion

Un problème récurrent concerne un ordinateur sous Windows XP touché par un virus, l'exécution d'Ad-Aware provoquant l'arrêt du système et bloquant la détection initiale dans les premiers tests. Des conseils indiquent de démarrer en mode sans échec, fermer les applications actives et utiliser la restauration système pour revenir à une heure antérieure, puis relancer le nettoyage si nécessaire. Des éléments utiles ajoutent CCleaner pour supprimer les traces et les fichiers temporaires et recommandent de fournir un nouveau rapport hijackthis après le nettoyage afin d’orienter le diagnostic. En cas de persistance des blocages dans Firefox après le nettoyage, certains échanges recommandent d’évaluer des composants DLL ou d’envisager des réparations plus approfondies, sans envisager une conclusion hâtive sur l'état du système.

Bobot (l’IA à votre service)
  1. Contributeur
    Hello ;)
    je n'arrive pas à trouver les options d'installations ou dois-je aller ? >> il faut cliquer sur Ici pour télécharger
    Si ce n'est pas ça dis moi quoi.
    +++
    1. Contributeur
      Ouep,
      C'est quoi la marque de ton pc?

      Essaye ça:
      * Démarre en mode sans échec
      Comment faire >> https://www.micro-astuce.com/depannage/demarrer-mode-sans-echec.php
      Redémarres l’ordinateur
      Dès le chargement du BIOS, commences à appuyer sur la touche F8 de ton clavier,i jusqu'au ou le menu des options avancées de Windows apparait.
      Sélectionne "Mode sans échec" dans le menu puis appuyez sur Entrée.

      Ouvres OTMoveIt .

      -> cliques sur le bouton [restor]

      --> dans la fenêtre qui s'ouvre : sélectionne le fichier " xxxx2008_xxxxxx.res " ( les " x " sont des chiffres ) et cliques sur " ouvrir " .

      --> dans cette nouvelle fenêtre d'OTmoveIt qui vient d'apparaitre, sélectionnes TOUTES les lignes présentes et cliques sur [RestorIt] .

      -> redémarres le PC et retestes ....

      ++
      1. Contributeur
        ça ne marche pas... Tu ne pas faire de restauration à une heure antérieur?
        1. Salut ET,

          ça ne marche pas...

          J'ai même désinstallé et réinstallé firefox, rie
          1. Salut ET

            J'ai fait ta manip mais rien ne marche.

            ---------------------------
            Ajout/Suppression de programmes
            ---------------------------
            La source d'installation pour ce produit n'est pas disponible. Vérifiez que la source existe et que vous y avez accès.

            ---------------------------
            OK
            ---------------------------

            Quand je fait ajout suppression de programme ,je veux supprimer le logiciel ciel mais il me refuse la suppression.

            Comment je fait il ne trouve pas l'emplacement et je suis sur que ca vient de ca...

            @+
            1. Contributeur
              Ouvres OTMoveIt .

              -> cliques sur le bouton [restor]

              --> dans la fenêtre qui s'ouvre : sélectionne le fichier " xxxx2008_xxxxxx.res " ( les " x " sont des chiffres ) et cliques sur " ouvrir " .

              --> dans cette nouvelle fenêtre d'OTmoveIt qui vient d'apparaitre, sélectionnes TOUTES les lignes présentes et cliques sur [RestorIt] .

              -> redémarres le PC et retestes ....

              ++
              1. Salut E..T,

                Apparement Pb avec DLL...
                j'ai fait la réparation mais rien ne change...
                1. oui, ca devient de pire en pire avec mozilla et même explorer ça se bloc ??

                  @+
                  1. Bonjour,

                    J'ai vraiment un pb avec mon ordinateur.
                    Firfox fait que de bloquer.

                    Merci de m'aider...
                    1. Contributeur
                      Hello,
                      dois-je dans le pire des cas formater l'ordinateur ?
                      Non non attebds que quelqu'un passe ici ;)
                      @+++
                      1. Je te fait un grand MERCI pour ce que tu as déjà accomplis...
                        Je n'arrive pas à lire les rapports que je t'envoies car ce n'est pas ma partie et je ne sais même pas ou la "m****" est située.
                        As-tu d'autres connaissances sur ce site qui pourrais éventuellement m'aider ?
                        Je t'ai dis hier que je n'avais pas de problème mais firfox se bloque fréquemment.
                        Je te fait encore un GRAND MERCI dois-je dans le pire des cas formater l'ordinateur ?

                        Merci pour ta réponse

                        @++
                        1. Contributeur
                          Bob_74 je ne sais pas comment faire pour virer cette m****, donc moi je stop la ;-)
                          On a bien avancé il reste plus grand chose donc on va pas tout casser.
                          Si tu n'as pas de réponse >> Lis ceci.
                          Voili voilou Désolé de na pas pouvoir finir.
                          Je suis ton soucis de près ;))
                          @++
                          1. voici le nouveau rapport hijack. le pc va plutôt bien pas de problème récurant

                            Logfile of Trend Micro HijackThis v2.0.2
                            Scan saved at 00:40:03, on 21/10/2008
                            Platform: Windows XP SP2 (WinNT 5.01.2600)
                            MSIE: Internet Explorer v8.00 (8.00.6001.18241)
                            Boot mode: Normal

                            Running processes:
                            C:\WINDOWS\System32\smss.exe
                            C:\WINDOWS\system32\winlogon.exe
                            C:\WINDOWS\system32\services.exe
                            C:\WINDOWS\system32\lsass.exe
                            C:\WINDOWS\system32\Ati2evxx.exe
                            C:\WINDOWS\system32\svchost.exe
                            C:\WINDOWS\System32\svchost.exe
                            C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe
                            C:\WINDOWS\system32\spoolsv.exe
                            C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                            C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
                            C:\Program Files\Bonjour\mDNSResponder.exe
                            C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                            C:\WINDOWS\system32\HPZipm12.exe
                            C:\WINDOWS\system32\svchost.exe
                            C:\Program Files\Linksys Wireless-G PCI Network Adapter with SpeedBooster\WLService.exe
                            C:\Program Files\Linksys Wireless-G PCI Network Adapter with SpeedBooster\WMP54GSv1_1.exe
                            C:\Program Files\Compact Wireless-G USB Adapter Wireless Network Monitor\WLService.exe
                            C:\Program Files\Compact Wireless-G USB Adapter Wireless Network Monitor\WUSB54GC.exe
                            C:\WINDOWS\system32\Ati2evxx.exe
                            C:\WINDOWS\Explorer.EXE
                            C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
                            C:\windows\system\hpsysdrv.exe
                            C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
                            C:\WINDOWS\system32\hphmon06.exe
                            C:\WINDOWS\ALCXMNTR.EXE
                            C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
                            C:\HP\KBD\KBD.EXE
                            C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe
                            C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe
                            C:\Program Files\Neuf\Kit\WiFi\9wifi.exe
                            C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe
                            C:\Program Files\QuickTime\QTTask.exe
                            C:\Program Files\iTunes\iTunesHelper.exe
                            C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                            C:\Program Files\Messenger\msmsgs.exe
                            C:\WINDOWS\system32\ctfmon.exe
                            C:\WINDOWS\system32\wuauclt.exe
                            C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                            C:\WinZip\WZQKPICK.EXE
                            C:\Program Files\iPod\bin\iPodService.exe
                            C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
                            C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
                            C:\Program Files\Mozilla Firefox\firefox.exe
                            C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                            R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr?cobrand=hp-desktop.msn.com&ocid=HPDHP&pc=HPDTDF
                            R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=FR_FR&c=Q305&bd=pavilion&pf=desktop
                            R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://actus.sfr.fr
                            R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://actus.sfr.fr
                            R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.neuf.fr/
                            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=FR_FR&c=Q305&bd=pavilion&pf=desktop
                            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                            R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
                            R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://www.msn.com/fr-fr?cobrand=hp-desktop.msn.com&ocid=HPDHP&pc=HPDTDF
                            R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
                            R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                            O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                            O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                            O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Fichiers communs\Symantec Shared\coShared\Browser\2.0\coIEPlg.dll
                            O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\FICHIE~1\SYMANT~1\IDS\IPSBHO.dll
                            O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
                            O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
                            O2 - BHO: Google Toolbar Notifier BHO - {af69de43-7d58-4638-b6fa-ce66b5ad205d} - C:\Program Files\Google\GoogleToolbarNotifier\4.1.805.4472\swg.dll
                            O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
                            O3 - Toolbar: Afficher Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Fichiers communs\Symantec Shared\coShared\Browser\2.0\CoIEPlg.dll
                            O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
                            O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
                            O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
                            O4 - HKLM\..\Run: [HPHUPD06] c:\Program Files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06.exe
                            O4 - HKLM\..\Run: [HPHmon06] C:\WINDOWS\system32\hphmon06.exe
                            O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
                            O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
                            O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
                            O4 - HKLM\..\Run: [AutoTBar] c:\Program Files\HP\Digital Imaging\bin\AUTOTBAR.EXE
                            O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
                            O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe"
                            O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
                            O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Fichiers communs\InstallShield\UpdateService\isuspm.exe" -startup
                            O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe" -start
                            O4 - HKLM\..\Run: [Autoconfigurateur WiFi Neuf] "C:\Program Files\Neuf\Kit\WiFi\9wifi.exe"
                            O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe"
                            O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton Internet Security\osCheck.exe"
                            O4 - HKLM\..\Run: [WindowsServicesStartup] C:\DOCUME~1\HP_PRO~1\LOCALS~1\Temp\svchost.exe 1
                            O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
                            O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
                            O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
                            O4 - HKLM\..\RunOnce: [SymLnch] "C:\Documents and Settings\HP_Propriétaire\Application Data\Symantec\Layouts\Norton Internet Security\15.0\SymAllLanguages\NIS_RETAIL\20070828\Support\SymLnch\SymLnch.exe" "C:\Documents and Settings\HP_Propriétaire\Application Data\Symantec\Layouts\Norton Internet Security\15.0\SymAllLanguages\NIS_RETAIL\20070828\Setup.exe" "/REALUPREBOOT /temp /patched"
                            O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                            O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
                            O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                            O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\mnyexpr.exe"
                            O4 - .DEFAULT User Startup: AutoTBar.exe (User 'Default user')
                            O4 - Global Startup: Démarrage rapide de HP Photosmart Premier.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
                            O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                            O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
                            O4 - Global Startup: WinZip Quick Pick.lnk = C:\WinZip\WZQKPICK.EXE
                            O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
                            O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
                            O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
                            O9 - Extra button: Aide à la connexion - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
                            O9 - Extra 'Tools' menuitem: Aide à la connexion - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
                            O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                            O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                            O9 - Extra button: Aide à la connexion - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm (HKCU)
                            O9 - Extra 'Tools' menuitem: Aide à la connexion - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm (HKCU)
                            O10 - Unknown file in Winsock LSP: c:\windows\system32\hikkhln.dll
                            O10 - Unknown file in Winsock LSP: c:\windows\system32\hikkhln.dll
                            O16 - DPF: microsoft xml parser for java - file:///C:/WINDOWS/Java/classes/xmldso.cab
                            O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} (Symantec Download Manager) - https://webdl.symantec.com/activex/symdlmgr.cab
                            O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/...
                            O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/flashplayer/current/swflash.cab
                            O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                            O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
                            O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
                            O23 - Service: Service Bonjour (bonjour service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
                            O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe
                            O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe
                            O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe
                            O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\VAScanner\comHost.exe
                            O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                            O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1150\Intel 32\IDriverT.exe
                            O23 - Service: Service de l’iPod (ipod service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
                            O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
                            O23 - Service: LiveUpdate Notice - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe
                            O23 - Service: Planificateur LiveUpdate automatique - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
                            O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
                            O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~1\FICHIE~1\SYMANT~1\CCPD-LC\symlcsvc.exe
                            O23 - Service: TeamViewer 3 (TeamViewer) - TeamViewer GmbH - C:\Program Files\TeamViewer3\TeamViewer_Host.exe
                            O23 - Service: WMP54GSSVC - GEMTEKS - C:\Program Files\Linksys Wireless-G PCI Network Adapter with SpeedBooster\WLService.exe
                            O23 - Service: WUSB54GCSVC - GEMTEKS - C:\Program Files\Compact Wireless-G USB Adapter Wireless Network Monitor\WLService.exe
                            1. Contributeur
                              Poste un nouveau rapport hijackthis et dis moi comment va le pc.
                              @++
                              1. l'ordinateur c'est bien éteint, en se rallumant il m'a bien affiché un rapport du type date_heure.txt

                                Le voici :

                                Folder move failed. C:\DOCUME~1\HP_PRO~1\LOCALS~1\Temporary Internet Files\Content.IE5 scheduled to be moved on reboot.
                                Folder move failed. C:\DOCUME~1\HP_PRO~1\LOCALS~1\Temporary Internet Files scheduled to be moved on reboot.
                                C:\DOCUME~1\HP_PRO~1\LOCALS~1\Temp\~DEST moved successfully.
                                C:\DOCUME~1\HP_PRO~1\LOCALS~1\Temp\plugtmp moved successfully.
                                C:\DOCUME~1\HP_PRO~1\LOCALS~1\Temp\nsv28.tmp moved successfully.
                                Folder move failed. C:\DOCUME~1\HP_PRO~1\LOCALS~1\Temp scheduled to be moved on reboot.
                                Folder move failed. C:\DOCUME~1\HP_PRO~1\LOCALS~1\Historique\History.IE5\MSHist012008102020081021 scheduled to be moved on reboot.
                                Folder move failed. C:\DOCUME~1\HP_PRO~1\LOCALS~1\Historique\History.IE5 scheduled to be moved on reboot.
                                Folder move failed. C:\DOCUME~1\HP_PRO~1\LOCALS~1\Historique scheduled to be moved on reboot.
                                C:\DOCUME~1\HP_PRO~1\LOCALS~1\Apps\2.0\8NBL5PWX.2RB\AV3GM6XN.WNY\manifests moved successfully.
                                C:\DOCUME~1\HP_PRO~1\LOCALS~1\Apps\2.0\8NBL5PWX.2RB\AV3GM6XN.WNY moved successfully.
                                C:\DOCUME~1\HP_PRO~1\LOCALS~1\Apps\2.0\8NBL5PWX.2RB moved successfully.
                                C:\DOCUME~1\HP_PRO~1\LOCALS~1\Apps\2.0 moved successfully.
                                C:\DOCUME~1\HP_PRO~1\LOCALS~1\Apps moved successfully.
                                C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\{3248F0A6-6813-11D6-A77B-00B0D0150000} moved successfully.
                                C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\{31519424-2560-4CEF-99E8-8CC7FABA1E09} moved successfully.
                                C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Paint.NET\1103296784 moved successfully.
                                C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Paint.NET moved successfully.
                                C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\NOS moved successfully.
                                C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Mozilla\Firefox\Profiles\tudhcadj.default\OfflineCache moved successfully.
                                Folder move failed. C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Mozilla\Firefox\Profiles\tudhcadj.default\Cache scheduled to be moved on reboot.
                                Folder move failed. C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Mozilla\Firefox\Profiles\tudhcadj.default scheduled to be moved on reboot.
                                Folder move failed. C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Mozilla\Firefox\Profiles scheduled to be moved on reboot.
                                C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Mozilla\Firefox\Mozilla Firefox\updates\0 moved successfully.
                                C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Mozilla\Firefox\Mozilla Firefox\updates moved successfully.
                                C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Mozilla\Firefox\Mozilla Firefox moved successfully.
                                Folder move failed. C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Mozilla\Firefox scheduled to be moved on reboot.
                                Folder move failed. C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Mozilla scheduled to be moved on reboot.
                                C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\MicroVision Applications\{963b9d7b-39b5-4437-996d-313866d97e68}\User Templates moved successfully.
                                C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\MicroVision Applications\{963b9d7b-39b5-4437-996d-313866d97e68}\TEMPLATE moved successfully.
                                C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\MicroVision Applications\{963b9d7b-39b5-4437-996d-313866d97e68}\DesignGallery moved successfully.
                                C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\MicroVision Applications\{963b9d7b-39b5-4437-996d-313866d97e68} moved successfully.
                                C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\MicroVision Applications moved successfully.
                                C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Microsoft\Windows Media\9.0 moved successfully.
                                C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Microsoft\Windows Media\11.0 moved successfully.
                                C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Microsoft\Windows Media\10.0 moved successfully.
                                C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Microsoft\Windows Media moved successfully.
                                Folder move failed. C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Microsoft\Windows scheduled to be moved on reboot.
                                C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Microsoft\Portable Devices moved successfully.
                                C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Microsoft\Outlook moved successfully.
                                C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Microsoft\Money\15.0\Webcache moved successfully.
                                C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Microsoft\Money\15.0 moved successfully.
                                C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Microsoft\Money moved successfully.
                                C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Microsoft\Media Player\Transcoded Files Cache moved successfully.
                                C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Microsoft\Media Player\Cache d’images\LocalMLS moved successfully.
                                C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Microsoft\Media Player\Cache d’images moved successfully.
                                C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Microsoft\Media Player moved successfully.
                                C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Microsoft\Internet Explorer\Services moved successfully.
                                C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Microsoft\Internet Explorer\Recovery\Last Active moved successfully.
                                C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Microsoft\Internet Explorer\Recovery\Active moved successfully.
                                C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Microsoft\Internet Explorer\Recovery moved successfully.
                                C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Microsoft\Internet Explorer moved successfully.
                                C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Microsoft\HelpCtr moved successfully.
                                C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Microsoft\FORMS\IPM.Contact.SBE moved successfully.
                                C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Microsoft\FORMS moved successfully.
                                C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Microsoft\Feeds Cache\VMQLGABL moved successfully.
                                C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Microsoft\Feeds Cache\R3FC0X9H moved successfully.
                                C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Microsoft\Feeds Cache\4SPUA3HW moved successfully.
                                C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Microsoft\Feeds Cache\2YAQIZL7 moved successfully.
                                C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Microsoft\Feeds Cache moved successfully.
                                C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Microsoft\Feeds\{5588ACFD-6436-411B-A5CE-666AE6A92D3D}~\WebFilters~ moved successfully.
                                C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Microsoft\Feeds\{5588ACFD-6436-411B-A5CE-666AE6A92D3D}~ moved successfully.
                                C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Microsoft\Feeds\Microsoft Feeds~ moved successfully.
                                C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Microsoft\Feeds moved successfully.
                                C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Microsoft\Credentials\S-1-5-21-816502443-3659147561-3435239684-1008 moved successfully.
                                C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Microsoft\Credentials moved successfully.
                                C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Microsoft\CD Burning moved successfully.
                                Folder move failed. C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Microsoft scheduled to be moved on reboot.
                                C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\IsolatedStorage\hit2mkgs.ftq\sutraphx.c5q\StrongName.xn2hptfmkme5wqehe3foutonjsxkvjd0\AssemFiles moved successfully.
                                C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\IsolatedStorage\hit2mkgs.ftq\sutraphx.c5q\StrongName.xn2hptfmkme5wqehe3foutonjsxkvjd0 moved successfully.
                                C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\IsolatedStorage\hit2mkgs.ftq\sutraphx.c5q\StrongName.xitmqsrqvpqpovqi5kx5u3ghwej4ru23\AssemFiles moved successfully.
                                C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\IsolatedStorage\hit2mkgs.ftq\sutraphx.c5q\StrongName.xitmqsrqvpqpovqi5kx5u3ghwej4ru23 moved successfully.
                                C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\IsolatedStorage\hit2mkgs.ftq\sutraphx.c5q moved successfully.
                                C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\IsolatedStorage\hit2mkgs.ftq moved successfully.
                                C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\IsolatedStorage moved successfully.
                                C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Identities\{03089365-441A-4383-BA8D-4736B9AC7834}\Microsoft\Outlook Express moved successfully.
                                C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Identities\{03089365-441A-4383-BA8D-4736B9AC7834}\Microsoft moved successfully.
                                C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Identities\{03089365-441A-4383-BA8D-4736B9AC7834} moved successfully.
                                C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Identities moved successfully.
                                C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\HP\Digital Imaging\Vault\temp moved successfully.
                                C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\HP\Digital Imaging\Vault moved successfully.
                                C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\HP\Digital Imaging\PlugInData moved successfully.
                                Folder move failed. C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\HP\Digital Imaging\db scheduled to be moved on reboot.
                                C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\HP\Digital Imaging\cache moved successfully.
                                Folder move failed. C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\HP\Digital Imaging scheduled to be moved on reboot.
                                Folder move failed. C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\HP scheduled to be moved on reboot.
                                C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Help moved successfully.
                                C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Google\GoogleEarth\models moved successfully.
                                C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Google\GoogleEarth\images moved successfully.
                                C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Google\GoogleEarth\icons moved successfully.
                                C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Google\GoogleEarth moved successfully.
                                C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Google\Custom Buttons\Overrides moved successfully.
                                C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Google\Custom Buttons\Enterprise moved successfully.
                                C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Google\Custom Buttons moved successfully.
                                C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Google moved successfully.
                                C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Conduit moved successfully.
                                Folder move failed. C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\ApplicationHistory scheduled to be moved on reboot.
                                C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Apple Computer\SyncNotifier\SyncNotifier\Logs moved successfully.
                                C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Apple Computer\SyncNotifier\SyncNotifier moved successfully.
                                C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Apple Computer\SyncNotifier moved successfully.
                                C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Apple Computer\Safari\History moved successfully.
                                C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Apple Computer\Safari moved successfully.
                                C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Apple Computer\QuickTime\downloads moved successfully.
                                C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Apple Computer\QuickTime moved successfully.
                                C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Apple Computer\iTunes moved successfully.
                                C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Apple Computer moved successfully.
                                C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Apple\Apple Software Update moved successfully.
                                C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Apple moved successfully.
                                C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Adobe\Updater5\Install\reader8rdr-fr_FR moved successfully.
                                C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Adobe\Updater5\Install moved successfully.
                                C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Adobe\Updater5\Data moved successfully.
                                C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Adobe\Updater5 moved successfully.
                                C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Adobe\ESD moved successfully.
                                C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Adobe\Color moved successfully.
                                C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Adobe\Acrobat\8.0\Updater moved successfully.
                                C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Adobe\Acrobat\8.0\Cache\Search80 moved successfully.
                                C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Adobe\Acrobat\8.0\Cache moved successfully.
                                C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Adobe\Acrobat\8.0 moved successfully.
                                C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Adobe\Acrobat\7.0\Cache\Search70 moved successfully.
                                C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Adobe\Acrobat\7.0\Cache moved successfully.
                                C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Adobe\Acrobat\7.0 moved successfully.
                                C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Adobe\Acrobat\6.0\Cache\Search moved successfully.
                                C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Adobe\Acrobat\6.0\Cache moved successfully.
                                C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Adobe\Acrobat\6.0 moved successfully.
                                C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Adobe\Acrobat moved successfully.
                                C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Adobe moved successfully.
                                Folder move failed. C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data scheduled to be moved on reboot.
                                Folder move failed. C:\DOCUME~1\HP_PRO~1\LOCALS~1 scheduled to be moved on reboot.

                                OTMoveIt2 by OldTimer - Version 1.0.4.3 log created on 10202008_224829

                                Files moved on Reboot...
                                C:\DOCUME~1\HP_PRO~1\LOCALS~1\Temporary Internet Files\Content.IE5\SUPA983I moved successfully.
                                C:\DOCUME~1\HP_PRO~1\LOCALS~1\Temporary Internet Files\Content.IE5\QI2LCXX9 moved successfully.
                                C:\DOCUME~1\HP_PRO~1\LOCALS~1\Temporary Internet Files\Content.IE5\BOZA6HAW moved successfully.
                                C:\DOCUME~1\HP_PRO~1\LOCALS~1\Temporary Internet Files\Content.IE5\1CB40VT3 moved successfully.
                                Folder move failed. C:\DOCUME~1\HP_PRO~1\LOCALS~1\Temporary Internet Files\Content.IE5 scheduled to be moved on reboot.
                                Folder move failed. C:\DOCUME~1\HP_PRO~1\LOCALS~1\Temporary Internet Files\Content.IE5 scheduled to be moved on reboot.
                                Folder move failed. C:\DOCUME~1\HP_PRO~1\LOCALS~1\Temporary Internet Files scheduled to be moved on reboot.
                                C:\DOCUME~1\HP_PRO~1\LOCALS~1\Temp moved successfully.
                                C:\DOCUME~1\HP_PRO~1\LOCALS~1\Historique\History.IE5\MSHist012008102020081021 moved successfully.
                                Folder move failed. C:\DOCUME~1\HP_PRO~1\LOCALS~1\Historique\History.IE5 scheduled to be moved on reboot.
                                Folder move failed. C:\DOCUME~1\HP_PRO~1\LOCALS~1\Historique\History.IE5 scheduled to be moved on reboot.
                                Folder move failed. C:\DOCUME~1\HP_PRO~1\LOCALS~1\Historique scheduled to be moved on reboot.
                                C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Mozilla\Firefox\Profiles\tudhcadj.default\Cache moved successfully.
                                C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Mozilla\Firefox\Profiles\tudhcadj.default moved successfully.
                                C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Mozilla\Firefox\Profiles moved successfully.
                                C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Mozilla\Firefox moved successfully.
                                C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Mozilla moved successfully.
                                Folder move failed. C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Microsoft\Windows scheduled to be moved on reboot.
                                Folder move failed. C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Microsoft\Windows scheduled to be moved on reboot.
                                C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Microsoft\Credentials\S-1-5-21-816502443-3659147561-3435239684-1008 moved successfully.
                                C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Microsoft\Credentials moved successfully.
                                Folder move failed. C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Microsoft scheduled to be moved on reboot.
                                C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\HP\Digital Imaging\db moved successfully.
                                C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\HP\Digital Imaging moved successfully.
                                C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\HP moved successfully.
                                C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\ApplicationHistory moved successfully.
                                Folder move failed. C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Microsoft\Windows scheduled to be moved on reboot.
                                Folder move failed. C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Microsoft scheduled to be moved on reboot.
                                Folder move failed. C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data scheduled to be moved on reboot.
                                Folder move failed. C:\DOCUME~1\HP_PRO~1\LOCALS~1\Temporary Internet Files\Content.IE5 scheduled to be moved on reboot.
                                Folder move failed. C:\DOCUME~1\HP_PRO~1\LOCALS~1\Temporary Internet Files scheduled to be moved on reboot.
                                Folder move failed. C:\DOCUME~1\HP_PRO~1\LOCALS~1\Historique\History.IE5 scheduled to be moved on reboot.
                                Folder move failed. C:\DOCUME~1\HP_PRO~1\LOCALS~1\Historique scheduled to be moved on reboot.
                                Folder move failed. C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Microsoft\Windows scheduled to be moved on reboot.
                                Folder move failed. C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data\Microsoft scheduled to be moved on reboot.
                                Folder move failed. C:\DOCUME~1\HP_PRO~1\LOCALS~1\Application Data scheduled to be moved on reboot.
                                Folder move failed. C:\DOCUME~1\HP_PRO~1\LOCALS~1 scheduled to be moved on reboot.
                                1. Contributeur
                                  double-clique sur OTMoveIt.exe pour le lancer.
                                  Assure toi que la case Unregister Dll's and Ocx's soit bien cochée
                                  copie la liste qui se trouve en gras ci-dessous,
                                  et colle-la dans le cadre de gauche de OTMoveIt :Paste List of Files/Folders to be moved.

                                  C:\DOCUME~1\HP_PRO~1\LOCALS~1

                                  clique sur MoveIt! pour lancer la suppression.
                                  le résultat apparaitra dans le cadre "Results".
                                  clique sur Exit pour fermer.
                                  poste le rapport situé dans C:\_OTMoveIt\MovedFiles.

                                  il te sera peut-être demander de redémarrer le pc pour achever la suppression.si c'est le cas accepte par Yes.

                                  @++
                                  1. Infection absente


                                    Pas de fichiers types date_heures_.txt



                                    Dossier .txt :


                                    C:\Program Files\skmw\
                                    C:\Program Files\skmw\sec\
                                    C:\Program Files\skmw\WinRds\
                                    C:\Program Files\Microsoft Studio Files\
                                    C:\Program Files\nsnimage\
                                    C:\Program Files\RealtekAZ\
                                    C:\Program Files\xerox\nwmedia\
                                    C:\WINDOWS\system32\mrdv\
                                    C:\Program Files\Spcron\
                                    C:\Program Files\Svconr\
                                    C:\DOCUME~1\HP_PRO~1\APPLIC~1\WinTouch\
                                    C:\Program Files\CPV\
                                    C:\Program Files\nvcoi\
                                    C:\Program Files\outerinfo\
                                    C:\Program Files\Temporary\
                                    C:\DOCUME~1\HP_PRO~1\APPLIC~1\SpeedRunner\
                                    C:\Program Files\Twain\
                                    C:\Program Files\Inet_Get_2\
                                    C:\Program Files\Fichiers communs\Carlson\
                                    C:\Program Files\Fichiers communs\Delsim\
                                    \Carlson\
                                    C:\Program Files\Bifrost\
                                    C:\Program Files\ddm\
                                    C:\Program Files\InetGet2\
                                    C:\Program Files\Insider\
                                    C:\Program Files\ISM\
                                    C:\Program Files\ISM2\
                                    C:\Program Files\QdrModule\
                                    C:\Program Files\QdrPack\
                                    C:\Program Files\Temporary\
                                    C:\Program Files\WinAble\
                                    C:\Program Files\WinPop\
                                    C:\Program Files\nvcoi\
                                    C:\AVG_BETA\
                                    C:\Conf\
                                    C:\Install\
                                    C:\Lixo\
                                    C:\oddysee\
                                    C:\Program Files\nvcoi\
                                    C:\DOCUME~1\HP_PRO~1\LOCALS~1\Temp\ARC64\
                                    C:\DOCUME~1\HP_PRO~1\LOCALS~1\Temp\nsa2.tmp\
                                    C:\WINDOWS\_tmp\
                                    C:\Program Files\CPV\
                                    C:\WINDOWS\crack\
                                    C:\WINDOWS\htmCache\
                                    C:\WINDOWS\system32\B1\
                                    C:\WINDOWS\system32\B2\
                                    C:\WINDOWS\system32\openfile\
                                    C:\WINDOWS\system32\Security\
                                    C:\WINDOWS\system32\service\
                                    C:\WINDOWS\system32\updatelinkmsn\
                                    C:\DOCUME~1\HP_PRO~1\APPLIC~1\WinTouch\
                                    C:\DOCUME~1\HP_PRO~1\LOCALS~1\Temp\nsb2.tmp\

                                    Temp.txt

                                    [C:\WINDOWS\system32\winchat.exe] 2A99260794224489F29B628717B7947E
                                    [C:\WINDOWS\system32\WinFXDocObj.exe] F248619BCAF7EA3AF6C6A7D4F1EA5699
                                    [C:\WINDOWS\system32\winhlp32.exe] 577624F19D0441C9111F2AF26C81E04D
                                    [C:\WINDOWS\system32\winlogon.exe] D2DE785AEAB0BB8CA4C14A8A199DBE4E
                                    [C:\WINDOWS\system32\winmine.exe] EA682C022F7204CC8E8C9EF5DCE29356
                                    [C:\WINDOWS\system32\winmsd.exe] 7EBF8A4B608AFB79C67F4E4A9C5885BB
                                    [C:\WINDOWS\system32\winspool.exe] 0B4B94B78123E8035B84105BC024F9F8
                                    [C:\WINDOWS\system32\winver.exe] CE30DCEF79B94D17A8B3BEC26FEF90A3
                                    [C:\WINDOWS\system32\winchat.exe] 2A99260794224489F29B628717B7947E
                                    [C:\WINDOWS\system32\WinFXDocObj.exe] F248619BCAF7EA3AF6C6A7D4F1EA5699
                                    [C:\WINDOWS\system32\winhlp32.exe] 577624F19D0441C9111F2AF26C81E04D
                                    [C:\WINDOWS\system32\winlogon.exe] D2DE785AEAB0BB8CA4C14A8A199DBE4E
                                    [C:\WINDOWS\system32\winmine.exe] EA682C022F7204CC8E8C9EF5DCE29356
                                    [C:\WINDOWS\system32\winmsd.exe] 7EBF8A4B608AFB79C67F4E4A9C5885BB
                                    [C:\WINDOWS\system32\winspool.exe] 0B4B94B78123E8035B84105BC024F9F8
                                    [C:\WINDOWS\system32\winver.exe] CE30DCEF79B94D17A8B3BEC26FEF90A3
                                    • 1
                                    • 2
                                    • 3