PROBLEME programme suspect !!

Bonjour,

J'ai un petit soucis.
Ca fait plusieurs semaines que un programme nommé "k.exe" apparait à l'écran dans une fentre Vista.
En effet, une fenetre s'ouvre en disant :
"un probleme a fait que le programme a cessé de fonctionner correctement... Fermer le programme"
Donc si vous aviez une idée de ce que ca peut être ...
Je ne sais pas du tout ce qu'est ce programme et quand je recherche sur mon disque dur il ne le trouve pas ...
Serait il possible que ce soit un programme malveillant ?
J'utilise aantivir et spybot destroy...

Voilà
Merci de votre aide ! ;)
Configuration: Windows Vista
Firefox 3.0.5

37 réponses

Résumé de la discussion

Un souci lié à un programme nommé k.exe apparaît sur Windows Vista, avec une fenêtre indiquant que le programme a cessé de fonctionner et qu'il n'est pas facilement localisable sur le disque. Des réponses recommandent d'utiliser Random's System Information Tool (RSIT) pour analyser et générer des fichiers log (log.txt et info.txt), puis de les poster pour analyse. Il est conseillé de ne pas utiliser d’outils non demandés et de redémarrer après, avec des rapports qui peuvent aider à diagnostiquer une éventuelle infection malware et les mesures de désinfection. En parallèle, certains échanges détaillent les noms de processus et les emplacements typiques des fichiers suspects, notamment dans les dossiers AppData Roaming et le dossier Temp.

Bobot (l’IA à votre service)
  1. bonjour ,

    Télécharge Random's System Information Tool (RSIT) de random/random et enregistre l'exécutable sur ton Bureau.

    -> http://images.malwareremoval.com/random/RSIT.exe

    ! Déconnecte toi et ferme toutes tes applications en cours !

    Double-clique sur " RSIT.exe " pour le lancer .

    -> Une première fenêtre s'ouvre avec en titre : " Disclaimer of warranty " .

    * Devant l'option "List files/folders created ..." , tu choisis : 2 months

    * clique ensuite sur " Continue " pour lancer l'analyse ...

    -> laisse faire le scan et ne touche pas au PC ...

    Lorsque l'analyse sera terminée, deux fichiers texte s'ouvriront (probablement avec le bloc-note).

    Poste le contenu de " log.txt " (c'est celui qui apparait à l'écran), ainsi que de " info.txt " (que tu verras dans la barre des tâches), pour analyse et attends la suite ...

    Important : poste un rapport, puis l'autre dans la réponse suivante
    Si tu essaies de poster les deux en même temps, cela risque d'être trop long pour le forum

    ( Note : les rapports seront en outre sauvegardés dans ce dossier -> C:\rsit )

    1. ok je pars jouer de la musique dès que je rentre je te suis....patience
      1. VOICI le premier rapport "info"

        info.txt logfile of random's system information tool 1.05 2009-01-10 18:33:19

        ======Uninstall list======

        -->C:\Program Files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
        -->C:\Program Files\OrangeHSS\Uninstall\Bas_Debit_CustoUpdate\Shell.exe MainUninstall.shl
        -->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{363435F2-7426-11D8-9966-00A0C9663221}\setup.exe" -l0x40c
        -->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{5CDDF96A-BC34-4D72-9ABA-E1FFF0C39977}\setup.exe" -l0x40c
        32 Bit HP CIO Components Installer-->MsiExec.exe /I{F7B0E599-C114-4493-BC4D-D8FC7CBBABBB}
        Acer Arcade Live Main Page-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{EFBDC2B0-FAA8-4B78-8DE1-AEBE7958FA37}\SETUP.exe" -uninstall
        Acer DV Magician-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F6EFFB76-4A07-11DA-9D78-000129760D75}\SETUP.exe" -uninstall
        Acer DVDivine-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{B145EC69-66F5-11D8-9D75-000129760D75}\SETUP.exe" -uninstall
        Acer eDataSecurity Management-->C:\Acer\Empowering Technology\eDataSecurity\eDSnstHelper.exe -Operation UNINSTALL
        Acer Empowering Technology-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{AB6097D9-D722-4987-BD9E-A076E2848EE2}\setup.exe" -l0x40c -removeonly
        Acer ePerformance Management-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{D462BF9E-0C35-4705-BF9B-3DF9F3816643}\setup.exe" -l0x40c -removeonly
        Acer HomeMedia Connect-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{132888AE-EF67-41C5-BCA2-7D5D2488AB63}\SETUP.exe" -uninstall
        Acer HomeMedia-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{AA4BF92B-2AAF-11DA-9D78-000129760D75}\SETUP.exe" -uninstall
        Acer PlayMovie-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{A450831D-25F6-4F42-9662-D000B25E0D82}\Setup.exe" -uninstall
        Acer ScreenSaver-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{79DD56FC-DB8B-47F5-9C80-78B62E05F9BC}\setup.exe" -l0x9 -removeonly
        Acer SlideShow DVD-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{41581EF5-45A7-11DA-9D78-000129760D75}\SETUP.exe" -uninstall
        Acer Tour-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{94389919-B0AA-4882-9BE8-9F0B004ECA35}\setup.exe" -l0x40c -removeonly
        Acer VideoMagician-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F79A208D-D929-11D9-9D77-000129760D75}\SETUP.exe" -uninstall
        Activation Assistant for the 2007 Microsoft Office suites-->"C:\ProgramData\{174892B1-CBE7-44F5-86FF-AB555EFD73A3}\Microsoft Office Activation Assistant.exe" REMOVE=TRUE MODIFY=FALSE
        Adobe AIR-->c:\Program Files\Common Files\Adobe AIR\Versions\1.0\Resources\Adobe AIR Updater.exe -arp:uninstall
        Adobe AIR-->MsiExec.exe /I{A2BCA9F1-566C-4805-97D1-7FDC93386723}
        Adobe Flash Player 10 Plugin-->C:\Windows\system32\Macromed\Flash\uninstall_plugin.exe
        Adobe Flash Player 9 ActiveX-->C:\Windows\system32\Macromed\Flash\FlashUtil9b.exe -uninstallDelete
        Adobe Flash Player ActiveX-->C:\Windows\system32\Macromed\Flash\uninstall_activeX.exe
        Adobe Reader 8.1.3 - Français-->MsiExec.exe /I{AC76BA86-7AD7-1036-7B44-A81300000003}
        Apple Mobile Device Support-->MsiExec.exe /I{44734179-8A79-4DEE-BB08-73037F065543}
        Apple Software Update-->MsiExec.exe /I{02DFF6B1-1654-411C-8D7B-FD6052EF016F}
        Archiveur WinRAR-->C:\Program Files\WinRAR\uninstall.exe
        Assistant de connexion Windows Live-->MsiExec.exe /I{AFA4E5FD-ED70-4D92-99D0-162FD56DC986}
        Audacity 1.2.6-->"C:\Program Files\Audacity\unins000.exe"
        Avira AntiVir Personal - Free Antivirus-->C:\Program Files\Avira\AntiVir PersonalEdition Classic\SETUP.EXE /REMOVE
        AviSynth 2.5-->"C:\Program Files\AviSynth 2.5\Uninstall.exe"
        Bonjour-->MsiExec.exe /I{47BF1BD6-DCAC-468F-A0AD-E5DECC2211C3}
        CamStudio 2.0 Fr-->"C:\Program Files\CamStudio\unins000.exe"
        CCleaner (remove only)-->"C:\Program Files\CCleaner\uninst.exe"
        Creative WebCam Center-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{363435F2-7426-11D8-9966-00A0C9663221}\setup.exe" -l0x40c /remove
        Creative WebCam Live! Driver (1.01.01.0730)-->C:\Windows\CtDrvIns.exe -uninstall -script Pd0630.uns -unsext NT -plugin P0630Pin.dll -pluginres P0630Pin.crl
        Empire of Sports 1.64-->C:\Program Files\Empire of Sports\Uninstall.exe
        eMule-->"C:\Program Files\eMule\Uninstall.exe"
        EPSON Logiciel imprimante-->C:\Windows\system32\spool\DRIVERS\W32X86\3\EPUPDATE.EXE /r
        EPSON PhotoQuicker3.2-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{B2EFE303-A594-11D5-95EB-005004BC1C65}\setup.exe" uninst
        Favorit-->c:\users\maxime\appdata\local\kecfcxux.bat
        Free Video Converter V 1.4-->"C:\Program Files\Free Video Converter\unins000.exe"
        Free Video to iPod Converter version 3.1-->"C:\Program Files\DVDVideoSoft\Free Video to iPod Converter\unins000.exe"
        Free Video to Mp3 Converter version 2.7-->"C:\Program Files\DVDVIDEOSOFT\Free Video to Mp3 Converter\unins000.exe"
        Free YouTube to iPod Converter version 3.1-->"C:\Program Files\DVDVideoSoft\Free YouTube to iPod Converter\unins000.exe"
        Google Toolbar for Internet Explorer-->"C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarManager_0531C63A913CC9D1.exe" /uninstall
        HijackThis 2.0.2-->"C:\Program Files\trend micro\HijackThis.exe" /uninstall
        HP Imaging Device Functions 11.0-->C:\Program Files\HP\Digital Imaging\DeviceManagement\hpzscr01.exe -datfile hpqbud01.dat
        HP Photosmart C5300 All-In-One Driver Software 11.0 Rel .4-->C:\Program Files\HP\Digital Imaging\{69C57747-551F-4e4f-AB60-13358DC4F00A}\setup\hpzscr01.exe -datfile hposcr32.dat -onestop
        HP Photosmart Essential 3.0-->C:\Program Files\HP\Digital Imaging\PhotoSmartEssential\hpzscr01.exe -datfile hpqbud13.dat
        HP Smart Web Printing-->C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpzscr01.exe -datfile hpqbud15.dat
        HP Solution Center 11.0-->C:\Program Files\HP\Digital Imaging\eSupport\hpzscr01.exe -datfile hpqbud05.dat
        HP Update-->MsiExec.exe /X{FE57DE70-95DE-4B64-9266-84DA811053DB}
        iTunes-->MsiExec.exe /I{9F70BF98-003C-491D-81FC-FF9792206AF0}
        Jaquette Express 1.8.0.0-->"C:\Program Files\Jaquette Express\uninstall.exe"
        Java(TM) 6 Update 11-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216011FF}
        Java(TM) 6 Update 7-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160070}
        livebox-->C:\Program Files\InstallShield Installation Information\{17342E3B-0818-4A6F-BFF8-99476605ADD6}\Setup.exe -runfromtemp -l0x040c -removeonly
        Luxor 2-->"C:\Program Files\Acer GameZone\Luxor 2\Uninstall.exe" "C:\Program Files\Acer GameZone\Luxor 2\install.log"
        MCF Ravenhearst-->"C:\Program Files\Acer GameZone\MCF Ravenhearst\Uninstall.exe" "C:\Program Files\Acer GameZone\MCF Ravenhearst\install.log"
        Messenger Plus! Live-->"C:\Program Files\Messenger Plus! Live\Uninstall.exe"
        Microsoft Office Professional Edition 2003-->MsiExec.exe /I{9011040C-6000-11D3-8CFE-0150048383C9}
        Microsoft Silverlight-->MsiExec.exe /I{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
        Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
        Mozilla Firefox (3.0.5)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
        MSXML 4.0 SP2 (KB936181)-->MsiExec.exe /I{C04E32E0-0416-434D-AFB9-6969D703A9EF}
        MSXML 4.0 SP2 (KB941833)-->MsiExec.exe /I{C523D256-313D-4866-B36A-F3DE528246EF}
        MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
        Navigateur Orange-->C:\Program Files\OrangeHSS\Uninstall\Browser\Shell.exe MainUninstall.shl
        NTI Backup NOW! 4.7-->"C:\Program Files\InstallShield Installation Information\{1598034D-7147-432C-8CA8-888E0632D124}\setup.exe" -removeonly
        NTI Backup NOW! 4.7-->C:\Program Files\InstallShield Installation Information\{1598034D-7147-432C-8CA8-888E0632D124}\setup.exe -runfromtemp -l0x040c
        NTI CD & DVD-Maker-->C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{1577A05B-EE62-4BBC-9DB7-FE748FA44EC2} /l1036 CDM7
        NVIDIA Drivers-->C:\Windows\system32\nvunrm.exe UninstallGUI
        Nvu 1.0-->"C:\Program Files\Nvu\unins000.exe"
        OCR Software by I.R.I.S. 11.0-->C:\Program Files\HP\Digital Imaging\OCR\hpzscr01.exe -datfile hpqbud11.dat
        OpenAL-->"C:\Program Files\OpenAL\oalinst.exe" /U
        OpenOffice.org 3.0 Language Pack (French)-->MsiExec.exe /I{2A0DB319-6365-4876-B7D8-994A79AA1329}
        OpenOffice.org 3.0-->MsiExec.exe /I{1572F66F-F9AD-4D45-B0D2-0F45A0D5A0F6}
        Orange - Logiciels Internet-->C:\Program Files\OrangeHSS\installation\core\Installgui.exe -u
        Pro Evolution Soccer 2009-->MsiExec.exe /X{A8DB611A-D80E-450D-85F6-3ACDD164BE31}
        QuickTime-->MsiExec.exe /I{08CA9554-B5FE-4313-938F-D4A417B81175}
        RealPlayer-->C:\Program Files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
        Realtek High Definition Audio Driver-->RtlUpd.exe -r -m
        SAMSUNG Mobile Modem Driver Set-->C:\Windows\system32\Samsung_USB_Drivers\3\SSCDUninstall.exe
        Samsung Mobile phone USB driver Software-->C:\Windows\system32\Samsung_USB_Drivers\5\SSSDUninstall.exe
        SAMSUNG Mobile USB Modem 1.0 Software-->C:\Windows\system32\Samsung_USB_Drivers\1\SS_Uninstall.exe
        SAMSUNG Mobile USB Modem Software-->C:\Windows\system32\Samsung_USB_Drivers\2\SSM_Uninstall.exe
        Samsung PC Studio 3 USB Driver Installer-->"C:\Program Files\InstallShield Installation Information\{EBA29752-DDD2-4B62-B2E3-9841F92A3E3A}\setup.exe" -runfromtemp -l0x040c -removeonly
        Samsung PC Studio 3-->"C:\Program Files\InstallShield Installation Information\{C4A4722E-79F9-417C-BD72-8D359A090C97}\setup.exe" -runfromtemp -l0x040c -removeonly
        Security Update for CAPICOM (KB931906)-->MsiExec.exe /I{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
        Security Update for CAPICOM (KB931906)-->MsiExec.exe /X{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
        Skype™ 3.8-->MsiExec.exe /X{5C82DAE5-6EB0-4374-9254-BE3319BA4E82}
        SopCast 3.0.1-->C:\Program Files\SopCast\uninst.exe
        Spelling Dictionaries Support For Adobe Reader 8-->MsiExec.exe /I{AC76BA86-7AD7-5464-3428-800000000003}
        Spybot - Search & Destroy-->"C:\Program Files\Spybot - Search & Destroy\unins000.exe"
        TmNationsForever-->"C:\Program Files\TmNationsForever\unins000.exe"
        VideoLAN VLC media player 0.8.6h-->C:\Program Files\VideoLAN\VLC\uninstall.exe
        Virtual DJ - Atomix Productions-->C:\PROGRA~1\VIRTUA~1\UNWISE.EXE C:\PROGRA~1\VIRTUA~1\INSTALL.LOG
        Vista Codec Package-->MsiExec.exe /I{F9FD80CE-0448-4D4F-8BCD-77FC514C3F99}
        Windows Live installer-->MsiExec.exe /X{FD44E544-E7D0-4DBA-9FA0-8AE1A1300390}
        Windows Live Messenger-->MsiExec.exe /X{BADF6744-3787-48F6-B8C9-4C4995401D65}
        Windows Media Player Firefox Plugin-->MsiExec.exe /I{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}

        ======Hosts File======

        127.0.0.1 myomemo.com
        127.0.0.1 www.myomemo.com

        ======Security center information======

        AV: Avira AntiVir PersonalEdition
        AS: Windows Defender

        System event log

        Computer Name: PC-des-Moitel
        Event Code: 3004
        Message: L’agent de protection en temps réel Windows Defender a détecté des modifications. Microsoft vous recommande d’analyser les logiciels responsables de ces modifications, à la recherche de risques potentiels. Vous pouvez vous servir des informations relatives au fonctionnement de ces programmes pour autoriser ou non leur exécution, ou pour les supprimer de l’ordinateur. N’autorisez les modifications que si vous faites confiance au programme ou à l’éditeur de logiciel. Windows Defender ne peut pas annuler les modifications que vous autorisez.
        Pour plus d’informations, consultez les données suivantes :
        Non applicable
        ID d’analyse : {1D3F492A-DDB2-4721-A1B6-89D5F4AF73C4}
        Utilisateur : PC-DES-MOITEL\Maxime
        Nom : Unknown
        ID :
        ID de gravité :
        ID de catégorie :
        Chemin d’accès trouvé : file:C:\Users\Maxime\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\StartUp\OpenOffice.org 3.0.lnk;file:C:\Program Files\OpenOffice.org 3\program\quickstart.exe;startup:C:\Users\Maxime\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\StartUp\OpenOffice.org 3.0.lnk
        Type d’alerte : Logiciel non classifié
        Type de détection :
        Record Number: 62831
        Source Name: Microsoft-Windows-Windows Defender
        Time Written: 20090110133821.000000-000
        Event Type: Avertissement
        User:

        Computer Name: PC-des-Moitel
        Event Code: 3005
        Message: L’agent de protection en temps réel Windows Defender a pris des mesures pour protéger cet ordinateur contre les logiciels espions ou autres logiciels potentiellement indésirables.
        Pour plus d’informations, consultez les informations suivantes :
        Non applicable
        ID d’analyse : {1D3F492A-DDB2-4721-A1B6-89D5F4AF73C4}
        Utilisateur : PC-DES-MOITEL\Maxime
        Nom : Unknown
        ID :
        ID de gravité :
        ID de catégorie :
        Type d’alerte : Logiciel non classifié
        Action : Ignorer
        Record Number: 62832
        Source Name: Microsoft-Windows-Windows Defender
        Time Written: 20090110133821.000000-000
        Event Type: Information
        User:

        Computer Name: PC-des-Moitel
        Event Code: 7036
        Message: Le service Service de découverte automatique de Proxy Web pour les services HTTP Windows est entré dans l'état : en cours d'exécution.
        Record Number: 62833
        Source Name: Service Control Manager
        Time Written: 20090110133821.000000-000
        Event Type: Information
        User:

        Computer Name: PC-des-Moitel
        Event Code: 7036
        Message: Le service Service de découverte automatique de Proxy Web pour les services HTTP Windows est entré dans l'état : arrêté.
        Record Number: 62834
        Source Name: Service Control Manager
        Time Written: 20090110135451.000000-000
        Event Type: Information
        User:

        Computer Name: PC-des-Moitel
        Event Code: 7036
        Message: Le service Informations d'application est entré dans l'état : en cours d'exécution.
        Record Number: 62835
        Source Name: Service Control Manager
        Time Written: 20090110170524.000000-000
        Event Type: Information
        User:

        Application event log

        Computer Name: PC-des-Moitel
        Event Code: 1000
        Message: Application défaillante k.exe, version 0.0.0.0, horodatage 0x2eee229e, module défaillant ntdll.dll, version 6.0.6001.18000, horodatage 0x4791a7a6, code d’exception 0xc0000005, décalage d’erreur 0x0003d0cd, ID du processus 0x11c0, heure de début de l’application 0x01c97344ead52765.
        Record Number: 16666
        Source Name: Application Error
        Time Written: 20090110170019.000000-000
        Event Type: Erreur
        User:

        Computer Name: PC-des-Moitel
        Event Code: 1000
        Message: Application défaillante k.exe, version 0.0.0.0, horodatage 0x2eee229e, module défaillant ntdll.dll, version 6.0.6001.18000, horodatage 0x4791a7a6, code d’exception 0xc0000005, décalage d’erreur 0x0003d0cd, ID du processus 0x121c, heure de début de l’application 0x01c973463cd569c5.
        Record Number: 16667
        Source Name: Application Error
        Time Written: 20090110170946.000000-000
        Event Type: Erreur
        User:

        Computer Name: PC-des-Moitel
        Event Code: 1024
        Message: Le ou les disques ont TtT analysTs pour lÆTtat SMART.
        Record Number: 16668
        Source Name: NVRAIDSERVICE
        Time Written: 20090110171017.000000-000
        Event Type: Information
        User:

        Computer Name: PC-des-Moitel
        Event Code: 1001
        Message: Récipient d’erreurs 990707048, type 1
        Événement : APPCRASH
        Réponse : Aucun
        ID de CAB : 0

        Signature du problème :
        P1 : k.exe
        P2 : 0.0.0.0
        P3 : 2eee229e
        P4 : ntdll.dll
        P5 : 6.0.6001.18000
        P6 : 4791a7a6
        P7 : c0000005
        P8 : 0003d0cd
        P9 :
        P10 :

        Fichiers joints :
        C:\Users\Maxime\AppData\Local\Temp\WER54AE.tmp.version.txt

        Ces fichiers sont peut-être disponibles ici :
        C:\Users\Maxime\AppData\Local\Microsoft\Windows\WER\ReportArchive\Report162e947c
        Record Number: 16669
        Source Name: Windows Error Reporting
        Time Written: 20090110173259.000000-000
        Event Type: Information
        User:

        Computer Name: PC-des-Moitel
        Event Code: 5
        Message: Unsupported service control request (see data below)
        Record Number: 16670
        Source Name: LightScribeService
        Time Written: 20090110173319.000000-000
        Event Type: Information
        User:

        Security event log

        Computer Name: PC-des-Moitel
        Event Code: 5038
        Message: L’intégrité du code a déterminé que le hachage de l’image d’un fichier n’est pas valide. Le fichier peut être endommagé en raison d’une modification non autorisée ou le hachage non valide peut indiquer une erreur d’unité de disque potentielle.

        Nom du fichier : \Device\HarddiskVolume2\Windows\System32\drivers\tcpip.sys
        Record Number: 22861
        Source Name: Microsoft-Windows-Security-Auditing
        Time Written: 20090110173317.101595-000
        Event Type: Échec de l'audit
        User:

        Computer Name: PC-des-Moitel
        Event Code: 5038
        Message: L’intégrité du code a déterminé que le hachage de l’image d’un fichier n’est pas valide. Le fichier peut être endommagé en raison d’une modification non autorisée ou le hachage non valide peut indiquer une erreur d’unité de disque potentielle.

        Nom du fichier : \Device\HarddiskVolume2\Windows\System32\drivers\tcpip.sys
        Record Number: 22862
        Source Name: Microsoft-Windows-Security-Auditing
        Time Written: 20090110173317.132795-000
        Event Type: Échec de l'audit
        User:

        Computer Name: PC-des-Moitel
        Event Code: 5038
        Message: L’intégrité du code a déterminé que le hachage de l’image d’un fichier n’est pas valide. Le fichier peut être endommagé en raison d’une modification non autorisée ou le hachage non valide peut indiquer une erreur d’unité de disque potentielle.

        Nom du fichier : \Device\HarddiskVolume2\Windows\System32\drivers\tcpip.sys
        Record Number: 22863
        Source Name: Microsoft-Windows-Security-Auditing
        Time Written: 20090110173317.148395-000
        Event Type: Échec de l'audit
        User:

        Computer Name: PC-des-Moitel
        Event Code: 5038
        Message: L’intégrité du code a déterminé que le hachage de l’image d’un fichier n’est pas valide. Le fichier peut être endommagé en raison d’une modification non autorisée ou le hachage non valide peut indiquer une erreur d’unité de disque potentielle.

        Nom du fichier : \Device\HarddiskVolume2\Windows\System32\drivers\tcpip.sys
        Record Number: 22864
        Source Name: Microsoft-Windows-Security-Auditing
        Time Written: 20090110173317.179595-000
        Event Type: Échec de l'audit
        User:

        Computer Name: PC-des-Moitel
        Event Code: 5038
        Message: L’intégrité du code a déterminé que le hachage de l’image d’un fichier n’est pas valide. Le fichier peut être endommagé en raison d’une modification non autorisée ou le hachage non valide peut indiquer une erreur d’unité de disque potentielle.

        Nom du fichier : \Device\HarddiskVolume2\Windows\System32\drivers\tcpip.sys
        Record Number: 22865
        Source Name: Microsoft-Windows-Security-Auditing
        Time Written: 20090110173317.210795-000
        Event Type: Échec de l'audit
        User:

        ======Environment variables======

        "ComSpec"=%SystemRoot%\system32\cmd.exe
        "FP_NO_HOST_CHECK"=NO
        "OS"=Windows_NT
        "Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;C:\Program Files\QuickTime\QTSystem\;C:\Program Files\Common Files\GIS\Tools;C:\Program Files\Samsung\Samsung PC Studio 3\
        "PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC
        "PROCESSOR_ARCHITECTURE"=x86
        "TEMP"=%SystemRoot%\TEMP
        "TMP"=%SystemRoot%\TEMP
        "USERNAME"=SYSTEM
        "windir"=%SystemRoot%
        "PROCESSOR_LEVEL"=6
        "PROCESSOR_IDENTIFIER"=x86 Family 6 Model 15 Stepping 11, GenuineIntel
        "PROCESSOR_REVISION"=0f0b
        "NUMBER_OF_PROCESSORS"=4
        "CLASSPATH"=.;C:\Program Files\Java\jre1.6.0_06\lib\ext\QTJava.zip
        "QTJAVA"=C:\Program Files\Java\jre1.6.0_06\lib\ext\QTJava.zip

        -----------------EOF-----------------
        1. Le deuxième rapport "log"

          Logfile of random's system information tool 1.05 (written by random/random)
          Run by Maxime at 2009-01-10 18:32:51
          Microsoft® Windows Vista™ Édition Familiale Premium Service Pack 1
          System drive C: has 134 GB (57%) free of 234 GB
          Total RAM: 3070 MB (48% free)

          Logfile of Trend Micro HijackThis v2.0.2
          Scan saved at 18:33:18, on 10/01/2009
          Platform: Windows Vista SP1 (WinNT 6.00.1905)
          MSIE: Internet Explorer v7.00 (7.00.6001.18000)
          Boot mode: Normal

          Running processes:
          C:\Windows\system32\Dwm.exe
          C:\Windows\system32\taskeng.exe
          C:\Windows\Explorer.EXE
          C:\Program Files\Windows Defender\MSASCui.exe
          C:\Windows\RtHDVCpl.exe
          C:\Acer\Empowering Technology\SysMonitor.exe
          C:\Acer\Empowering Technology\eDataSecurity\eDSLoader.exe
          C:\Windows\System32\nvraidservice.exe
          C:\Program Files\Acer Arcade Live\Acer PlayMovie\PMVService.exe
          C:\Program Files\OrangeHSS\Systray\SystrayApp.exe
          C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
          C:\Program Files\iTunes\iTunesHelper.exe
          C:\Program Files\Common Files\Real\Update_OB\realsched.exe
          C:\Windows\System32\rundll32.exe
          C:\Program Files\Java\jre6\bin\jusched.exe
          C:\Windows\System32\rundll32.exe
          C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
          C:\Program Files\Windows Sidebar\sidebar.exe
          C:\Windows\ehome\ehtray.exe
          C:\Users\Maxime\AppData\Roaming\tmobd.exe
          C:\Users\Maxime\AppData\Roaming\finalssf\fssf.exe
          C:\Program Files\DAEMON Tools Lite\daemon.exe
          C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
          C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
          C:\Users\Maxime\AppData\Local\uiako.exe
          C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
          C:\Windows\system32\wbem\unsecapp.exe
          C:\Windows\ehome\ehmsas.exe
          C:\Acer\Empowering Technology\eRecovery\ERAGENT.EXE
          C:\Program Files\Internet Explorer\iexplore.exe
          C:\Program Files\Internet Explorer\IEUser.exe
          C:\Program Files\Google\Google Toolbar\GoogleToolbarUser.exe
          C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
          C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_clipbook.exe
          C:\PROGRA~1\COMMON~1\France Telecom\Shared Modules\AlertModule\0\AlertModule.exe
          C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
          C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe
          C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe
          C:\Users\Maxime\AppData\Roaming\tmobd.exe
          C:\Program Files\OrangeHSS\Launcher\Launcher.exe
          C:\Program Files\OrangeHSS\connectivity\connectivitymanager.exe
          C:\Program Files\OrangeHSS\connectivity\CoreCom\CoreCom.exe
          C:\Program Files\OrangeHSS\connectivity\CoreCom\OraConfigRecover.exe
          C:\PROGRA~1\COMMON~1\France Telecom\Shared Modules\FTCOMModule\0\FTCOMModule.exe
          C:\Windows\System32\mobsync.exe
          C:\Program Files\OpenOffice.org 3\program\soffice.exe
          C:\Program Files\OpenOffice.org 3\program\soffice.bin
          C:\Windows\system32\conime.exe
          C:\Windows\system32\cmd.exe
          C:\Users\Maxime\AppData\Roaming\hdf\httpddos.exe
          C:\Program Files\Mozilla Firefox\firefox.exe
          C:\Users\Maxime\AppData\Roaming\msnf3\ms.exe
          C:\Windows\system32\SearchFilterHost.exe
          C:\Users\Maxime\Downloads\RSIT.exe
          C:\Program Files\trend micro\Maxime.exe

          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://fr.rd.yahoo.com/customize/ycomp/defaults/sp/*https://fr.yahoo.com/
          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://fr.yahoo.com/
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
          R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://fr.yahoo.com/
          R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
          R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
          R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://fr.rd.yahoo.com/customize/ycomp/defaults/su/*https://fr.yahoo.com/
          R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
          R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\Program Files\OrangeHSS\SearchURLHook\SearchPageURL.dll
          O1 - Hosts: ::1 localhost
          O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
          O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
          O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
          O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
          O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
          O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
          O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
          O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll
          O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll
          O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
          O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
          O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Windows\system32\eDStoolbar.dll
          O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
          O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
          O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
          O4 - HKLM\..\Run: [Acer Empowering Technology Monitor] C:\Acer\Empowering Technology\SysMonitor.exe
          O4 - HKLM\..\Run: [eDataSecurity Loader] C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe
          O4 - HKLM\..\Run: [PCMMediaSharing] C:\Program Files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\PCMMediaSharing.exe
          O4 - HKLM\..\Run: [Apanel] C:\ACERSW\config\NewSetApanel.cmd
          O4 - HKLM\..\Run: [WarReg_PopUp] C:\Acer\WR_PopUp\WarReg_PopUp.exe
          O4 - HKLM\..\Run: [NVRaidService] C:\Windows\system32\nvraidservice.exe
          O4 - HKLM\..\Run: [Acer Tour Reminder] C:\Acer\AcerTour\Reminder.exe
          O4 - HKLM\..\Run: [PlayMovie] "C:\Program Files\Acer Arcade Live\Acer PlayMovie\PMVService.exe"
          O4 - HKLM\..\Run: [SystrayORAHSS] "C:\Program Files\OrangeHSS\Systray\SystrayApp.exe"
          O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
          O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
          O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
          O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
          O4 - HKLM\..\Run: [Skytel] Skytel.exe
          O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
          O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
          O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
          O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
          O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
          O4 - HKLM\..\Run: [hpqSRMon] C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe
          O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
          O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
          O4 - HKCU\..\Run: [Acer Tour Reminder] C:\Acer\AcerTour\Reminder.exe
          O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
          O4 - HKCU\..\Run: [tmobd] C:\Users\Maxime\AppData\Roaming\tmobd.exe
          O4 - HKCU\..\Run: [ssf] C:\Users\Maxime\AppData\Roaming\finalssf\fssf.exe
          O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
          O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
          O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
          O4 - HKCU\..\Run: [uiako] "c:\users\maxime\appdata\local\uiako.exe" uiako
          O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
          O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
          O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
          O4 - Startup: OpenOffice.org 3.0.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe
          O4 - Global Startup: Empowering Technology Launcher.lnk = ?
          O4 - Global Startup: E_SPSU01.lnk = C:\Windows\System32\spool\drivers\w32x86\3\E_SPSU01.EXE
          O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
          O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
          O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
          O9 - Extra button: Sélection intelligente HP - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
          O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
          O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
          O13 - Gopher Prefix:
          O16 - DPF: {2250C29C-C5E9-4F55-BE4E-01E45A40FCF1} (CMediaMix Object) - http://musicmix.messenger.msn.com/Medialogic.CAB
          O16 - DPF: {9122D757-5A4F-4768-82C5-B4171D8556A7} (PhotoPickConvert Class) - http://appdirectory.messenger.msn.com/AppDirectory/P4Apps/PhotoSwap/PhtPkMSN.cab
          O16 - DPF: {A1F2F2CE-06AF-483C-9F12-D3BAA72477D6} (BatchDownloader Class) - http://appdirectory.messenger.msn.com/AppDirectory/P4Apps/PhotoSwap/DigWXMSN.cab
          O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
          O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
          O23 - Service: Acer HomeMedia Connect Service - CyberLink - C:\Program Files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\CLMSServer.exe
          O23 - Service: ePerformance Service (AcerMemUsageCheckService) - Unknown owner - C:\Acer\Empowering Technology\ePerformance\MemCheck.exe
          O23 - Service: Avira AntiVir Personal – Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
          O23 - Service: Avira AntiVir Personal – Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
          O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
          O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
          O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
          O23 - Service: eDSService.exe (eDataSecurity Service) - HiTRSUT - C:\Acer\Empowering Technology\eDataSecurity\eDSService.exe
          O23 - Service: eRecovery Service (eRecoveryService) - Acer Inc. - C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
          O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom SA - C:\PROGRA~1\COMMON~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
          O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
          O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
          O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
          O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
          1. Pas de soucis Gen ! à Toute ;)

            Et au fait, si il y a d'autres choses anormalessignalez le ! :D
            1. bonjour :

              Télécharge UsbFix (de Chiquitine29) sur ton Bureau :
              http://sd-1.archive-host.com/membres/up/116615172019703188/UsbFix.exe

              --> Lance l'installation avec les paramètres par défaut.

              --> Branche tes sources de données externes à ton PC (clé USB, disque dur externe, etc...) sans les ouvrir.

              --> Double-clique sur le raccourci UsbFix sur ton Bureau. choisis nettoyage

              --> Le PC va redémarrer.

              --> Après redémarrage, poste le rapport UsbFix.txt

              Note : le rapport UsbFix.txt est sauvegardé à la racine du disque.

              (Si le Bureau ne réapparait pas, presse Ctrl+Alt+Suppr, Onglet "Fichier", "Nouvelle tâche", tape explorer.exe et valide)
              1. Okaii'
                Il y a rien de spcécial dans ces rapports !?
                Rien d'anormal ?
                1. Okaii' Jfais ca jte donne tout de suite !
                  Mais quand tu dis à la racine du disque C'est ou que je dois aller chercher le rapport ?

                  Pourrais tu me dire les lgines qui sont bizarres pour que j'aprenne en même temps à detecter tout ca ... ?
                  1. [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{03ac2419-d1b7-11dd-89b1-001d926a1f57}]
                    shell\AutoRun\command - zcouwz.exe
                    shell\explore\command - zcouwz.exe
                    shell\open\command - zcouwz.exe


                    ceci est ennuyeux
                    1. 01/05/2009 18:55:39 Program Start
                      01/05/2009 18:55:39 Process hpwuSchd2.exe was found and terminated. Result = 1

                      01/05/2009 18:55:39 Process HPWUCli.exe was found and terminated. Result = 1

                      01/05/2009 18:55:39 Process HpuFunction.dll was found and terminated. Result = 1
                      01/05/2009 18:55:39 SetNameSecruityInfo on C:\Program Files\HP\HP Software Update\ returned 5

                      01/05/2009 18:55:39 Program exited with 5
                      01/05/2009 18:55:49 Program Start
                      01/05/2009 18:55:49 SetNameSecruityInfo on C:\Program Files\HP\HP Software Update\ returned 0

                      01/05/2009 18:55:49 Program exited with 0

                      C ca ?
                      1. Est ce que c'est ca ?

                        Changelog UsbFix établit le 2 decembre 2008
                        outils créé par Chiquitine29 , aide aux mises a jours -> Chimay8

                        >>>>>>in "ProgramFiles"<<<<<<<<<

                        Internet Explorer\Connection Wizard\icwconn1\rada
                        Internet Explorer\Connection Wizard\icwconn1\rade
                        Internet Explorer\Connection Wizard\icwconn1\radf
                        Internet Explorer\Connection Wizard\icwconn1\rad5
                        Internet Explorer\Connection Wizard\icwconn1\rad0
                        Internet Explorer\Connection Wizard\icwconn1\rad9
                        Internet Explorer\Connection Wizard\icwconn1\rad4
                        Internet Explorer\Connection Wizard\icwconn1\rad1
                        Internet Explorer\Connection Wizard\icwconn1
                        Movie Maker\explorer.exe
                        Internet Explorer\explorer.exe

                        >>>>>>in "Windows"<<<<<<<<<

                        autorun.inf
                        autorun.exe
                        autorun.vbs
                        autorun.reg
                        autorun.ini
                        autorun.fcb
                        autorun.bat
                        autorun.com
                        AdobeR.exe
                        Alecks.vbs
                        bittorrent.exe
                        cmd32.exe
                        CwbRmDir.bat
                        Fonts\Fonts.exe
                        FS6519.dll.vbs
                        funny.exe
                        GMOGLFEO.exe
                        hiqalowo.inf
                        icapy.scr
                        ilezyvu.bin
                        Lany.vbs
                        lumy.exe
                        manulopa.reg
                        MS32DLL.dll.vbs
                        MyMP3.vbs
                        nar.vbs
                        osok.inf
                        osotilasiq.pif
                        oxafa.com
                        qobo.dat
                        rundll32.vbe
                        sleep.vbe
                        SysRes.vbs
                        takice.lib
                        tusoha.exe
                        unahafiwik.exe
                        waol.exe
                        waziqepehi.ban
                        WillPolo.vbs
                        Win32DLL.vbs
                        win.vbe
                        window.exe
                        wyzeha.com
                        xcopy.exe
                        yjilu.inf
                        ylacupyb.dll

                        RECYCLER\systems.com

                        temp\039.tmp

                        >>>>>>in "Windows\system32"<<<<<<<<<

                        agucuri.vbs
                        ahr.exe
                        Alecks.vbs
                        antinul.vbe
                        amvo.exe
                        amvo0.dll
                        amvo1.dll
                        amvo2.dll
                        autorun.bat
                        Autorun.com
                        autorun.exe
                        autorun.fcb
                        autorun.inf
                        autorun.ini
                        autorun.reg
                        autorun.vbs
                        Autoruns.exe
                        avpo.exe
                        avpo0.dll
                        avpo1.dll
                        Bitkvo.exe
                        Bitkv0.dll
                        Bitkv1.dll
                        cftmonn.exe
                        Christina.jpg
                        Christina.vbs
                        ckvo.exe
                        ckvo0.dll
                        ckvo1.dll
                        ckvo2.dll
                        cradle_of_filth.vbe
                        delself.bat
                        FS6519.dll.vbs
                        GMOGLFEO.exe
                        icf.exe.exe
                        ie.exe
                        jvvo.exe
                        jvvo0.dll
                        jvvo1.dll
                        jvvo2.dll
                        jvvo3.dll
                        j3ewro.exe
                        jwedsfdo0.dll
                        jwedsfdo1.dll
                        jwedsfdo2.dll
                        jwedsfdo3.dll
                        jxnraqjxg.exe
                        kavo.exe
                        kamsoft.exe
                        kav0.dll
                        kav1.dll
                        kav2.dll
                        kav3.dll
                        kavo0.dll
                        kavo1.dll
                        kavo2.dll
                        kavo3.dll
                        kdkfm.exe
                        KEYBOARD.exe
                        keygen.exe
                        kulitut.bat
                        kulitut.vbs
                        kxvo.exe
                        kxvo0.dll
                        kxvo1.dll
                        kxvo2.dll
                        kxvo3.dll
                        lExplore.exe
                        loader.exe
                        logoneui.exe
                        LOVE-LETTER-FOR-YOU.HTM
                        LOVE-LETTER-FOR-YOU.TXT.vbs
                        msfun80.exe
                        msime82.exe
                        MSKernel32.vbs
                        ne0kS.dll.wsf
                        ne0kS.exe
                        OeApi.vbs
                        pubnet.vbs
                        rs32net.exe
                        SemiAntiVirus.vbs
                        Sexy Girls.scr
                        SpiderH.bmp
                        SpiderH.jpeg
                        SpiderH.vbs
                        sys.vbs
                        Syso.vbs
                        SysRes.vbs
                        syx.exe
                        taso.exe
                        tavo.exe
                        tavo0.dll
                        tavo1.dll
                        tavo2.dll
                        tavo3.dll
                        temp1.exe
                        temp2.exe
                        temp?.exe
                        text.txt
                        Ecran.exe
                        THe Girls
                        tmp.reg
                        tmp.txt
                        t.txt
                        vb@dock.vbs
                        vl@dock.vbs
                        Win32.vbs
                        winudp64.exe

                        dllcache\Default.exe

                        >>>>>>in "Windows\system32\drivers"<<<<<<<<<

                        ._Sanaa style-1 les formes.exe
                        0hct8ybw.exe
                        1ere partie du projet modifier.exe
                        abdelali lahrach.exe
                        Analyse transactionnelle.exe
                        AutoRun.exe
                        Bernoulli01215.exe"
                        Cahiers français Quels modes de financement pour les entreprises - La Documentation française.exe
                        Copie de Devoir I.exe
                        e-ticket Juba Paris.exe
                        fdfp2.exe
                        fihi ghizlane Rapport de stage.exe
                        graphic.exe
                        intel.exe
                        isew32.exe
                        kheireddine.exe
                        le_cadeau_du_sud(1).exe
                        LEADERSHIP SKILLS FINAL.exe
                        lettre de motivation.exe
                        MSDS.exe
                        Note.exe
                        PREMIER CHAPITRE modifié.exe
                        Raila Odinga.exe
                        Rapport NADIA.exe
                        spectro_masse1.exe
                        td de reacteur.exe
                        these-223.exe
                        xyw9tmdj.exe

                        >>>>>>in "Documents and Settings"<<<<<<<<<

                        tazebama.dl_
                        hook.dl_

                        >>>>>>in "appdata"<<<<<<<<<

                        fetomiv.vbs
                        gumugy.vbs
                        jicapikase.vbs
                        mobyhikaja.vbs
                        nebohozi.com
                        orimuwy.exe
                        sidymyvig.vbs
                        tazebama\tazebama.log
                        tazebama\zPharaoh.dat
                        tazebama

                        >>>>>>in "Temp files"<<<<<<<<<

                        1.reg
                        2.dll
                        6257890.exe
                        fq9.dll
                        help.exe
                        help1.rar
                        inst.exe
                        system.dll
                        w2e.sys
                        winhqqo.exe
                        wintoift.exe
                        xhjb.dll
                        xxx6042.exe
                        zb5ok.dll

                        >>>>>>in "All Drives"<<<<<<<<<

                        ._autorun.inf
                        autorun.inf
                        autorun.ini
                        autorun.reg
                        autorun.bat
                        autorun.vbs
                        autorun2.inf
                        autosys.exe
                        00hoeav.com
                        096.bat
                        0gjn3yw.exe
                        0qx0sc6.bat
                        0tmhoc.cmd
                        0u.cmd
                        0w.com
                        0wk2.cmd
                        108i.cmd
                        1aq1obb.bat
                        1bbvq96y.com
                        1dg.exe
                        1i.com
                        1nkbd8h.bat
                        1rfw8hjr.com
                        1u0o8bnq.cmd
                        1weicxa.com
                        1XXEC.exe
                        22xo.exe
                        2ifetri.cmd
                        2y8la.exe
                        30ed3.exe
                        33gmhso.bat
                        39lpji.com
                        3o.exe
                        3wcxx91.cmd
                        3xXx31.exe
                        4vzjaw3o.sys
                        62oop0ak.bat
                        68.exe
                        6tkoyhx.cmd
                        6x8be16.cmd
                        8e9gmih.bat
                        8ng8w.com
                        93vx0c.com
                        9yqusig.bat
                        22wcb21o.exe
                        31n3b2h.exe
                        39lpji.com
                        80avp08.com
                        82r9.cmd
                        83fgj.com
                        83l3v.cmd
                        8df.exe >
                        8h3hh3m.exe
                        8tss2gwq.bat
                        90imhpnc.exe
                        92j11sm.com
                        9es.com
                        a1.bat
                        a9.com
                        abk.bat
                        activexdebugger32.exe
                        Administrateur_Fichiers.exe
                        admp.exe
                        adobeR.exe
                        Akon.exe
                        Alecks.vbs
                        antihost.exe
                        antinul.vbe
                        aoutfq.exe
                        ar.exe
                        Atisetup.exe
                        auto.exe
                        autorum.exe
                        AutoRun\Demo.exe
                        autorun.exe
                        autorun.pif
                        autoruns.exe
                        AutoScr.exe
                        ay8p6v3.cmd
                        Ayame.exe
                        b3b9u.com
                        bicsxk03.com
                        bittorrent.exe
                        bndafai.exe
                        bo1dhu.bat
                        bobm.exe
                        boot.exe
                        bootin.exe
                        bplrl98.cmd
                        buis.exe
                        bwpncb6.com
                        bxuup9r.bat c18vk.exe
                        c9.com
                        c9hehpa.bat
                        camp.exe
                        cayfq2.cmd
                        cd8idoyl.com
                        cdr.exe
                        ceb6eu98.bat
                        cekbru.pif
                        clear.bat
                        ClickMe.exe
                        cftmonn.exe
                        cfv90h.com
                        Christina.vbs
                        cjq.exe
                        commands.txt
                        comment.htt
                        copetttt.com
                        copy.exe
                        cradle_of_filth.vbe
                        cqdis.cmd
                        cvqkuk.exe
                        d3bn0j.exe
                        ddyikr.cmd
                        delautorun.bat
                        DFD34719171.bat
                        DFD34719375.bat
                        DFD34719609.bat
                        DFD34723328.bat
                        DFD34723375.bat
                        DFD34723781.bat
                        DFD34724390.bat
                        DFD34719609.bat
                        DFD34724531.bat
                        DFD34724656.bat
                        DFD34725125.bat
                        DFD34725218.bat
                        DFD34726312.bat
                        DFD34724390.bat
                        DFD34726328.bat
                        DFD34729609.bat
                        DFD34730531.bat
                        DFD34730937.bat
                        DFD34734937.bat
                        DFD34739859.bat
                        DFD34741421.bat
                        DFD34741734.bat
                        DFD34741843.bat
                        DFD*.bat
                        dhv2u8.cmd
                        DPFMate.exe
                        dstart.exe
                        dtqlv.exe
                        dynrn6e.cmd
                        e898.com
                        e9ehn1m8.com
                        eb9ehyh.exe
                        Ecran.exe
                        ek.com
                        ekf6dbg0.com
                        ekugb3.bat
                        erdeIect.com
                        esta ig.vbs
                        ev60a2.cmd
                        explorer.exe
                        exqmmle.exe
                        f0.cmd
                        f2ir.com
                        fe.bat
                        ffojc.com
                        fi.cmd
                        FLIPART.EXE
                        folder.exe
                        Folder.htt
                        fooool.exe
                        Form5.exe
                        forSV.exe
                        FS6519.dll.vbs
                        fucker.vbs
                        fun.xls.exe
                        g2p3s.exe
                        g2pfnid.com
                        g83816.com
                        gdmae.bmp
                        Ghost.pif
                        gkyzcijfb.exe
                        GMOGLFEO.exe
                        gqsk.bat
                        graphic.exe
                        gsxlexd.cmd
                        gxlxknou.exe
                        gy.cmd
                        h0s2.bat h2.com
                        hfhludy.exe
                        hgu.bat
                        hni.cmd
                        host.exe
                        hsomklg.exe
                        hxt9.bat
                        i0.cmd
                        i8.cmd
                        ie.exe
                        igxv.cmd
                        ij.bat
                        ilpg9ejd.com
                        info.exe
                        infrom.exe
                        ino6.com
                        install.exe
                        intel.exe
                        intro.exe
                        ipy.cmd
                        iq0ecwcj.cmd
                        lsass.exe
                        itsduel.exe
                        iwjj.com
                        j4c8t8b5l3a6.exe
                        j8q8d.cmd
                        jbfqv8j.cmd
                        jdhc2x2.com
                        jdwx.exe
                        jfjsipw.exe
                        jfvkcsy.bat
                        jiwsxh39.exe
                        JJJ.exe
                        Jojo.exe
                        jwwgtuh.exe
                        jxnraqjxg.exe
                        jxpiinstall.exe
                        k6wkwon2.exe
                        ka1nk.bat
                        kaq86asx.bat
                        kayira.bat
                        kbqbptn.exe
                        kdkfm.exe
                        kdy.cmd
                        kfmyoc.pif
                        khbph.exe
                        killVBS.vbs
                        kk3.bat
                        KM.exe
                        kmd.exe
                        kn6jhgc.cmd
                        kqnns.exe
                        kqsr.exe
                        krg62.cmd
                        kulitut.bat
                        kulitut.vbs
                        kxax.cmd
                        l2f.cmd
                        l9dwu8.bat
                        lExplore.exe
                        lgcadwx.bat
                        lgrncie.bat
                        lky.exe
                        ln9.exe
                        lo.exe
                        loader.exe
                        logoneui.exe
                        Long.exe
                        LOVE.PIF
                        ltljrg.exe
                        lumy.exe
                        lurjlnps.exe
                        lvxvo1xg.cmd
                        m1t8ta.com
                        m9j.com
                        mail.exe
                        manulopa.reg
                        mcxa.exe
                        Menu.exe
                        mgjpcfdg.cm
                        mnl6on3.com
                        mp.bat
                        mp.cmd
                        mp.com
                        Movie1.exe
                        mrsne.bat
                        MS-DOS.com
                        MS32DLL.dll.vbs
                        MSd040.vbs
                        MSdC64.vbs
                        MSdFB7.vbs
                        MSd141.vbs
                        MSd191.vbs
                        MSd49A.vbs
                        MSdE78.vbs
                        MSd*.vbs
                        mshta.exe
                        MSKernel32.vbs
                        muniu.exe
                        MyMP3.vbs
                        n1detect.com
                        n2de.cmd
                        n6j.com
                        n6j6pc0.com
                        n6t1h.cmd
                        nansy ajram.vbs
                        nar.vbs
                        ne0kS.exe
                        nemesis.exe
                        nemesis.inf
                        nfdmg.com
                        nideiect.com
                        niu.exe
                        njibyekk.com
                        nl.com
                        nncu6kk.com
                        NoLimit.exe
                        np.exe
                        nq0cq.cmd
                        nqvarn.pif
                        nriljal.exe
                        ntde1ect.com
                        ntdelect.com
                        nq.bat
                        nq0cq.cmd
                        nqgcd.com
                        nsv.bat
                        nw0t1l0d.exe
                        o2yf0w.bat
                        o9o2u.bat
                        o6opnro.bat
                        OeApi.vbs
                        oegbi.exe
                        ogcikeq.com
                        oka3yrf.bat
                        oq.cmd
                        oskkofa.exe
                        osotilasiq.pif
                        osy3.sys
                        otyh.cmd
                        oufddh.exe
                        oxafa.com
                        p3r1ud.exe
                        p83gjy.exe
                        p9.exe
                        pa39xth.cmd
                        pagefile.pif
                        pbwkwj.com
                        pefbutr.exe
                        pkxfkrki.bat
                        ph.com
                        phgr1j.bat
                        phim_nguoi_lon.exe
                        pnc.exe
                        prhyper.exe
                        psqrhqn.exe
                        pxka.exe
                        q3v.com
                        q83iwmgf.bat
                        q8sywiva.cmd
                        qcwpung.exe
                        qd.cmd
                        qjfl.exe
                        qkarc.exe
                        qquq.bat
                        qqzjnhuoi.exe
                        qpe6.com
                        qobo.dat
                        qrkugxtw.exe
                        qxbx9blb.com
                        r1y1.bat
                        r2nl.com
                        r6r.exe
                        r813.bat
                        Raila Odinga.exe
                        Raila Odinga.gif
                        ranvrgn.exe
                        ravmon.exe
                        ravmon.log
                        ReadMe.exe
                        RecInfo\RecInfo.exe
                        Recycle.exe
                        Recycled\ctfmon.exe
                        RECYCLED\INFO.exe
                        Recycled.exe
                        RECYCLER\Lock Folder.exe
                        RECYCLER\RECYCLER.exe
                        RECYCLER\*.exe
                        regxpcom.exe
                        resycled\boot.com
                        resycled\ctfmon.exe
                        revo.exe
                        rggbw.exe
                        rjiybg.exe
                        rn.exe
                        rombkaewl.exe
                        rosftpm.exe
                        rqq2v.bat
                        rs.cmd
                        rt.exe
                        Run.exe
                        runaut~1\autorun.pif
                        RunDll32.exe
                        rxukgcm.exe
                        s38k.exe
                        sal.xls.exe
                        sasyg1y8.com
                        script.bat
                        scriptlo.txt
                        scvhosts.exe
                        sdcvhost.exe
                        SemiAntiVirus.vbs
                        smkjd.cmd
                        smss.exe
                        semo2x.exe
                        spq.bat
                        serivces.exe
                        server.exe
                        server.inf
                        Sex City.jpg.wsf
                        sowar.vbs
                        SpiderH.vbs
                        sq.com
                        sqlserv.exe
                        SSVICHOSST.exe
                        stwi.com
                        svch0st.exe
                        scvhosts.exe
                        svdioajm.cmd
                        sxs.exe
                        sydp.exe
                        sys.vbs
                        Syso.vbs
                        SysRes.vbs
                        system.exe
                        system32.exe
                        systems.com
                        systems.exe
                        t82e2v.cmd
                        TAE7ESLP.exe
                        taipingtianguov1.1.exe
                        takice.lib
                        tel.xls.exe
                        temp.bat
                        temp.exe
                        temp.temp
                        temp1.exe
                        temp2.exe
                        test.exe
                        testfile.bat
                        testflo.bat
                        tfk8.exe
                        The_Cars.vbs
                        THe Girls
                        tknapl.exe
                        tknn6.bat
                        tmf3w3g0.com
                        TMMDW8LP.exe
                        Toy.exe
                        tusoha.exe
                        tyktjfww.exe
                        u18vxqle.com
                        u6k.cmd
                        u9dyi.exe
                        udnnnvq.exe
                        UFO.exe
                        ufuaugwq.exe
                        uis.com
                        uis.exe
                        um.cmd
                        un9.cmd
                        unahafiwik.exe
                        UnplugDrive.exe
                        uorys.cmd
                        update.exe
                        uqhqx1.cmd
                        usdeiect.com
                        userinit.exe
                        utdetect.com
                        uxdeiect.com
                        u?de?ect.com
                        v2h3.exe
                        v3pif.bat
                        VB6FR.DLL
                        vb@dock.vbs
                        vfpkkbq.exe
                        vksucydrh.exe
                        vl@dock.vbs
                        vmhr.bat
                        vmyphd.bat
                        vva0hc0p.cmd
                        vxl.exe
                        w0o.com
                        w0owgn.bat
                        w32sys.exe
                        w3dn9f.bat
                        waziqepehi.ban
                        wa6.vbs
                        Wallpaper.vbs
                        WallpaperMEHDI.vbs
                        wfhth.exe
                        whi.com
                        WillPolo.vbs
                        WINDOWS.EXE
                        Windows.scr
                        winfile.exe
                        winglogon.exe
                        winrun.vbs
                        winstall.exe
                        wjlfhtfm.cmd
                        wol.exe
                        wsctf.exe
                        wtbcccq.exe
                        x0.cmd
                        XAdeIect.com
                        xcopy.exe
                        xfoolavp.com
                        xih9.cmd
                        xj.bat
                        xk2n.bat
                        xlk9.com
                        xlu8a8sy.exe
                        xmnm2.cmd
                        xn1i9x.com
                        xnynrnh.exe
                        xo8wr9.exe
                        xp19.com
                        xpbkh.com
                        xqf.com
                        xvlyb.exe
                        xyhav.pif
                        y82td3td.com
                        ybj8df.exe
                        yew.bat
                        yg.cmd
                        yjilu.inf
                        ylacupyb.dl
                        ylr.exe
                        yjkjfuo.cmd
                        yjvmtaa.exe
                        ynfs9ks.cmd
                        yssjnngm.cmd
                        yvmkdwn.exe
                        zPharaoh.exe
                        0.cmd
                        1.cmd
                        2.cmd
                        3.cmd
                        4.cmd
                        5.cmd
                        6.cmd
                        7.cmd
                        8.cmd
                        9.cmd
                        0.bat
                        1.bat
                        2.bat
                        3.bat
                        4.bat
                        5.bat
                        6.bat
                        7.bat
                        8.bat
                        9.bat
                        0.exe
                        1.exe
                        2.exe
                        3.exe
                        4.exe
                        5.exe
                        6.exe
                        7.exe
                        8.exe
                        9.exe
                        0.com
                        1.com
                        2.com
                        3.com
                        4.com
                        5.com
                        6.com
                        7.com
                        8.com
                        9.com
                        0.vbs
                        1.vbs
                        2.vbs
                        3.vbs
                        4.vbs
                        5.vbs
                        6.vbs
                        7.vbs
                        8.vbs
                        9.vbs
                        a.com
                        b.com
                        c.com
                        d.com
                        e.com
                        f.com
                        g.com
                        h.com
                        i.com
                        j.com
                        k.com
                        l.com
                        m.com
                        n.com
                        o.com
                        p.com
                        q.com
                        r.com
                        s.com
                        t.com
                        u.com
                        v.com
                        w.com
                        x.com
                        y.com
                        z.com
                        a.bat
                        b.bat
                        c.bat
                        d.bat
                        e.bat
                        f.bat
                        g.bat
                        h.bat
                        i.bat
                        j.bat
                        k.bat
                        l.bat
                        m.bat
                        n.bat
                        o.bat
                        p.bat
                        q.bat
                        r.bat
                        s.bat
                        t.bat
                        u.bat
                        v.bat
                        w.bat
                        x.bat
                        y.bat
                        z.bat
                        a.cmd
                        b.cmd
                        c.cmd
                        d.cmd
                        e.cmd
                        f.cmd
                        g.cmd
                        h.cmd
                        i.cmd
                        j.cmd
                        k.cmd
                        l.cmd
                        m.cmd
                        n.cmd
                        o.cmd
                        p.cmd
                        q.cmd
                        r.cmd
                        s.cmd
                        t.cmd
                        u.cmd
                        v.cmd
                        w.cmd
                        x.cmd
                        y.cmd
                        z.cmd
                        a.exe
                        b.exe
                        c.exe
                        d.exe
                        e.exe
                        f.exe
                        g.exe
                        h.exe
                        i.exe
                        j.exe
                        k.exe
                        l.exe
                        m.exe
                        n.exe
                        o.exe
                        p.exe
                        q.exe
                        r.exe
                        s.exe
                        t.exe
                        u.exe
                        v.exe
                        w.exe
                        x.exe
                        y.exe
                        z.exe
                        a.vbs
                        b.vbs
                        c.vbs
                        d.vbs
                        e.vbs
                        f.vbs
                        g.vbs
                        h.vbs
                        i.vbs
                        j.vbs
                        k.vbs
                        l.vbs
                        m.vbs
                        n.vbs
                        o.vbs
                        p.vbs
                        q.vbs
                        r.vbs
                        s.vbs
                        t.vbs
                        u.vbs
                        v.vbs
                        w.vbs
                        x.vbs
                        y.vbs
                        z.vbs
                        *.dll.vbs

                        >>Dossiers :

                        AutoRun
                        autorun.inf
                        fsc.tmp
                        RecInfo
                        Recycled\Recycled
                        Recycler\Recycler
                        resycled
                        runaut~1
                        sdlflzoip

                        >>>>>>"Registry"<<<<<<<<<

                        [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
                        "Window Title"=-
                        "Start Page"=-
                        "Start Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome"
                        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\MAIN]
                        "Start Page"="https://www.msn.com/fr-fr"

                        [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
                        "fucker"=-
                        "SysDir"=-
                        "ms32dll"=-
                        "cftmonn"=-
                        "Lany"=-
                        "Zip"=-
                        "RavAV"=-
                        "cmd32"=-
                        "Install.exe"=-
                        "FIXEDFON.FON"=-
                        "MS-RAD0"=-
                        "MS-RAD1"=-
                        "MS-RAD2"=-
                        "MS-RAD3"=-
                        "MS-RAD4"=-
                        "MS-RAD5"=-
                        "MS-RAD6"=-
                        "MS-RAD7"=-
                        "MS-RAD8"=-
                        "MS-RAD9"=-
                        "MS-RADA"=-
                        "MS-RADB"=-
                        "MS-RADC"=-
                        "MS-RADD"=-
                        "MS-RADE"=-
                        "MS-RADF"=-
                        "MS-RADG"=-
                        "MS-RADH"=-
                        "MS-RADI"=-
                        "MS-RADJ"=-
                        "MS-RADK"=-
                        "MS-RADL"=-
                        "MS-RADM"=-
                        "MS-RADN"=-
                        "MS-RADO"=-
                        "MS-RADP"=-
                        "MS-RADQ"=-
                        "MS-RADR"=-
                        "MS-RADS"=-
                        "MS-RADT"=-
                        "MS-RADU"=-
                        "MS-RADV"=-
                        "MS-RADW"=-
                        "MS-RADX"=-
                        "MS-RADY"=-
                        "MS-RADZ"=-
                        " "=-
                        "winrun.dll"=-
                        "loader.exe"=-
                        "recinfo49"=-
                        "System"=-
                        "System Updater Machine"=-
                        "SpiderH"=-
                        "winudp64.exe"=-
                        "System12"=-
                        "System64"=-
                        "IMJPMIG8.2"=-
                        "CARPService"=-
                        "039.tmp"=-
                        "userd"=-
                        "nar"=-
                        "MSKernel32"=-
                        "WillPolo"=-
                        "MyMP3"=-
                        "FS6519"=-
                        "Windows\SysRes.vbs"=-
                        "SysRes"=-
                        "Raila Odinga"=-
                        "reginit"=-
                        "lnternet Update"=-
                        "GMOGLFEO"=-
                        "WintelUpdate"=-
                        "Pubnet"=-
                        "antihost"=-

                        [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices]
                        "System Updater Machine"=-
                        "Win32DLL"=-
                        "lnternet Update"=-

                        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
                        " "=-

                        [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RavAV]

                        [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                        "kamsoft"=-
                        "amva"=-
                        "kava"=-
                        "tava"=-
                        "avpa"=-
                        "internet_explorer"=-
                        "anti-virus 2007"=-
                        "Mp3 player"=-
                        "kxvo"=-
                        "EXPLORER.EXE"=-
                        "wsctf.exe"=-
                        "loader.exe"=-
                        "jvvo"=-
                        "taso"=-
                        "Avg_AntiHost"=-
                        "jvsoft"=-
                        "tasoft"=-
                        "SpiderH"=-
                        "MsServer"=-
                        "MSFox"=-
                        "msn"=-
                        "????r"=-
                        "Windows Update"=-
                        "Microsoft Debug Manager"=-
                        "protect_autorun"=-
                        "Le Petit Robert Hyperappel"=-
                        "firewall 2008"=-
                        " "=-

                        [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce]
                        " "=-

                        [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
                        "test"=-
                        "Msn"=-
                        "MsnHost"=-
                        "MsnLoad"=-
                        "MsnConvert"=-
                        "MsnMessendger"=-
                        "sys"=-

                        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
                        "DefaultUserName"=-
                        "LegalNoticeCaption"=-
                        "LegalNoticeText"=-

                        [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ActiveDesktop\NoChangingWallPaper]

                        -------------------------------------------------------------------------------------------------------------

                        Mises a jours du 5 decembre 2008

                        >>>>>>in "All Drives"<<<<<<<<<

                        6xdgw26.com
                        6xig.com
                        8386nac.com
                        8e.com
                        8u.com
                        8uot.exe
                        arun.exe
                        asneg.com
                        bpu.exe
                        br1e.com
                        cdwfql2v.com
                        ceqfqp.bat
                        cm0.com
                        d1y36.com
                        dh66ln.cmd
                        dpu1.exe
                        dyr2j6mv.exe
                        ermvu8.cmd
                        fblfnthuh.exe
                        fn20.exe
                        fufb6tq3.cmd
                        g2o1n.exe
                        gx.com h3hi1k3.exe
                        i8.com
                        ivcvknr.bat
                        jv.exe
                        kernel32.dll.vbs
                        kg2v.com
                        klp8j6i.com
                        ktnquo.exe
                        l1.cmd
                        lp3c.bat
                        m0g8sqx.cmd
                        m6dqm2vd.exe
                        m8wafly.com
                        m9as2c.cmd
                        MicrosoftPowerPoint.exe
                        MSd30D.vbs
                        msnmsgr_plus.exe
                        ncyrf.bat
                        ntdeIect.com
                        ntnq.exe
                        ntphyy.com
                        NTsys.exe
                        o6pq1n8.com
                        okhr.exe
                        ous.exe
                        ox.cmd
                        p1f6b.exe
                        program.exe
                        qeoc6sj.exe
                        qwultj1.bat
                        rcukd.cmd
                        rdsfk.com
                        rjx0.exe
                        rqb0v2ot.bat
                        scene.exe
                        Server082.exe
                        tigi.cmd
                        uh31.exe
                        uwlmj.com
                        uxkktr.cmd
                        vd91t29.exe
                        w2qagd.com
                        welcome.exe
                        WindowsXP.exe
                        winsys3.exe
                        ypjq1.cmd

                        .MGT_reg32.dll.vbs
                        achitasin.dll.vbs
                        autoupdate.dll.vbs
                        bat32.txt
                        happy.vbs
                        ie.vbs
                        killgodzilla.vbs
                        maskrider.dll.vbs
                        maskrider2001.vbs
                        msiexec.dll.vbs
                        MsUpdate.sys.vbs
                        nohack.vbs
                        RUNDLL64.dll.vbs
                        setup.dll.vbs
                        VBRuntime32.dll.vbs
                        viva.dll.vbs
                        Win32.dll.vbs
                        winconfig.dll.vbs
                        xepet.html
                        xepet.txt

                        >>>>>>in "Windows"<<<<<<<<<

                        .MGT_reg32.dll.vbs
                        achitasin.dll.vbs
                        autoupdate.dll.vbs
                        bat32.txt
                        boot.ini
                        happy.vbs
                        ie.vbs
                        killgodzilla.vbs
                        maskrider.dll.vbs
                        maskrider2001.vbs
                        msiexec.dll.vbs
                        MsUpdate.sys.vbs
                        nohack.vbs
                        RUNDLL64.dll.vbs
                        setup.dll.vbs
                        VBRuntime32.dll.vbs
                        viva.dll.vbs
                        Win32.dll.vbs
                        winconfig.dll.vbs
                        xepet.html
                        xepet.txt

                        >>>>>>in "Windows\system32"<<<<<<<<<

                        kdyul.exe
                        gasretyw0.dll
                        gasretyw1.dll
                        gasretyw2.dll
                        gasretyw3.dll
                        DC4491.DLL

                        >>>>>>"Registry"<<<<<<<<<

                        [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                        "Winboot"=-

                        [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
                        "UC"=-
                        "r4n694-24y"=-
                        "kernel32"=-
                        "MSConfigs"=-
                        "Microsoft"=-
                        "MGT_reg"=-
                        "Winboot"=-
                        "Winamp"=-
                        "Macromedia"=-
                        "WINFIX"=-
                        "winconfig"=-
                        "Achitasin"=-
                        "mcafee"=-
                        "wscript32dll"=-
                        "Batch32"=-
                        "maskrider"=-
                        "autoupdate"=-
                        "KILLMS32DLL"=-
                        "WinExpress"=-
                        "WinDebugger"=-
                        "C:\WINDOWS\system32\kdyul.exe"=-

                        mises a jours du 6 Décembre 2008

                        >>>>>>in "All Drives"<<<<<<<<<

                        lgrncie.bat
                        info.bat
                        iqosrtk.bat
                        0oyl662q.cmd
                        eb.bat
                        New Folder.exe
                        Setup_ver1.1779.2.exe
                        Setup_ver*.exe

                        >>>>>>in "Windows"<<<<<<<<<

                        SSVICHOSST.exe

                        >>>>>>in "Windows\system32"<<<<<<<<<

                        SSVICHOSST.exe
                        kdxkt.exe
                        kdjay.exe
                        kdwzh.exe
                        msiconf.exe

                        >>>>>>"Registry"<<<<<<<<<

                        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\run]
                        "MsUpdate"=-
                        "C:\WINDOWS\system32\kdxkt.exe"=-
                        "C:\WINDOWS\system32\kdjay.exe"=-
                        "C:\WINDOWS\system32\kdwzh.exe"=-

                        [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\run]
                        "msiexec.exe"=-
                        "Yahoo Messengger"=-

                        mises a jours du 11 Décembre 2008

                        >>>>>>in "All Drives"<<<<<<<<<

                        Secret.exe
                        hupxj.bat
                        fphj6j31.bat
                        shell.exe
                        Installer.exe
                        fvbk.exe
                        snaoc9i.exe
                        bt8vuaw.com
                        wjlc.exe
                        6fnlpetp.exe
                        g8rruyw.exe
                        o1.com
                        yannh.cmd
                        1t6yxlxx.cmd
                        2h60k.cmd
                        3rl3lqbq.bat
                        ewatr.cmd
                        Maradona.exe
                        iw.bat
                        m2nl.bat
                        ov.cmd
                        pnt.com
                        t1ypkh.exe
                        grgarevn.inf
                        microsvn.inf
                        refsanvn.inf
                        Zidan vs Tito.exe
                        desktop.exe
                        omsirutnarg.exe
                        Alisa.exe
                        blazzers.exe
                        burimi.exe
                        nfd.exe
                        repppp.exe
                        wax.exe
                        wny.exe
                        msv2008.exe
                        GETBOOTD.BAT
                        tbm9.bat
                        08dgu.com

                        >>>>>>in "Windows\system32"<<<<<<<<<

                        vamsoft.exe
                        vbsdfe0.dll
                        vbsdfe1.dll
                        vbsdfe2.dll
                        vbsdfe3.dll
                        syx.exe

                        >>>>>>"Registry"<<<<<<<<<

                        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\run]
                        "Host Process for Windows Services"=-
                        "Advanced DHTML Enable"=-

                        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\runServices]
                        "Host Process for Windows Services"=-

                        [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\run]
                        "Runonce"=-
                        "vamsoft"=-

                        mises a jours du 17 Décembre 2008

                        >>>>>>in "Windows"<<<<<<<<<

                        pagefile.sys.vbs
                        backinf.tab
                        session.exe
                        startup.vbs
                        KAT.vbs
                        explorar.vbs

                        help\destrukto.vbs
                        inf\destrukto.vbs
                        registration\destrukto.vbs

                        >>>>>>in "Windows\system32"<<<<<<<<<

                        filekan.exe
                        socksa.exe
                        KAT.vbs
                        destrukto.vbs
                        security.vbs
                        explorar.vbs
                        destrukto.html

                        >>>>>>in "Windows\system32\drivers"<<<<<<<<<

                        Memoire Jeff EYEGHE.exe

                        >>>>>>in "All Drives"<<<<<<<<<

                        .\Recycled\Driveinfo.exe
                        m9ma.exe
                        JIM.exe
                        iri.exe
                        lol.exe
                        mpsn.exe
                        pagefile.sys.vbs
                        al.xls.exe
                        MDM.EXE
                        RavManE.exe
                        iexp1ore.exe
                        msvcr71.dll
                        BSserver
                        FileKan.exe
                        ASocksrv.exe
                        algsrv.exe
                        BACKINF.TAB
                        ufdata2000.log
                        twunk32.exe
                        windhcp.ocx
                        algssl.exe
                        msfir80.exe
                        msime80.exe
                        destrukto.vbs
                        Xsfr.exe
                        Zser.exe
                        THUMBS.DB.COM
                        KAT.vbs
                        startup.vbs
                        THUMBS.DB
                        MrHelloween.scr
                        mig2.exe
                        Perso_Stress.exe
                        msfun80.exe
                        IMJPMIG8.2
                        msime82.exe
                        IMJPMIG8.1
                        algsrvs.exe
                        pr2.exe
                        sdfgh.exe
                        p1y2.cmd h3.bat
                        session.exe
                        explorar.vbs
                        security.vbs

                        >>>>>>"Registry"<<<<<<<<<

                        [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
                        "MSRegInfo"=-
                        "ASocksrv"=-
                        "Startup"=-
                        "Explorer"=-

                        [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                        "BSserver"=-

                        Mises a jours de 21 decembre 2008

                        >>>>>>"Registry"<<<<<<<<<

                        [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
                        "zakariag"=-

                        >>>>>>in "Windows"<<<<<<<<<

                        csrss.exe

                        >>>>>>in "Windows\system32"<<<<<<<<<

                        GG.bat
                        install.exe

                        >>>>>>in "All Drives"<<<<<<<<<

                        yt8a.exe
                        log.exe
                        iri.exe
                        okea.exe
                        system43.exe
                        system9.exe
                        xx.exe
                        recycled\sirc32.exe
                        iky.bat
                        GuelmimG.bat

                        Mises a jours de 23 decembre 2008

                        >>>>>>in "Windows"<<<<<<<<<

                        help.exe
                        mg.exe

                        >>>>>>in "Windows\system32"<<<<<<<<<

                        kav320.dll
                        kav321.dll
                        kav322.dll
                        mldmm.exe
                        spooIsv.exe
                        system.exe

                        >>>>>>in "Temp files"<<<<<<<<<

                        help.rar
                        nodB.tmp

                        >>>>>>in "appdata"<<<<<<<<<

                        addon.dat
                        CISxCC.tmp
                        ISxCB.tmp
                        ISx97.tmp

                        >>>>>>in "All Drives"<<<<<<<<<

                        MSd355.vbs
                        xrdygg.bat
                        MSd48F.vbs
                        bold.log
                        qthqdso.exe
                        mguvbfr.exe
                        kxhvehm.exe
                        msvsc.exe
                        2w.cmd
                        x0.com
                        u2.cmd
                        je26200.com
                        lkxcqdb.bat
                        gr06t.cmd
                        xfl3hx.exe
                        1gk8ha.bat
                        sucksa.exe

                        >>>>>>"Registry"<<<<<<<<<

                        [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices]
                        "mmsass"=-
                        [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
                        "mmsass"=-
                        "Spooler SubSystem App"=-

                        Mises a jours de 24 decembre 2008 ( Feliz Navidad )

                        >>>>>>in "Windows"<<<<<<<<<

                        system32.exe

                        >>>>>>in "Windows\system32"<<<<<<<<<

                        dse235rgd1.dll
                        kavo.exe
                        kavo0.dll
                        kavo1.dll
                        kavo2.dll
                        kavo3.dll
                        wedasgads0.dll
                        wedasgads1.dll
                        wedasgads2.dll
                        wedasgads3.dll
                        WS2Fix.exe
                        VCCLSID.exe
                        VACFix.exe
                        swxcacls.exe
                        swsc.exe
                        swreg.exe
                        SrchSTS.exe
                        Process.exe
                        o4Patch.exe
                        IEDFix.exe
                        IEDFix.C.exe
                        dumphive.exe
                        Agent.OMZ.Fix.exe
                        404Fix.exe

                        >>>>>>in "All Drives"<<<<<<<<<

                        6j2j.com
                        iok.exe
                        MSd05E.vbs
                        MSd329.vbs
                        wi.com
                        ab31.exe

                        >>>>>>"Registry"<<<<<<<<<

                        [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                        "EXPLORER.EXE"=-
                        "wsctf.exe"=-

                        Mises a jours du 27 Décembre 2008

                        >>>>>>in "Windows"<<<<<<<<<

                        admintxt.txt
                        u.bat
                        u.vbe
                        s.vbe

                        >>>>>>in "Windows\system32"<<<<<<<<<

                        temp#01.exe
                        dse235rgd0.dll
                        dse235rgd2.dll
                        dse235rgd3.dll

                        >>>>>>in "Temp files"<<<<<<<<<

                        pa.exe

                        >>>>>>in "All Drives"<<<<<<<<<

                        reps.exe
                        bud3.bat
                        sjqkci.cmd
                        hehe.exe
                        oskie.exe
                        u.vbe
                        Knight.exe
                        sss.exe
                        x6.bat
                        sokeie.exe
                        sucker.exe
                        fhrqdpi.exe
                        plugin.exe
                        s.vbe

                        >>>>>>"Registry"<<<<<<<<<

                        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                        "vbe"=-

                        Mises a jours du 09 Janvier 2009

                        >>>>>>in "Windows"<<<<<<<<<

                        wintask.exe
                        svcwroot.exe
                        smms.exe
                        inf\csrss.exe
                        inf\diskini.xp
                        smms.bat
                        k.txt

                        >>>>>>in "Windows\system32"<<<<<<<<<

                        kav323.dll
                        blastclnnn.exe
                        Bitkv2.dll
                        ahtn.htm
                        kdjpf.exe
                        kdind.exe
                        warning.gif
                        jjj.exe
                        frmwrk32.exe
                        ciuytr3.dll
                        ciuytr2.dll
                        ciuytr1.dll
                        ciuytr0.dll

                        >>>>>>in "Windows\system32\Drivers"<<<<<<<<<

                        av.exe
                        RACHIDA.exe

                        >>>>>>in "Temp files"<<<<<<<<<

                        a3a4_appcompat.txt
                        1AFC3.dmp

                        >>>>>>in "Application Data"<<<<<<<<<

                        autorun.inf
                        gadcom\gadcom.exe
                        gadcom

                        >>>>>>in "All Drives"<<<<<<<<<

                        e8kj.exe
                        vfjc8mxm.exe
                        iqe68o.bat
                        fzqxyrlpa.exe
                        Taskmgr.exe
                        FullHouse
                        Config\smss.exe
                        Kurdish.exe
                        desktop.dll

                        escro.exe
                        gdgd.exe
                        ipyrs.exe
                        spoolsn.exe
                        300y.cmd
                        cb.bat
                        riky.exe
                        VirusRemoval.vbs
                        Pagefi1e.sys
                        rox.exe
                        yhiqadw.exe
                        p2hhr.bat
                        SCVHOST.exe
                        yuqpba.exe
                        vmsavzvx.exe
                        8de.bat
                        frslsryk.exe
                        yb12j.cmd
                        xcisvxl.com
                        wqesvxa.exe
                        inqfnq.exe
                        qopitm.exe
                        sjpj.exe
                        vhmdq.exe
                        RECYCLER\Lock Folder.exe
                        1sertc.exe
                        r8.bat
                        knupkb.com

                        >>>>>>"Registry"<<<<<<<<<

                        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                        "win32dll"=-
                        "Framework Windows"=-
                        "C:\WINDOWS\system32\kdjpf.exe"=-
                        "C:\WINDOWS\system32\kdind.exe"=-
                        "wintask"=-
                        "MSN"=-
                        "zzzHPSETUP"=-
                        "I downloaded pirated Software from P2P and now I post my Hijack log whining"=-
                        "Proyecto1"=-
                        "svchost"=-

                        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
                        "autorun"=-

                        [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                        "Windows"=-
                        "Cognac"=-

                        [-HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop\NoChangingWallpaper]
                        [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\activedesktop\NoChangingWallpaper]
                        [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSetActiveDesktop]
                        [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoActiveDesktopChanges]
                        [-HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSetActiveDesktop]
                        [-HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoActiveDesktopChanges]

                        [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explore\Run]
                        "Manager Task"=-
                        • 1
                        • 2