Probleme avec generic.malware.FBdld!.E1A1C4D5

Résolu
Bonjour,

J'ai un gros soucis. Bitdefender a laisser passer le malware : generic.malware.FBdld!.E1A1C4D5
Comme je ne suis pas un brute en informatique j'ai vraiment besoin d'un coup de main. C'est mon ordianteur du boulot, et je ne peux plus rien faire, a peine puis-je vous ecrire.
J'ai essayé tout les scan possbile, j'ai toujours le même soucis!

Merci bien a tous

G.C
Configuration: Windows XP
Internet Explorer 7.0

44 réponses

Résumé de la discussion

Le sujet porte sur une détection incomplète du malware generic.malware.FBdld!.E1A1C4D5 par Bitdefender sur un PC professionnel sous Windows XP et IE7, rendant l’ordinateur inutilisable pour l'utilisateur. Des interventions proposées incluent des scans complémentaires et l’analyse de rapports Log, avec Malwarebytes et HijackThis, afin d’identifier des éléments tels que Trojan.KoobFace et Backdoor.Bot, et de nettoyer les clés et fichiers malveillants. En parallèle, certains conseils évoquent la gestion du proxy Internet (désactivation si IE ne charge plus) et l’examen de fichiers de démarrage et de paramètres réseau, afin d’empêcher la persistance du malware. Des éléments supplémentaires évoquent la désinfection par outils dédiés et le contrôle des services Windows, sans conclure sur l’état final du fil.

Bobot (l’IA à votre service)
  1. Contributeur sécurité
    slt

    tu as le rapport bitdefender a nous soumettre?

    puis

    Slt,

    scan avec malwarebyte , fais un scan rapide et colle le rapport obtenu et vire ce qui est trouvé:

    https://www.malekal.com/tutoriel-malwarebyte-anti-malware/­

    ______________________

    Télécharge ici :

    http://images.malwareremoval.com/random/RSIT.exe

    random's system information tool (RSIT) par andom/random et sauvegarde-le sur le Bureau.

    Double-clique sur RSIT.exe afin de lancer RSIT.

    Clique Continue à l'écran Disclaimer.

    Si l'outil HijackThis (version à jour) n'est pas présent ou non détecté sur l'ordinateur, RSIT le téléchargera (autorise l'accès dans ton pare-feu, si demandé) et tu devras accepter la licence.

    Lorsque l'analyse sera terminée, deux fichiers texte s'ouvriront.

    Poste le contenu de log.txt (<<qui sera affiché)
    ainsi que de info.txt (<<qui sera réduit dans la Barre des Tâches).

    NB : Les rapports sont sauvegardés dans le dossier C:\rsit
    1. Bien,

      Je poste ce que tu m'as demander le log txt d'abord

      shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL serivces.exe

      [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{1b44f90a-122a-11de-8a08-002264a40a06}]
      shell\AutoRun\command - G:\ReadMe.exe

      [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{45cb2b1f-a4db-11dd-973b-806d6172696f}]
      shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe protect.ed 480 480

      ======List of files/folders created in the last 1 months======

      2009-04-22 17:47:36 ----D---- C:\rsit
      2009-04-22 16:18:53 ----A---- C:\WINDOWS\ntbtlog.txt
      2009-04-22 15:26:11 ----A---- C:\WINDOWS\st_1240413104.exe
      2009-04-22 15:26:09 ----D---- C:\WINDOWS\system32\179223
      2009-04-22 14:55:27 ----A---- C:\WINDOWS\st_1240404967.exe
      2009-04-22 13:17:13 ----D---- C:\Documents and Settings\direction\Application Data\AVG8
      2009-04-22 13:08:37 ----D---- C:\Program Files\CCleaner
      2009-04-22 13:06:44 ----D---- C:\GenProc
      2009-04-22 11:33:53 ----D---- C:\Program Files\Trend Micro
      2009-04-21 17:23:07 ----H---- C:\WINDOWS\pp06.exe
      2009-04-21 17:23:06 ----A---- C:\WINDOWS\system32\dll32.exe
      2009-04-21 17:23:04 ----H---- C:\WINDOWS\freddy41.exe
      2009-04-21 17:23:04 ----D---- C:\WINDOWS\system32\219198
      2009-04-21 17:22:33 ----H---- C:\WINDOWS\ld08.exe
      2009-04-16 03:03:32 ----HDC---- C:\WINDOWS\$NtUninstallKB959426$
      2009-04-16 03:03:26 ----HDC---- C:\WINDOWS\$NtUninstallKB961373$
      2009-04-16 03:01:52 ----HDC---- C:\WINDOWS\$NtUninstallKB956572$
      2009-04-16 03:01:41 ----HDC---- C:\WINDOWS\$NtUninstallKB952004$
      2009-04-16 03:00:50 ----HDC---- C:\WINDOWS\$NtUninstallKB960803$
      2009-04-16 03:00:31 ----HDC---- C:\WINDOWS\$NtUninstallKB923561$
      2009-03-28 18:42:28 ----D---- C:\Sounds
      2009-03-28 18:25:34 ----D---- C:\Program Files\LG Electronics
      2009-03-28 18:23:35 ----A---- C:\WINDOWS\system32\NMSDVDXU.dll
      2009-03-28 18:23:21 ----D---- C:\Program Files\LG PC Suite II
      2009-03-28 18:23:21 ----D---- C:\Documents and Settings\direction\Application Data\LG Electronics
      2009-03-23 14:09:20 ----A---- C:\WINDOWS\system32\xinput9_1_0.dll
      2009-03-23 14:09:18 ----A---- C:\WINDOWS\system32\d3dx9_25.dll
      2009-03-23 14:08:14 ----D---- C:\Program Files\Cyanide

      ======List of files/folders modified in the last 1 months======

      2009-04-22 16:50:21 ----D---- C:\WINDOWS\Temp
      2009-04-22 16:50:21 ----D---- C:\WINDOWS\system32
      2009-04-22 16:49:38 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
      2009-04-22 16:45:56 ----D---- C:\WINDOWS
      2009-04-22 16:45:19 ----D---- C:\WINDOWS\SMINST
      2009-04-22 15:37:28 ----A---- C:\WINDOWS\BRWMARK.INI
      2009-04-22 14:55:47 ----D---- C:\WINDOWS\Prefetch
      2009-04-22 13:14:37 ----D---- C:\WINDOWS\Debug
      2009-04-22 13:08:37 ----RD---- C:\Program Files
      2009-04-22 12:39:31 ----N---- C:\WINDOWS\SchedLgU.Txt
      2009-04-21 17:30:38 ----D---- C:\WINDOWS\system32\CatRoot2
      2009-04-16 03:10:29 ----D---- C:\WINDOWS\system32\wbem
      2009-04-16 03:10:29 ----D---- C:\WINDOWS\AppPatch
      2009-04-16 03:03:36 ----HD---- C:\WINDOWS\inf
      2009-04-16 03:03:33 ----RSHD---- C:\WINDOWS\system32\dllcache
      2009-04-16 03:03:15 ----D---- C:\WINDOWS\system32\fr-FR
      2009-04-16 03:03:15 ----D---- C:\Program Files\Internet Explorer
      2009-04-16 03:03:07 ----D---- C:\WINDOWS\ie7updates
      2009-04-16 03:01:48 ----HD---- C:\WINDOWS\$hf_mig$
      2009-04-16 03:01:39 ----SHD---- C:\WINDOWS\Installer
      2009-04-16 03:01:39 ----D---- C:\Documents and Settings\All Users\Application Data\Microsoft Help
      2009-04-15 08:32:58 ----D---- C:\Documents and Settings\direction\Application Data\Spotify
      2009-04-13 11:43:55 ----SD---- C:\Documents and Settings\direction\Application Data\Microsoft
      2009-04-07 08:07:17 ----D---- C:\WINDOWS\system32\drivers
      2009-04-06 16:57:24 ----A---- C:\WINDOWS\system32\MRT.exe
      2009-03-28 18:25:34 ----HD---- C:\Program Files\InstallShield Installation Information
      2009-03-23 14:09:33 ----D---- C:\WINDOWS\WinSxS
      2009-03-23 14:09:33 ----D---- C:\Program Files\Fichiers communs\Microsoft Shared
      2009-03-23 14:09:21 ----D---- C:\WINDOWS\system32\DirectX

      ======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

      R1 bdftdif;bdftdif; \??\C:\Program Files\Fichiers communs\BitDefender\BitDefender Firewall\bdftdif.sys []
      R1 intelppm;Pilote de processeur Intel; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-13 40576]
      R1 WmiAcpi;Interface de gestion Microsoft Windows pour ACPI; C:\WINDOWS\system32\DRIVERS\wmiacpi.sys [2008-04-13 8832]
      R2 ANIO;ANIO Service; \??\C:\WINDOWS\system32\ANIO.SYS []
      R2 BDVEDISK;BDVEDISK; \??\C:\Program Files\BitDefender\BitDefender 2009\BDVEDISK.sys []
      R3 ADIHdAudAddService;ADI UAA Function Driver for High Definition Audio Service; C:\WINDOWS\system32\drivers\ADIHdAud.sys [2007-07-10 307712]
      R3 AEAudio;AE Audio Service; C:\WINDOWS\system32\drivers\AEAudio.sys [2007-06-19 103424]
      R3 bdfm;BDFM; C:\WINDOWS\system32\drivers\bdfm.sys [2008-11-18 111112]
      R3 Bdfndisf;BitDefender Firewall NDIS Filter Service; C:\WINDOWS\system32\DRIVERS\bdfndisf.sys [2009-04-07 104328]
      R3 bdfsfltr;bdfsfltr; C:\WINDOWS\system32\drivers\bdfsfltr.sys [2009-01-20 242184]
      R3 BDSelfPr;BDSelfPr; \??\C:\Program Files\BitDefender\BitDefender 2009\bdselfpr.sys []
      R3 e1express;Intel(R) PRO/1000 PCI Express Network Connection Driver; C:\WINDOWS\system32\DRIVERS\e1e5132.sys [2007-04-13 254872]
      R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys [2009-01-15 23848]
      R3 HDAudBus;Pilote de bus Microsoft UAA pour High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
      R3 HECI;Intel(R) Management Engine Interface; C:\WINDOWS\system32\DRIVERS\HECI.sys [2007-05-11 45056]
      R3 HidUsb;Pilote de classe HID Microsoft; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
      R3 ialm;ialm; C:\WINDOWS\system32\DRIVERS\igxpmp32.sys [2007-08-24 5776928]
      R3 IFXTPM;IFXTPM; C:\WINDOWS\system32\DRIVERS\IFXTPM.SYS [2007-01-23 36608]
      R3 mouhid;Pilote HID de souris; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-08-23 12288]
      R3 StillCam;Pilote d'appareil photo numérique série; C:\WINDOWS\system32\DRIVERS\serscan.sys [2001-08-23 6912]
      R3 usbehci;Pilote miniport de contrôleur d'hôte amélioré Microsoft USB 2.0; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-13 30208]
      R3 usbhub;Concentrateur USB2; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-13 59520]
      R3 USBSTOR;Pilote de stockage de masse USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
      R3 usbuhci;Pilote miniport de contrôleur hôte universel USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]
      S1 P3;Pilote processeur Intel Pentium III; C:\WINDOWS\system32\DRIVERS\p3.sys [2008-04-13 46848]
      S3 ac97intc;Service d'installation du pilote audio Intel(r) 82801 (WDM); C:\WINDOWS\system32\drivers\ac97intc.sys [2001-08-17 96256]
      S3 E100B;Pilote de carte Intel (R) PRO; C:\WINDOWS\system32\DRIVERS\e100b325.sys [2001-08-23 117760]
      S3 i81x;i81x; C:\WINDOWS\system32\DRIVERS\i81xnt5.sys [2004-08-03 161020]
      S3 iAimFP0;iAimFP0; C:\WINDOWS\system32\DRIVERS\wADV01nt.sys [2004-08-03 12415]
      S3 iAimFP1;iAimFP1; C:\WINDOWS\system32\DRIVERS\wADV02NT.sys [2004-08-03 12127]
      S3 iAimFP2;iAimFP2; C:\WINDOWS\system32\DRIVERS\wADV05NT.sys [2004-08-03 11775]
      S3 iAimFP3;iAimFP3; C:\WINDOWS\system32\DRIVERS\wSiINTxx.sys [2004-08-03 12063]
      S3 iAimFP4;iAimFP4; C:\WINDOWS\system32\DRIVERS\wVchNTxx.sys [2004-08-03 19455]
      S3 iAimFP5;iAimFP5; C:\WINDOWS\system32\DRIVERS\wADV07nt.sys [2004-08-03 11807]
      S3 iAimFP6;iAimFP6; C:\WINDOWS\system32\DRIVERS\wADV08nt.sys [2004-08-03 11295]
      S3 iAimFP7;iAimFP7; C:\WINDOWS\system32\DRIVERS\wADV09nt.sys [2004-08-03 11871]
      S3 iAimTV0;iAimTV0; C:\WINDOWS\system32\DRIVERS\wATV01nt.sys [2004-08-03 29311]
      S3 iAimTV1;iAimTV1; C:\WINDOWS\system32\DRIVERS\wATV02NT.sys [2004-08-03 19551]
      S3 iAimTV3;iAimTV3; C:\WINDOWS\system32\DRIVERS\wATV04nt.sys [2004-08-03 33599]
      S3 iAimTV4;iAimTV4; C:\WINDOWS\system32\DRIVERS\wCh7xxNT.sys [2004-08-03 23615]
      S3 iAimTV5;iAimTV5; C:\WINDOWS\system32\DRIVERS\wATV10nt.sys [2004-08-03 25471]
      S3 iAimTV6;iAimTV6; C:\WINDOWS\system32\DRIVERS\wATV06nt.sys [2004-08-03 22271]
      S3 Profos;Profos; \??\C:\Program Files\Fichiers communs\BitDefender\BitDefender Threat Scanner\profos.sys []
      S3 RT73;D-Link USB Wireless LAN Card Driver; C:\WINDOWS\system32\DRIVERS\Dr71WU.sys [2005-11-03 245504]
      S3 Trufos;Trufos; \??\C:\Program Files\Fichiers communs\BitDefender\BitDefender Threat Scanner\trufos.sys []
      S3 USBAAPL;Apple Mobile USB Driver; C:\WINDOWS\System32\Drivers\usbaapl.sys [2009-03-06 36864]
      S3 usbbus;LGE Mobile Composite USB Device; C:\WINDOWS\system32\DRIVERS\lgusbbus.sys [2008-09-04 13056]
      S3 UsbDiag;LGE Mobile USB Serial Port; C:\WINDOWS\system32\DRIVERS\lgusbdiag.sys [2008-09-04 19968]
      S3 USBModem;LGE Mobile USB Modem; C:\WINDOWS\system32\DRIVERS\lgusbmodem.sys [2008-09-04 24832]
      S3 usbscan;Usbscan; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-13 15104]
      S3 WpdUsb;WpdUsb; C:\WINDOWS\system32\DRIVERS\wpdusb.sys [2006-10-18 38528]
      S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
      S4 adpu320;adpu320; C:\WINDOWS\system32\DRIVERS\adpu320.sys [2002-05-08 105472]
      S4 IntelIde;IntelIde; C:\WINDOWS\system32\DRIVERS\intelide.sys [2008-04-13 5504]
      S4 Symmpi;Symmpi; C:\WINDOWS\system32\DRIVERS\symmpi.sys [2002-04-04 28416]

      ======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

      R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe [2009-03-06 132424]
      R2 BcmSqlStartupSvc;Service de démarrage SQL Server pour le Gestionnaire de contacts professionnels; C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe [2008-01-16 30312]
      R2 Bonjour Service;Service Bonjour; C:\Program Files\Bonjour\mDNSResponder.exe [2008-12-12 238888]
      R2 IviRegMgr;IviRegMgr; C:\Program Files\Fichiers communs\InterVideo\RegMgr\iviRegMgr.exe [2007-01-04 112152]
      R2 LIVESRV;BitDefender Desktop Update Service; C:\Program Files\Fichiers communs\BitDefender\BitDefender Update Service\livesrv.exe [2009-04-07 415024]
      R2 pdfcDispatcher;PDF Document Manager; C:\Program Files\PDF Complete\pdfsvc.exe [2008-04-07 576024]
      R2 SQLBrowser;SQL Server Browser; c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe [2008-11-24 239968]
      R2 SQLWriter;Enregistreur VSS SQL Server; c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe [2008-11-24 87904]
      R2 VSSERV;BitDefender Virus Shield; C:\Program Files\BitDefender\BitDefender 2009\vsserv.exe [2009-04-07 1626112]
      R2 WSearch;Windows Search; C:\WINDOWS\system32\SearchIndexer.exe [2008-05-26 439808]
      R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-13 14336]
      R3 iPod Service;Service de l’iPod; C:\Program Files\iPod\bin\iPodService.exe [2009-03-11 656168]
      R3 usnjsvc;Service Messenger Sharing Folders USN Journal Reader; C:\Program Files\Windows Live\Messenger\usnsvc.exe [2007-10-18 98328]
      S2 0146531225189889mcinstcleanup;McAfee Application Installer Cleanup (0146531225189889); C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\014653~1.EXE C:\PROGRA~1\FICHIE~1\McAfee\INSTAL~1\cleanup.ini -cleanup -nolog -service []
      S2 ANIWZCSdService;ANIWZCSd Service; C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe [2006-07-03 49152]
      S2 PCA;PC Angel; C:\WINDOWS\SMINST\PCAngel.exe [2006-06-13 364544]
      S3 Arrakis3;BitDefender Arrakis Server; C:\Program Files\Fichiers communs\BitDefender\BitDefender Arrakis Server\bin\Arrakis3.exe [2008-07-17 118784]
      S3 aspnet_state;Service d'état ASP.NET; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2007-10-24 33800]
      S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2007-10-24 70144]
      S3 MSSQL$MSSMLBIZ;SQL Server (MSSMLBIZ); c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [2008-11-24 29263712]
      S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Fichiers communs\Microsoft Shared\OFFICE12\ODSERV.EXE [2007-08-24 443776]
      S3 ose;Office Source Engine; C:\Program Files\Fichiers communs\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
      S3 scan;BitDefender Threat Scanner; C:\WINDOWS\System32\svchost.exe [2008-04-13 14336]
      S3 WLSetupSvc;Windows Live Setup Service; C:\Program Files\Windows Live\installer\WLSetupSvc.exe [2007-10-25 266240]
      S3 WMPNetworkSvc;Service Partage réseau du Lecteur Windows Media; C:\Program Files\Windows Media Player\WMPNetwk.exe [2006-11-03 918016]
      S4 MSSQLServerADHelper;SQL Server Active Directory Helper; c:\Program Files\Microsoft SQL Server\90\Shared\sqladhlp90.exe [2008-11-24 45408]

      -----------------EOF-----------------

      PUIS info.txt

      info.txt logfile of random's system information tool 1.06 2009-04-22 17:47:53

      ======Uninstall list======

      -->C:\Program Files\DivX\DivXConverterUninstall.exe /CONVERTER
      -->C:\Program Files\InstallShield Installation Information\{69333A04-5134-40A5-A055-9166A7AA1EC8}\setup.exe -runfromtemp -l0x0009 -removeonly
      -->MsiExec.exe /I{403EF592-953B-4794-BCEF-ECAB835C2095}
      -->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
      2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-0015-040C-0000-0000000FF1CE} /uninstall {A0353900-21A2-42CF-B973-883500A027F7}
      2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-0016-040C-0000-0000000FF1CE} /uninstall {A0353900-21A2-42CF-B973-883500A027F7}
      2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-0018-040C-0000-0000000FF1CE} /uninstall {A0353900-21A2-42CF-B973-883500A027F7}
      2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-0019-040C-0000-0000000FF1CE} /uninstall {A0353900-21A2-42CF-B973-883500A027F7}
      2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001A-040C-0000-0000000FF1CE} /uninstall {A0353900-21A2-42CF-B973-883500A027F7}
      2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001B-040C-0000-0000000FF1CE} /uninstall {A0353900-21A2-42CF-B973-883500A027F7}
      2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001F-0401-0000-0000000FF1CE} /uninstall {5A2F65A4-808F-4A1E-973E-92E17824982D}
      2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001F-0407-0000-0000000FF1CE} /uninstall {2AB528A5-BB1B-4EBE-8E51-AD0C4CD33CA9}
      2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001F-0409-0000-0000000FF1CE} /uninstall {3EC77D26-799B-4CD8-914F-C1565E796173}
      2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001F-040C-0000-0000000FF1CE} /uninstall {430971B1-C31E-45DA-81E0-72C095BAB72C}
      2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001F-0413-0000-0000000FF1CE} /uninstall {B3F4DC34-7F60-4B7C-A79F-1C13012D99D4}
      2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001F-0C0A-0000-0000000FF1CE} /uninstall {F7A31780-33C4-4E39-951A-5EC9B91D7BF1}
      2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {91120000-0031-0000-0000-0000000FF1CE} /uninstall {BEE75E01-DD3F-4D5F-B96C-609E6538D419}
      2007 Microsoft Office system-->"C:\Program Files\Fichiers communs\Microsoft Shared\OFFICE12\Office Setup Controller\setup.exe" /uninstall PROHYBRIDR /dll OSETUP.DLL
      Activation Assistant for the 2007 Microsoft Office suites-->"C:\Documents and Settings\All Users\Application Data\{174892B1-CBE7-44F5-86FF-AB555EFD73A3}\Microsoft Office Activation Assistant.exe" REMOVE=TRUE MODIFY=FALSE
      Adobe Flash Player 10 ActiveX-->C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
      Adobe Reader 8.1.4 - Français-->MsiExec.exe /I{AC76BA86-7AD7-1036-7B44-A81300000003}
      Adobe Shockwave Player-->C:\WINDOWS\system32\Adobe\SHOCKW~1\UNWISE.EXE C:\WINDOWS\system32\Adobe\SHOCKW~1\Install.log
      AirPlus G-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\10\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{2B7E4354-0492-460A-BDB1-1F59EE141025}\setup.exe" -l0x40c -removeonly
      Analyseur MSXML 6.0-->MsiExec.exe /I{5903C48B-E953-47B8-A651-B9222C483057}
      ANIO Service-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{7B5CE976-C7A9-4E38-A7F3-6C8EF025DD8E}\setup.exe"
      ANIWZCS2 Service-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{4C590030-7469-453E-8589-D15DA9D03F52}\setup.exe"
      AOL Toolbar 5.0-->"C:\Program Files\AOL\AOL Toolbar 5.0\uninstall.exe"
      APIBAT Comptabilité ENTREPRENEUR-->C:\WINDOWS\IsUn040c.exe -fC:\APIBAT\COMP_ENT\Uninst.isu
      APIBAT Financier ENTREPRENEUR-->C:\WINDOWS\IsUn040c.exe -fC:\APIBAT\FIN_ENT\Uninst.isu
      Apple Mobile Device Support-->MsiExec.exe /I{162B71B8-8464-4680-A086-601D555B331D}
      Apple Software Update-->MsiExec.exe /I{6956856F-B6B3-4BE0-BA0B-8F495BE32033}
      Archiveur WinRAR-->C:\Program Files\WinRAR\uninstall.exe
      Batigest ENTREPRENEUR 6-->C:\WINDOWS\IsUn040c.exe -fC:\APIBAT\BatigEnt6\Uninst.isu
      BitDefender Internet Security 2009-->MsiExec.exe /X{0B246DA8-309B-4BFD-B2DE-6CB584CCC3EF}
      Bonjour-->MsiExec.exe /I{07287123-B8AC-41CE-8346-3D777245C35B}
      Brother MFL-Pro Suite-->"C:\Program Files\InstallShield Installation Information\{C83FB11D-9EC6-49D7-99A7-DDDB2264883C}\Setup.exe" -runfromtemp -l0x040c Brunin03.dll -removeonly
      CCleaner (remove only)-->"C:\Program Files\CCleaner\uninst.exe"
      CCScore-->MsiExec.exe /I{B4B44FE7-41FF-4DAD-8C0A-E406DDA72992}
      Correctif pour Lecteur Windows Media 11 (KB939683)-->"C:\WINDOWS\$NtUninstallKB939683$\spuninst\spuninst.exe"
      Correctif pour Windows XP (KB952117-v2)-->"C:\WINDOWS\$NtUninstallKB952117-v2$\spuninst\spuninst.exe"
      Correctif pour Windows XP (KB952287)-->"C:\WINDOWS\$NtUninstallKB952287$\spuninst\spuninst.exe"
      DivX Codec-->C:\Program Files\DivX\DivXCodecUninstall.exe /CODEC
      DivX Converter-->C:\Program Files\DivX\DivXConverterUninstall.exe /CONVERTER
      DivX Player-->C:\Program Files\DivX\DivXPlayerUninstall.exe /PLAYER
      DivX Plus DirectShow Filters-->C:\Program Files\DivX\DivXDSFiltersUninstall.exe /DSFILTERS
      Dungeon Party 0.7.2.3-->"C:\Program Files\Cyanide\Dungeon Party\unins000.exe"
      eMule-->"C:\Program Files\eMule\Uninstall.exe"
      ESSBrwr-->MsiExec.exe /I{643EAE81-920C-4931-9F0B-4B343B225CA6}
      ESSCDBK-->MsiExec.exe /I{AE1FA02D-E6A4-4EA0-8E58-6483CAC016DD}
      ESScore-->MsiExec.exe /I{42938595-0D83-404D-9F73-F8177FDD531A}
      ESSgui-->MsiExec.exe /I{91517631-A9F3-4B7C-B482-43E0068FD55A}
      ESSini-->MsiExec.exe /I{8E92D746-CD9F-4B90-9668-42B74C14F765}
      ESSPCD-->MsiExec.exe /I{14D4ED84-6A9A-45A0-96F6-1753768C3CB5}
      ESSPDock-->MsiExec.exe /I{FCDB1C92-03C6-4C76-8625-371224256091}
      ESSSONIC-->MsiExec.exe /I{073F22CE-9A5B-4A40-A604-C7270AC6BF34}
      ESSTOOLS-->MsiExec.exe /I{8A502E38-29C9-49FA-BCFA-D727CA062589}
      essvatgt-->MsiExec.exe /I{2D03B6F8-DF36-4980-B7B6-5B93D5BA3A8F}
      Extension d'application APIBAT-->MsiExec.exe /I{B7C76AC1-35E0-4254-B97D-07DB2BD65D64}
      fflink-->MsiExec.exe /I{608D2A3C-6889-4C11-9B54-A42F45ACBFDB}
      Fichiers de prise en charge de l'installation de Microsoft SQL Server (Français)-->MsiExec.exe /X{3380F354-C5F7-4E71-8F51-EEE6C3F06C62}
      Gestionnaire de contacts professionnels pour Outlook 2007 SP1-->"C:\Program Files\Microsoft Small Business\Business Contact Manager\SetupBootstrap\Setup.exe" /remove {69ca8988-1c6c-4285-b8af-db780a6e42af}
      Gestionnaire de contacts professionnels pour Outlook 2007 SP1-->MsiExec.exe /X{69CA8988-1C6C-4285-B8AF-DB780A6E42AF}
      HijackThis 2.0.2-->"C:\Program Files\Trend Micro\HijackThis\HijackThis.exe" /uninstall
      Hotfix for Windows Media Format 11 SDK (KB929399)-->"C:\WINDOWS\$NtUninstallKB929399$\spuninst\spuninst.exe"
      Hotfix for Windows XP (KB915800-v4)-->"C:\WINDOWS\$NtUninstallKB915800-v4$\spuninst\spuninst.exe"
      HP Backup and Recovery Manager-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\10\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{3F9F7336-6DF8-476F-ABF6-C70A17FAF619}\setup.exe" -l0x40c -uninst -removeonly
      HP Help and Support-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\10\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{A93C4E94-1005-489D-BEAA-B873C1AA6CFC}\SETUP.exe" -l0x40c -removeonly
      Intel(R) Graphics Media Accelerator Driver-->C:\WINDOWS\system32\igxpun.exe -uninstall
      Intel(R) PRO Network Connections 12.1.14.1-->MsiExec.exe /i{777CA40C-0206-4EF6-A0FC-618BF06BF8D0} ARPREMOVE=1
      Interface Intel® Management Engine-->C:\WINDOWS\system32\heciudlg.exe -uninstall
      InterVideo WinDVD-->"C:\Program Files\InstallShield Installation Information\{91810AFC-A4F8-4EBA-A5AA-B198BBC81144}\setup.exe" REMOVEALL
      iTunes-->MsiExec.exe /I{E5145D2D-793B-4A16-BA42-3F13EEAA7D5E}
      Java(TM) 6 Update 2-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160020}
      kgcbaby-->MsiExec.exe /I{E18B549C-5D15-45DA-8D8F-8FD2BD946344}
      kgcbase-->MsiExec.exe /I{F22C222C-3CE2-4A4B-A83F-AF4681371ABE}
      kgchday-->MsiExec.exe /I{11F3F858-4131-4FFA-A560-3FE282933B6E}
      kgchlwn-->MsiExec.exe /I{03EDED24-8375-407D-A721-4643D9768BE1}
      kgcinvt-->MsiExec.exe /I{9BD54685-1496-46A5-AB62-357CD140ED8B}
      kgckids-->MsiExec.exe /I{693C08A7-9E76-43FF-B11E-9A58175474C4}
      kgcmove-->MsiExec.exe /I{A1588373-1D86-4D44-86C9-78ABD190F9CC}
      kgcvday-->MsiExec.exe /I{8A8664E1-84C8-4936-891C-BC1F07797549}
      Lecteur Windows Media 11-->"C:\Program Files\Windows Media Player\Setup_wm.exe" /Uninstall
      LG PC Suite II-->C:\Program Files\InstallShield Installation Information\{14DCD95A-EBA3-4BF0-B7EF-533852E99BE6}\setup.exe -runfromtemp -l0x040c -removeonly
      LG USB Modem driver-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\10\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{C3ABE126-2BB2-4246-BFE1-6797679B3579}\setup.exe" -l0x40c LG -removeonly
      Logiciel Kodak EasyShare-->C:\Documents and Settings\All Users\Application Data\Kodak\EasyShareSetup\$SETUP_140002_3d66cda\Setup.exe /APR-REMOVE
      Microsoft .NET Framework 1.1 French Language Pack-->MsiExec.exe /X{9A394342-4A68-4EBA-85A6-55B559F4E700}
      Microsoft .NET Framework 1.1 Hotfix (KB928366)-->"C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\hotfix.exe" "C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\M928366\M928366Uninstall.msp"
      Microsoft .NET Framework 1.1-->msiexec.exe /X {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
      Microsoft .NET Framework 1.1-->MsiExec.exe /X{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
      Microsoft .NET Framework 2.0 Service Pack 1 Language Pack - FRA-->MsiExec.exe /I{3F7924B9-D148-3141-87B1-68F36043A940}
      Microsoft .NET Framework 2.0 Service Pack 1-->MsiExec.exe /I{B508B3F1-A24A-32C0-B310-85786919EF28}
      Microsoft Compression Client Pack 1.0 for Windows XP-->"C:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe"
      Microsoft Internationalized Domain Names Mitigation APIs-->"C:\WINDOWS\$NtServicePackUninstallIDNMitigationAPIs$\spuninst\spuninst.exe"
      Microsoft National Language Support Downlevel APIs-->"C:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$\spuninst\spuninst.exe"
      Microsoft Office 2003 Web Components-->MsiExec.exe /I{90A4040C-6000-11D3-8CFE-0150048383C9}
      Microsoft Office 2007 Primary Interop Assemblies-->MsiExec.exe /X{50120000-1105-0000-0000-0000000FF1CE}
      Microsoft Office Access MUI (French) 2007-->MsiExec.exe /X{90120000-0015-040C-0000-0000000FF1CE}
      Microsoft Office Excel MUI (French) 2007-->MsiExec.exe /X{90120000-0016-040C-0000-0000000FF1CE}
      Microsoft Office Language Pack 2007 Service Pack 1 (SP1)-->msiexec /package {90120000-006E-040C-0000-0000000FF1CE} /uninstall {EC50B538-CBE1-42E6-B7FE-87AA540AADFB}
      Microsoft Office Outlook MUI (French) 2007-->MsiExec.exe /X{90120000-001A-040C-0000-0000000FF1CE}
      Microsoft Office PowerPoint MUI (French) 2007-->MsiExec.exe /X{90120000-0018-040C-0000-0000000FF1CE}
      Microsoft Office Professional Hybrid 2007-->MsiExec.exe /X{91120000-0031-0000-0000-0000000FF1CE}
      Microsoft Office Proof (Arabic) 2007-->MsiExec.exe /X{90120000-001F-0401-0000-0000000FF1CE}
      Microsoft Office Proof (Dutch) 2007-->MsiExec.exe /X{90120000-001F-0413-0000-0000000FF1CE}
      Microsoft Office Proof (English) 2007-->MsiExec.exe /X{90120000-001F-0409-0000-0000000FF1CE}
      Microsoft Office Proof (French) 2007-->MsiExec.exe /X{90120000-001F-040C-0000-0000000FF1CE}
      Microsoft Office Proof (German) 2007-->MsiExec.exe /X{90120000-001F-0407-0000-0000000FF1CE}
      Microsoft Office Proof (Spanish) 2007-->MsiExec.exe /X{90120000-001F-0C0A-0000-0000000FF1CE}
      Microsoft Office Proofing (French) 2007-->MsiExec.exe /X{90120000-002C-040C-0000-0000000FF1CE}
      Microsoft Office Publisher MUI (French) 2007-->MsiExec.exe /X{90120000-0019-040C-0000-0000000FF1CE}
      Microsoft Office Shared MUI (French) 2007-->MsiExec.exe /X{90120000-006E-040C-0000-0000000FF1CE}
      Microsoft Office Small Business Connectivity Components-->MsiExec.exe /X{A939D341-5A04-4E0A-BB55-3E65B386432D}
      Microsoft Office Word MUI (French) 2007-->MsiExec.exe /X{90120000-001B-040C-0000-0000000FF1CE}
      Microsoft SQL Server 2005 Express Edition (MSSMLBIZ)-->MsiExec.exe /I{480DBB60-F0B6-45F2-B26F-1A2E11197791}
      Microsoft SQL Server 2005-->"c:\Program Files\Microsoft SQL Server\90\Setup Bootstrap\ARPWrapper.exe" /Remove
      Microsoft SQL Server Native Client-->MsiExec.exe /I{1F24E48F-7692-4E89-8784-68DD4D2712A0}
      Microsoft SQL Server VSS Writer-->MsiExec.exe /I{A30179B7-997A-4D47-AA43-57AE59A9C78B}
      Microsoft User-Mode Driver Framework Feature Pack 1.0-->"C:\WINDOWS\$NtUninstallWudf01000$\spuninst\spuninst.exe"
      Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
      Mise à jour critique pour Lecteur Windows Media 11 (KB959772)-->"C:\WINDOWS\$NtUninstallKB959772_WM11$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Lecteur Windows Media (KB952069)-->"C:\WINDOWS\$NtUninstallKB952069_WM9$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Lecteur Windows Media 11 (KB936782)-->"C:\WINDOWS\$NtUninstallKB936782_WMP11$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Lecteur Windows Media 11 (KB954154)-->"C:\WINDOWS\$NtUninstallKB954154_WM11$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows Internet Explorer 7 (KB938127-v2)-->"C:\WINDOWS\ie7updates\KB938127-v2-IE7\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows Internet Explorer 7 (KB953838)-->"C:\WINDOWS\ie7updates\KB953838-IE7\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows Internet Explorer 7 (KB956390)-->"C:\WINDOWS\ie7updates\KB956390-IE7\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows Internet Explorer 7 (KB958215)-->"C:\WINDOWS\ie7updates\KB958215-IE7\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows Internet Explorer 7 (KB960714)-->"C:\WINDOWS\ie7updates\KB960714-IE7\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows Internet Explorer 7 (KB961260)-->"C:\WINDOWS\ie7updates\KB961260-IE7\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows Internet Explorer 7 (KB963027)-->"C:\WINDOWS\ie7updates\KB963027-IE7\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB923561)-->"C:\WINDOWS\$NtUninstallKB923561$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB923789)-->C:\WINDOWS\system32\MacroMed\Flash\genuinst.exe C:\WINDOWS\system32\MacroMed\Flash\KB923789.inf
      Mise à jour de sécurité pour Windows XP (KB938464)-->"C:\WINDOWS\$NtUninstallKB938464$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB941569)-->"C:\WINDOWS\$NtUninstallKB941569$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB946648)-->"C:\WINDOWS\$NtUninstallKB946648$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB950762)-->"C:\WINDOWS\$NtUninstallKB950762$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB950974)-->"C:\WINDOWS\$NtUninstallKB950974$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB951066)-->"C:\WINDOWS\$NtUninstallKB951066$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB951376-v2)-->"C:\WINDOWS\$NtUninstallKB951376-v2$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB951698)-->"C:\WINDOWS\$NtUninstallKB951698$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB951748)-->"C:\WINDOWS\$NtUninstallKB951748$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB952004)-->"C:\WINDOWS\$NtUninstallKB952004$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB952954)-->"C:\WINDOWS\$NtUninstallKB952954$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB954211)-->"C:\WINDOWS\$NtUninstallKB954211$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB954459)-->"C:\WINDOWS\$NtUninstallKB954459$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB954600)-->"C:\WINDOWS\$NtUninstallKB954600$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB955069)-->"C:\WINDOWS\$NtUninstallKB955069$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB956391)-->"C:\WINDOWS\$NtUninstallKB956391$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB956572)-->"C:\WINDOWS\$NtUninstallKB956572$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB956802)-->"C:\WINDOWS\$NtUninstallKB956802$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB956803)-->"C:\WINDOWS\$NtUninstallKB956803$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB956841)-->"C:\WINDOWS\$NtUninstallKB956841$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB957095)-->"C:\WINDOWS\$NtUninstallKB957095$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB957097)-->"C:\WINDOWS\$NtUninstallKB957097$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB958644)-->"C:\WINDOWS\$NtUninstallKB958644$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB958687)-->"C:\WINDOWS\$NtUninstallKB958687$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB958690)-->"C:\WINDOWS\$NtUninstallKB958690$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB959426)-->"C:\WINDOWS\$NtUninstallKB959426$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB960225)-->"C:\WINDOWS\$NtUninstallKB960225$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB960715)-->"C:\WINDOWS\$NtUninstallKB960715$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB960803)-->"C:\WINDOWS\$NtUninstallKB960803$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB961373)-->"C:\WINDOWS\$NtUninstallKB961373$\spuninst\spuninst.exe"
      Mise à jour pour Windows XP (KB898461)-->"C:\WINDOWS\$NtUninstallKB898461$\spuninst\spuninst.exe"
      Mise à jour pour Windows XP (KB943729)-->"C:\WINDOWS\$NtUninstallKB943729$\spuninst\spuninst.exe"
      Mise à jour pour Windows XP (KB951072-v2)-->"C:\WINDOWS\$NtUninstallKB951072-v2$\spuninst\spuninst.exe"
      Mise à jour pour Windows XP (KB951978)-->"C:\WINDOWS\$NtUninstallKB951978$\spuninst\spuninst.exe"
      Mise à jour pour Windows XP (KB955839)-->"C:\WINDOWS\$NtUninstallKB955839$\spuninst\spuninst.exe"
      Mise à jour pour Windows XP (KB967715)-->"C:\WINDOWS\$NtUninstallKB967715$\spuninst\spuninst.exe"
      MobileMe Control Panel-->MsiExec.exe /I{C7EEC93A-2A61-4B1E-B696-A264680A889D}
      MSN-->C:\Program Files\MSN\MsnInstaller\msninst.exe /Action:ARP
      MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
      Navman NavDesk 2008-->C:\Program Files\InstallShield Installation Information\{9C8732C3-32DE-4569-9E90-30040D76DABC}\Setup.exe -runfromtemp -l0x040c -removeonly
      netbrdg-->MsiExec.exe /I{4537EA4B-F603-4181-89FB-2953FC695AB1}
      OfotoXMI-->MsiExec.exe /I{B162D0A6-9A1D-4B7C-91A5-88FB48113C45}
      PaperPort Image Printer-->MsiExec.exe /X{332CC6BF-E6C7-48EE-BA3D-435E576AD67F}
      PDF Complete-->C:\Program Files\PDF Complete\uninstall.exe
      PhotoFiltre-->"C:\Documents and Settings\direction\Mes documents\doc adada\PhotoFiltre\Uninst.exe"
      QuickTime-->MsiExec.exe /I{216AB108-2AE1-4130-B3D5-20B2C4C80F8F}
      Safari-->MsiExec.exe /I{D90AFDE3-3E67-407A-ACA8-F0BAAD012F08}
      ScanSoft PaperPort 11-->MsiExec.exe /I{B6C89654-A6A2-477C-873B-724EC1C56407}
      Security Update for 2007 Microsoft Office System (KB951550)-->msiexec /package {91120000-0031-0000-0000-0000000FF1CE} /uninstall {B243E9A5-ED77-4F1B-B338-2486FD82DC85}
      Security Update for 2007 Microsoft Office System (KB951944)-->msiexec /package {91120000-0031-0000-0000-0000000FF1CE} /uninstall {797AE457-BA17-4BBC-B501-25FB3A0103C7}
      Security Update for 2007 Microsoft Office System (KB960003)-->msiexec /package {91120000-0031-0000-0000-0000000FF1CE} /uninstall {F04F8702-18D0-458D-921E-146FB7CD38CF}
      Security Update for Microsoft Office Excel 2007 (KB959997)-->msiexec /package {91120000-0031-0000-0000-0000000FF1CE} /uninstall {9EAC3AEC-5C81-4856-A05B-DE9DC236D740}
      Security Update for Microsoft Office PowerPoint 2007 (KB951338)-->msiexec /package {91120000-0031-0000-0000-0000000FF1CE} /uninstall {558B709B-821B-4FC5-90FC-9A8890641E77}
      Security Update for Microsoft Office Publisher 2007 (KB950114)-->msiexec /package {91120000-0031-0000-0000-0000000FF1CE} /uninstall {F9C3CDBA-1F00-4D4D-959D-75C9D3ACDD85}
      Security Update for Microsoft Office system 2007 (KB954326)-->msiexec /package {91120000-0031-0000-0000-0000000FF1CE} /uninstall {5F7F6FFF-395D-480E-8450-64F385D82C5F}
      Security Update for Microsoft Office system 2007 (KB956828)-->msiexec /package {91120000-0031-0000-0000-0000000FF1CE} /uninstall {885E081B-72BD-4E76-8E98-30B4BE468FAC}
      Security Update for Microsoft Office Word 2007 (KB956358)-->msiexec /package {91120000-0031-0000-0000-0000000FF1CE} /uninstall {4551666D-0FD6-4C69-8A81-1C6F2E64517C}
      SFR-->MsiExec.exe /I{DB02F716-6275-42E9-B8D2-83BA2BF5100B}
      SHASTA-->MsiExec.exe /I{605A4E39-613C-4A12-B56F-DEFBE6757237}
      skin0001-->MsiExec.exe /I{5316DFC9-CE99-4458-9AB3-E8726EDE0210}
      SKINXSDK-->MsiExec.exe /I{F4A2E7CC-60CA-4AFA-B67F-AD5E58173C3F}
      SoundMAX-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\10\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F0A37341-D692-11D4-A984-009027EC0A9C}\SETUP.exe" -l0x40c -removeonly
      Spotify-->"C:\Program Files\Spotify\uninstall.exe"
      staticcr-->MsiExec.exe /I{8943CE61-53BD-475E-90E1-A580869E98A2}
      tooltips-->MsiExec.exe /I{E79987F0-0E34-42CC-B8FF-6C860AEEB26A}
      Update for Microsoft Office Outlook 2007 (KB952142)-->msiexec /package {91120000-0031-0000-0000-0000000FF1CE} /uninstall {4AD3A076-427C-491F-A5B7-7D1DE788A756}
      Update for Office 2007 (KB946691)-->msiexec /package {91120000-0031-0000-0000-0000000FF1CE} /uninstall {A420F522-7395-4872-9882-C591B4B92278}
      Update for Outlook 2007 Junk Email Filter (kb962871)-->msiexec /package {91120000-0031-0000-0000-0000000FF1CE} /uninstall {297857BF-4011-449B-BD74-DB64D182821C}
      VC80CRTRedist - 8.0.50727.762-->MsiExec.exe /I{767CC44C-9BBC-438D-BAD3-FD4595DD148B}
      VPRINTOL-->MsiExec.exe /I{999D43F4-9709-4887-9B1A-83EBB15A8370}
      Winamp Toolbar for Firefox-->"\extensions\{0b38152b-1b20-484d-a11f-5e04a9b0661f}\uninstall.exe"
      Winamp-->"C:\Program Files\Winamp\UninstWA.exe"
      Windows Internet Explorer 7-->"C:\WINDOWS\ie7\spuninst\spuninst.exe"
      Windows Live installer-->MsiExec.exe /X{FD44E544-E7D0-4DBA-9FA0-8AE1A1300390}
      Windows Live Messenger-->MsiExec.exe /X{BADF6744-3787-48F6-B8C9-4C4995401D65}
      Windows Media Format 11 runtime-->"C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll
      Windows Media Format 11 runtime-->"C:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe"
      Windows Media Player 11-->"C:\WINDOWS\$NtUninstallwmp11$\spuninst\spuninst.exe"
      Windows Search 4.0-->"C:\WINDOWS\$NtUninstallKB940157$\spuninst\spuninst.exe"
      Windows XP Service Pack 3-->"C:\WINDOWS\$NtServicePackUninstall$\spuninst\spuninst.exe"
      WIRELESS-->MsiExec.exe /I{F9593CFB-D836-49BC-BFF1-0E669A411D9F}

      ======Security center information======

      AV: BitDefender Antivirus
      FW: BitDefender Firewall (disabled)

      ======System event log======

      Computer Name: D5800S
      Event Code: 7036
      Message: Le service Acquisition d'image Windows (WIA) est entré dans l'état : en cours d'exécution.

      Record Number: 6618
      Source Name: Service Control Manager
      Time Written: 20090309014317.000000+060
      Event Type: Informations
      User:

      Computer Name: D5800S
      Event Code: 7036
      Message: Le service Acquisition d'image Windows (WIA) est entré dans l'état : en cours d'exécution.

      Record Number: 6617
      Source Name: Service Control Manager
      Time Written: 20090309014117.000000+060
      Event Type: Informations
      User:

      Computer Name: D5800S
      Event Code: 7036
      Message: Le service Acquisition d'image Windows (WIA) est entré dans l'état : en cours d'exécution.

      Record Number: 6616
      Source Name: Service Control Manager
      Time Written: 20090309013717.000000+060
      Event Type: Informations
      User:

      Computer Name: D5800S
      Event Code: 7036
      Message: Le service Acquisition d'image Windows (WIA) est entré dans l'état : en cours d'exécution.

      Record Number: 6615
      Source Name: Service Control Manager
      Time Written: 20090309013517.000000+060
      Event Type: Informations
      User:

      Computer Name: D5800S
      Event Code: 7036
      Message: Le service Acquisition d'image Windows (WIA) est entré dans l'état : en cours d'exécution.

      Record Number: 6614
      Source Name: Service Control Manager
      Time Written: 20090309013318.000000+060
      Event Type: Informations
      User:

      =====Application event log=====

      Computer Name: D5800S
      Event Code: 100
      Message: MsnMsgr (3452) Le moteur de base de données 5.01.2600.5512 est démarré.

      Record Number: 4070
      Source Name: ESENT
      Time Written: 20090215131227.000000+060
      Event Type: Informations
      User:

      Computer Name: D5800S
      Event Code: 101
      Message: MsnMsgr (3452) Le moteur de base de données est arrêté.

      Record Number: 4069
      Source Name: ESENT
      Time Written: 20090215131207.000000+060
      Event Type: Informations
      User:

      Computer Name: D5800S
      Event Code: 103
      Message: MsnMsgr (3452) \\.\C:\Documents and Settings\direction\Local Settings\Application Data\Microsoft\Messenger\very_guiloutifull@live.fr\SharingMetadata\Working\database_404B_268_5820_177E\dfsr.db: Le moteur de base de données a arrêté une instance (0).

      Record Number: 4068
      Source Name: ESENT
      Time Written: 20090215131207.000000+060
      Event Type: Informations
      User:

      Computer Name: D5800S
      Event Code: 302
      Message: MsnMsgr (3452) \\.\C:\Documents and Settings\direction\Local Settings\Application Data\Microsoft\Messenger\very_guiloutifull@live.fr\SharingMetadata\Working\database_404B_268_5820_177E\dfsr.db: Le moteur de base de données a exécuté la procédure de récupération avec succès.

      Record Number: 4067
      Source Name: ESENT
      Time Written: 20090215131201.000000+060
      Event Type: Informations
      User:

      Computer Name: D5800S
      Event Code: 301
      Message: MsnMsgr (3452) \\.\C:\Documents and Settings\direction\Local Settings\Application Data\Microsoft\Messenger\very_guiloutifull@live.fr\SharingMetadata\Working\database_404B_268_5820_177E\dfsr.db: Le moteur de base de données commence la relecture du fichier journal \\.\C:\Documents and Settings\direction\Local Settings\Application Data\Microsoft\Messenger\very_guiloutifull@live.fr\SharingMetadata\Working\database_404B_268_5820_177E\fsr.log.

      Record Number: 4066
      Source Name: ESENT
      Time Written: 20090215131200.000000+060
      Event Type: Informations
      User:

      ======Environment variables======

      "ComSpec"=%SystemRoot%\system32\cmd.exe
      "Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;C:\Program Files\Intel\DMIX;c:\Program Files\Microsoft SQL Server\90\Tools\binn\;C:\Program Files\QuickTime\QTSystem\
      "windir"=%SystemRoot%
      "FP_NO_HOST_CHECK"=NO
      "OS"=Windows_NT
      "PROCESSOR_ARCHITECTURE"=x86
      "PROCESSOR_LEVEL"=6
      "PROCESSOR_IDENTIFIER"=x86 Family 6 Model 23 Stepping 10, GenuineIntel
      "PROCESSOR_REVISION"=170a
      "NUMBER_OF_PROCESSORS"=2
      "PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
      "TEMP"=%SystemRoot%\TEMP
      "TMP"=%SystemRoot%\TEMP
      "OnlineServices"=Online Services
      "Platform"=BPC
      "CLASSPATH"=.;C:\Program Files\Java\jre1.6.0_02\lib\ext\QTJava.zip
      "QTJAVA"=C:\Program Files\Java\jre1.6.0_02\lib\ext\QTJava.zip

      -----------------EOF-----------------

      Quand au rapport Bitdefender je veux bien mais il n'indique aucun soucis... C'est grave docteur? Save my work please
      1. Contributeur sécurité
        il manque le debut du premier rapport refais et mets le en entier

        puis

        Télécharge et install UsbFix de C_XX & Chiquitine29

        Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) susceptible d'avoir été infectées sans les ouvrir

        # Double clic sur le raccourci UsbFix présent sur ton bureau .

        # Choisis l'option 1 ( Recherche )

        # Laisse travailler l'outil.

        # Ensuite post le rapport UsbFix.txt qui apparaitra.

        # Note : Le rapport UsbFix.txt est sauvegardé a la racine du disque. ( C:\UsbFix.txt )

        ( CTRL+A Pour tout selectionner , CTRL+C pour copier et CTRL+V pour coller )

        # Note : "Process.exe", une composante de l'outil, est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool.
        Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.
        Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall...) d'où l'alerte émise par ces antivirus.
        1. Je vous repost ce que j'ai sous les yeux :

          Logfile of random's system information tool 1.06 (written by random/random)
          Run by direction at 2009-04-22 17:47:36
          Microsoft Windows XP Professionnel Service Pack 3
          System drive C: has 166 GB (73%) free of 228 GB
          Total RAM: 2021 MB (61% free)

          Logfile of Trend Micro HijackThis v2.0.2
          Scan saved at 17:47:49, on 22/04/2009
          Platform: Windows XP SP3 (WinNT 5.01.2600)
          MSIE: Internet Explorer v7.00 (7.00.6000.16827)
          Boot mode: Normal

          Running processes:
          C:\WINDOWS\System32\smss.exe
          C:\WINDOWS\system32\winlogon.exe
          C:\WINDOWS\system32\services.exe
          C:\WINDOWS\system32\lsass.exe
          C:\WINDOWS\system32\svchost.exe
          C:\Program Files\Fichiers communs\BitDefender\BitDefender Update Service\livesrv.exe
          C:\Program Files\BitDefender\BitDefender 2009\vsserv.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\system32\spoolsv.exe
          C:\WINDOWS\Explorer.EXE
          C:\WINDOWS\system32\igfxtray.exe
          C:\WINDOWS\system32\igfxsrvc.exe
          C:\WINDOWS\system32\hkcmd.exe
          C:\WINDOWS\system32\igfxpers.exe
          C:\Program Files\Analog Devices\Core\smax4pnp.exe
          C:\Program Files\Analog Devices\SoundMAX\Smax4.exe
          C:\WINDOWS\SMINST\Scheduler.exe
          C:\Program Files\D-Link\AirPlus G\AirGCFG.exe
          C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
          C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
          C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
          C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe
          C:\Program Files\Bonjour\mDNSResponder.exe
          C:\Program Files\Fichiers communs\InterVideo\RegMgr\iviRegMgr.exe
          C:\Program Files\Winamp\winampa.exe
          C:\Program Files\PDF Complete\pdfsvc.exe
          C:\Program Files\BitDefender\BitDefender 2009\bdagent.exe
          C:\Program Files\Brother\ControlCenter3\brccMCtl.exe
          C:\Program Files\iTunes\iTunesHelper.exe
          C:\windows\pp06.exe
          C:\WINDOWS\system32\ctfmon.exe
          C:\Program Files\BitDefender\BitDefender 2009\seccenter.exe
          C:\WINDOWS\system32\dll32.exe
          C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
          C:\Program Files\Windows Desktop Search\WindowsSearch.exe
          c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\system32\SearchIndexer.exe
          C:\Program Files\iPod\bin\iPodService.exe
          C:\Program Files\Windows Live\Messenger\usnsvc.exe
          C:\Documents and Settings\direction\Bureau\stinger1001546.exe
          C:\Program Files\Internet Explorer\iexplore.exe
          C:\WINDOWS\system32\wuauclt.exe
          C:\WINDOWS\system32\SearchProtocolHost.exe
          C:\Documents and Settings\direction\Bureau\RSIT.exe
          C:\Program Files\Trend Micro\HijackThis\direction.exe

          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.fr/
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
          R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
          R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=localhost:7171
          R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local;<local>
          R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
          O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
          O2 - BHO: 219198 helper - {5B452B01-12C9-4286-81D9-2308AEB3CD94} - C:\WINDOWS\system32\219198\219198.dll
          O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
          O2 - BHO: AOL Toolbar BHO - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll
          O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
          O2 - BHO: 179223 helper - {B3FA56CF-B3F9-4328-9802-CFAACEA86646} - C:\WINDOWS\system32\179223\179223.dll
          O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file)
          O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll
          O3 - Toolbar: BitDefender Toolbar - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - C:\Program Files\BitDefender\BitDefender 2009\IEToolbar.dll
          O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
          O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
          O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
          O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
          O4 - HKLM\..\Run: [SoundMAX] "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray
          O4 - HKLM\..\Run: [PDF Complete] C:\Program Files\PDF Complete\pdfsty.exe
          O4 - HKLM\..\Run: [SetRefresh] C:\Program Files\Compaq\SetRefresh\SetRefresh.exe
          O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\Sminst\Recguard.exe
          O4 - HKLM\..\Run: [Reminder] C:\WINDOWS\Creator\Remind_XP.exe
          O4 - HKLM\..\Run: [Scheduler] C:\WINDOWS\SMINST\Scheduler.exe
          O4 - HKLM\..\Run: [D-Link AirPlus G] C:\Program Files\D-Link\AirPlus G\AirGCFG.exe
          O4 - HKLM\..\Run: [ANIWZCS2Service] C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
          O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Fichiers communs\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
          O4 - HKLM\..\Run: [PaperPort PTD] "C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe"
          O4 - HKLM\..\Run: [IndexSearch] "C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe"
          O4 - HKLM\..\Run: [PPort11reminder] "C:\Program Files\ScanSoft\PaperPort\Ereg\Ereg.exe" -r "C:\Documents and Settings\All Users\Application Data\ScanSoft\PaperPort\11\Config\Ereg\Ereg.ini
          O4 - HKLM\..\Run: [BrMfcWnd] C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe /AUTORUN
          O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
          O4 - HKLM\..\Run: [BDAgent] "C:\Program Files\BitDefender\BitDefender 2009\bdagent.exe"
          O4 - HKLM\..\Run: [BitDefender Antiphishing Helper] "C:\Program Files\BitDefender\BitDefender 2009\IEShow.exe"
          O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
          O4 - HKLM\..\Run: [ControlCenter3] C:\Program Files\Brother\ControlCenter3\brctrcen.exe /autorun
          O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
          O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
          O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
          O4 - HKLM\..\Run: [sysldtray] C:\windows\ld08.exe
          O4 - HKLM\..\Run: [pp] C:\windows\pp06.exe
          O4 - HKLM\..\Run: [sysmstray] C:\windows\mstre18.exe
          O4 - HKLM\..\Run: [sysfbtray] C:\windows\freddy41.exe
          O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
          O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
          O4 - HKCU\..\Run: [dll32] dll32
          O4 - HKCU\..\RunOnce: [Shockwave Updater] C:\WINDOWS\system32\Adobe\SHOCKW~1\SWHELP~1.EXE -Update -1103471 -"Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 1.1.4322; .NET CLR 2.0.50727)" -"http://www.absoluflash.com/..."
          O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
          O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
          O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
          O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
          O4 - Global Startup: Logiciel Kodak EasyShare.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
          O4 - Global Startup: Windows Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
          O8 - Extra context menu item: &Recherche AOL Toolbar - C:\Documents and Settings\All Users\Application Data\AOL\ieToolbar\resources\fr-FR\local\search.html
          O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
          O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
          O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
          O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll
          O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
          O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
          O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
          O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
          O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
          O14 - IERESET.INF: START_PAGE_URL=http://www.hp.com
          O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/...
          O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
          O17 - HKLM\System\CCS\Services\Tcpip\..\{100FBF70-59C7-488E-AEC3-AB1EB6B61B8A}: NameServer = 193.252.19.3,193.252.19.4
          O17 - HKLM\System\CCS\Services\Tcpip\..\{97873F82-E1EA-4CDA-A765-B94D23476B92}: NameServer = 192.168.0.254
          O23 - Service: McAfee Application Installer Cleanup (0146531225189889) (0146531225189889mcinstcleanup) - Unknown owner - C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\014653~1.EXE (file missing)
          O23 - Service: ANIWZCSd Service (ANIWZCSdService) - Alpha Networks Inc. - C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe
          O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
          O23 - Service: BitDefender Arrakis Server (Arrakis3) - BitDefender S.R.L. https://www.bitdefender.fr/ - C:\Program Files\Fichiers communs\BitDefender\BitDefender Arrakis Server\bin\Arrakis3.exe
          O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
          O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
          O23 - Service: IviRegMgr - InterVideo - C:\Program Files\Fichiers communs\InterVideo\RegMgr\iviRegMgr.exe
          O23 - Service: BitDefender Desktop Update Service (LIVESRV) - BitDefender SRL - C:\Program Files\Fichiers communs\BitDefender\BitDefender Update Service\livesrv.exe
          O23 - Service: PC Angel (PCA) - SoftThinks - C:\WINDOWS\SMINST\PCAngel.exe
          O23 - Service: PDF Document Manager (pdfcDispatcher) - PDF Complete Inc - C:\Program Files\PDF Complete\pdfsvc.exe
          O23 - Service: BitDefender Virus Shield (VSSERV) - BitDefender S. R. L. - C:\Program Files\BitDefender\BitDefender 2009\vsserv.exe
          1. Contributeur sécurité
            Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) susceptible d avoir été infectés sans les ouvrir

            # Double clic sur le raccourci UsbFix présent sur ton bureau

            # choisis l'option 2 ( Suppression )

            # Ton bureau disparaitra et le pc redémarrera .

            # Au redémarrage , UsbFix scannera ton pc , laisse travailler l'outil.

            # Ensuite post le rapport UsbFix.txt qui apparaitra avec le bureau .

            # Note : Le rapport UsbFix.txt est sauvegardé a la racine du disque.( C:\UsbFix.txt )

            ( CTRL+A Pour tout selectionner , CTRL+C pour copier et CTRL+V pour coller )

            ______________________
            remets un rapport RSIT ensuite

            a plus
            1. voila le rapport

              ############################## [ UsbFix V3.010 ]

              # User : direction (Administrateurs) # D5800S
              # Update on 19/04/09 by C_XX & Chiquitine29
              # Start at: 18:37:22 | 22/04/2009
              # Website : http://pagesperso-orange.fr/FindyKill.Ad.Remover/

              # Processeur Intel Pentium III Xeon
              # Microsoft Windows XP Professionnel (5.1.2600 32-bit) # Service Pack 3
              # Internet Explorer 7.0.5730.13
              # Windows Firewall Status : Enabled
              # AV : BitDefender Antivirus 12.0 [ Enabled | Updated ]
              # FW : BitDefender Firewall[ (!) Disabled ]12.0

              # C:\ # Disque fixe local # 222,86 Go (161,72 Go free) # NTFS
              # D:\ # Disque fixe local # 10 Go (5,74 Go free) [HP_RECOVERY] # NTFS
              # E:\ # Disque CD-ROM
              # F:\ # Disque amovible
              # G:\ # Disque amovible # 485,73 Mo (467,48 Mo free) # FAT
              # H:\ # Disque amovible
              # I:\ # Disque amovible
              # J:\ # Disque amovible

              ############################## [ Processus actifs ]

              C:\WINDOWS\System32\smss.exe
              C:\WINDOWS\system32\csrss.exe
              C:\WINDOWS\system32\winlogon.exe
              C:\WINDOWS\system32\services.exe
              C:\WINDOWS\system32\lsass.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\system32\svchost.exe
              C:\Program Files\Fichiers communs\BitDefender\BitDefender Update Service\livesrv.exe
              C:\Program Files\BitDefender\BitDefender 2009\vsserv.exe
              C:\WINDOWS\System32\svchost.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\system32\spoolsv.exe
              C:\WINDOWS\system32\svchost.exe
              C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe
              C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
              C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe
              C:\Program Files\Bonjour\mDNSResponder.exe
              C:\Program Files\Fichiers communs\InterVideo\RegMgr\iviRegMgr.exe
              C:\WINDOWS\SMINST\PCAngel.exe
              C:\Program Files\PDF Complete\pdfsvc.exe
              C:\WINDOWS\system32\userinit.exe
              C:\WINDOWS\system32\WgaTray.exe
              C:\WINDOWS\Explorer.EXE
              c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
              c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\system32\SearchIndexer.exe
              C:\WINDOWS\system32\wbem\wmiprvse.exe

              ################## [ Fichiers # Dossiers infectieux ]

              ################## [ Registre # Clés Run infectieuses ]

              # -> Not Found !

              ################## [ Registre # Startup ]

              HKCU_Main: "Local Page"="C:\\WINDOWS\\system32\\blank.htm"
              HKCU_Main: "Search Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"
              HKCU_Main: "Start Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome"
              HKCU_Main: "Window Title"=""
              HKLM_logon: "Userinit"="C:\\WINDOWS\\system32\\userinit.exe,"
              HKLM_logon: "DefaultUserName"=""
              HKLM_logon: "AltDefaultUserName"="direction"
              HKLM_logon: "LegalNoticeCaption"=""
              HKLM_logon: "LegalNoticeText"=""
              HKLM_Run: IgfxTray=C:\WINDOWS\system32\igfxtray.exe
              HKLM_Run: HotKeysCmds=C:\WINDOWS\system32\hkcmd.exe
              HKLM_Run: Persistence=C:\WINDOWS\system32\igfxpers.exe
              HKLM_Run: SoundMAXPnP=C:\Program Files\Analog Devices\Core\smax4pnp.exe
              HKLM_Run: SoundMAX="C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray
              HKLM_Run: PDF Complete=C:\Program Files\PDF Complete\pdfsty.exe
              HKLM_Run: SetRefresh=C:\Program Files\Compaq\SetRefresh\SetRefresh.exe
              HKLM_Run: Recguard=C:\WINDOWS\Sminst\Recguard.exe
              HKLM_Run: Reminder=C:\WINDOWS\Creator\Remind_XP.exe
              HKLM_Run: Scheduler=C:\WINDOWS\SMINST\Scheduler.exe
              HKLM_Run: D-Link AirPlus G=C:\Program Files\D-Link\AirPlus G\AirGCFG.exe
              HKLM_Run: ANIWZCS2Service=C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
              HKLM_Run: SSBkgdUpdate="C:\Program Files\Fichiers communs\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
              HKLM_Run: PaperPort PTD="C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe"
              HKLM_Run: IndexSearch="C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe"
              HKLM_Run: PPort11reminder="C:\Program Files\ScanSoft\PaperPort\Ereg\Ereg.exe" -r "C:\Documents and Settings\All Users\Application Data\ScanSoft\PaperPort\11\Config\Ereg\Ereg.ini
              HKLM_Run: BrMfcWnd=C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe /AUTORUN
              HKLM_Run: WinampAgent="C:\Program Files\Winamp\winampa.exe"
              HKLM_Run: BDAgent="C:\Program Files\BitDefender\BitDefender 2009\bdagent.exe"
              HKLM_Run: BitDefender Antiphishing Helper="C:\Program Files\BitDefender\BitDefender 2009\IEShow.exe"
              HKLM_Run: Adobe Reader Speed Launcher="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
              HKLM_Run: ControlCenter3=C:\Program Files\Brother\ControlCenter3\brctrcen.exe /autorun
              HKLM_Run: AppleSyncNotifier=C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
              HKLM_Run: QuickTime Task="C:\Program Files\QuickTime\qttask.exe" -atboottime
              HKLM_Run: iTunesHelper="C:\Program Files\iTunes\iTunesHelper.exe"
              HKLM_Run: sysldtray=C:\windows\ld08.exe
              HKLM_Run: pp=C:\windows\pp06.exe
              HKLM_Run: sysmstray=C:\windows\mstre18.exe
              HKLM_Run: sysfbtray=C:\windows\freddy41.exe
              HKLM_Run: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents=
              HKCU_Run: CTFMON.EXE=C:\WINDOWS\system32\ctfmon.exe
              HKCU_Run: MsnMsgr="C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
              HKCU_Run: dll32=dll32

              ################## [ Registre # Mountpoints2 ]

              Deleted ! HKCU\Software\Microsoft\....\MountPoints2\D\Shell\AutoRun\command
              Deleted ! HKCU\Software\Microsoft\....\MountPoints2\{1809cea6-d0f5-11dd-89c7-002264a40a06}\Shell\Auto\command
              Deleted ! HKCU\Software\Microsoft\....\MountPoints2\{1809cea6-d0f5-11dd-89c7-002264a40a06}\Shell\AutoRun\command
              Deleted ! HKCU\Software\Microsoft\....\MountPoints2\{1b44f90a-122a-11de-8a08-002264a40a06}\Shell\AutoRun\command

              ################## [ Listing des fichiers présent ]

              C:\ntdetect.com
              C:\boot.ini
              D:\NTDETECT.COM
              D:\Info.exe
              D:\Desktop.ini
              D:\WINBOM.INI
              D:\Folder.htt
              G:\stinger1001546.exe

              ################## [ Vaccination ]

              # C:\autorun.inf -> Folder created by UsbFix.
              # D:\autorun.inf -> Folder created by UsbFix.
              # G:\autorun.inf -> Folder created by UsbFix.

              ################## [ ! Fin du rapport # UsbFix V3.010 ! ]

              et le rapport RSIT

              Logfile of random's system information tool 1.06 (written by random/random)
              Run by direction at 2009-04-22 18:51:18
              Microsoft Windows XP Professionnel Service Pack 3
              System drive C: has 166 GB (73%) free of 228 GB
              Total RAM: 2021 MB (68% free)

              Logfile of Trend Micro HijackThis v2.0.2
              Scan saved at 18:51:25, on 22/04/2009
              Platform: Windows XP SP3 (WinNT 5.01.2600)
              MSIE: Internet Explorer v7.00 (7.00.6000.16827)
              Boot mode: Normal

              Running processes:
              C:\WINDOWS\System32\smss.exe
              C:\WINDOWS\system32\winlogon.exe
              C:\WINDOWS\system32\services.exe
              C:\WINDOWS\system32\lsass.exe
              C:\WINDOWS\system32\svchost.exe
              C:\Program Files\Fichiers communs\BitDefender\BitDefender Update Service\livesrv.exe
              C:\Program Files\BitDefender\BitDefender 2009\vsserv.exe
              C:\WINDOWS\System32\svchost.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\system32\spoolsv.exe
              C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
              C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe
              C:\Program Files\Bonjour\mDNSResponder.exe
              C:\Program Files\Fichiers communs\InterVideo\RegMgr\iviRegMgr.exe
              C:\Program Files\PDF Complete\pdfsvc.exe
              c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\Explorer.EXE
              C:\WINDOWS\system32\SearchIndexer.exe
              C:\WINDOWS\system32\igfxtray.exe
              C:\WINDOWS\system32\hkcmd.exe
              C:\WINDOWS\system32\igfxsrvc.exe
              C:\WINDOWS\system32\igfxpers.exe
              C:\Program Files\Analog Devices\Core\smax4pnp.exe
              C:\Program Files\Analog Devices\SoundMAX\Smax4.exe
              C:\WINDOWS\SMINST\Scheduler.exe
              C:\Program Files\D-Link\AirPlus G\AirGCFG.exe
              C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
              C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
              C:\Program Files\Winamp\winampa.exe
              C:\Program Files\BitDefender\BitDefender 2009\bdagent.exe
              C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
              C:\Program Files\BitDefender\BitDefender 2009\seccenter.exe
              C:\Program Files\iTunes\iTunesHelper.exe
              C:\windows\pp06.exe
              C:\Program Files\Brother\ControlCenter3\brccMCtl.exe
              C:\WINDOWS\system32\ctfmon.exe
              C:\WINDOWS\system32\dll32.exe
              C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
              C:\Program Files\Windows Desktop Search\WindowsSearch.exe
              C:\WINDOWS\system32\wuauclt.exe
              C:\Program Files\iPod\bin\iPodService.exe
              C:\Program Files\Internet Explorer\iexplore.exe
              C:\WINDOWS\system32\SearchProtocolHost.exe
              C:\Documents and Settings\direction\Bureau\RSIT.exe
              C:\Program Files\Trend Micro\HijackThis\direction.exe
              \?\C:\WINDOWS\system32\WBEM\WMIADAP.EXE

              R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://fr.yahoo.com/
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
              R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
              R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=localhost:7171
              R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local;<local>
              R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
              O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
              O2 - BHO: 219198 helper - {5B452B01-12C9-4286-81D9-2308AEB3CD94} - C:\WINDOWS\system32\219198\219198.dll
              O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
              O2 - BHO: AOL Toolbar BHO - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll
              O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
              O2 - BHO: 179223 helper - {B3FA56CF-B3F9-4328-9802-CFAACEA86646} - C:\WINDOWS\system32\179223\179223.dll
              O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file)
              O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll
              O3 - Toolbar: BitDefender Toolbar - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - C:\Program Files\BitDefender\BitDefender 2009\IEToolbar.dll
              O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
              O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
              O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
              O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
              O4 - HKLM\..\Run: [SoundMAX] "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray
              O4 - HKLM\..\Run: [PDF Complete] C:\Program Files\PDF Complete\pdfsty.exe
              O4 - HKLM\..\Run: [SetRefresh] C:\Program Files\Compaq\SetRefresh\SetRefresh.exe
              O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\Sminst\Recguard.exe
              O4 - HKLM\..\Run: [Reminder] C:\WINDOWS\Creator\Remind_XP.exe
              O4 - HKLM\..\Run: [Scheduler] C:\WINDOWS\SMINST\Scheduler.exe
              O4 - HKLM\..\Run: [D-Link AirPlus G] C:\Program Files\D-Link\AirPlus G\AirGCFG.exe
              O4 - HKLM\..\Run: [ANIWZCS2Service] C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
              O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Fichiers communs\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
              O4 - HKLM\..\Run: [PaperPort PTD] "C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe"
              O4 - HKLM\..\Run: [IndexSearch] "C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe"
              O4 - HKLM\..\Run: [PPort11reminder] "C:\Program Files\ScanSoft\PaperPort\Ereg\Ereg.exe" -r "C:\Documents and Settings\All Users\Application Data\ScanSoft\PaperPort\11\Config\Ereg\Ereg.ini
              O4 - HKLM\..\Run: [BrMfcWnd] C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe /AUTORUN
              O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
              O4 - HKLM\..\Run: [BDAgent] "C:\Program Files\BitDefender\BitDefender 2009\bdagent.exe"
              O4 - HKLM\..\Run: [BitDefender Antiphishing Helper] "C:\Program Files\BitDefender\BitDefender 2009\IEShow.exe"
              O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
              O4 - HKLM\..\Run: [ControlCenter3] C:\Program Files\Brother\ControlCenter3\brctrcen.exe /autorun
              O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
              O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
              O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
              O4 - HKLM\..\Run: [sysldtray] C:\windows\ld08.exe
              O4 - HKLM\..\Run: [pp] C:\windows\pp06.exe
              O4 - HKLM\..\Run: [sysmstray] C:\windows\mstre18.exe
              O4 - HKLM\..\Run: [sysfbtray] C:\windows\freddy41.exe
              O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
              O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
              O4 - HKCU\..\Run: [dll32] dll32
              O4 - HKCU\..\RunOnce: [Shockwave Updater] C:\WINDOWS\system32\Adobe\SHOCKW~1\SWHELP~1.EXE -Update -1103471 -"Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 1.1.4322; .NET CLR 2.0.50727)" -"https://www.voodoo.com/?domain=absoluflash.com&http_host=www.absoluflash.com"
              O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
              O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
              O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
              O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
              O4 - Global Startup: Logiciel Kodak EasyShare.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
              O4 - Global Startup: Windows Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
              O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
              O8 - Extra context menu item: &Recherche AOL Toolbar - C:\Documents and Settings\All Users\Application Data\AOL\ieToolbar\resources\fr-FR\local\search.html
              O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
              O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
              O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
              O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll
              O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
              O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
              O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
              O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
              O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
              O14 - IERESET.INF: START_PAGE_URL=https://www8.hp.com/fr/fr/home.html
              O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/...
              O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
              O17 - HKLM\System\CCS\Services\Tcpip\..\{100FBF70-59C7-488E-AEC3-AB1EB6B61B8A}: NameServer = 193.252.19.3,193.252.19.4
              O17 - HKLM\System\CCS\Services\Tcpip\..\{97873F82-E1EA-4CDA-A765-B94D23476B92}: NameServer = 192.168.0.254
              O23 - Service: McAfee Application Installer Cleanup (0146531225189889) (0146531225189889mcinstcleanup) - Unknown owner - C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\014653~1.EXE (file missing)
              O23 - Service: ANIWZCSd Service (ANIWZCSdService) - Alpha Networks Inc. - C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe
              O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
              O23 - Service: BitDefender Arrakis Server (Arrakis3) - BitDefender S.R.L. https://www.bitdefender.fr/ - C:\Program Files\Fichiers communs\BitDefender\BitDefender Arrakis Server\bin\Arrakis3.exe
              O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
              O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
              O23 - Service: IviRegMgr - InterVideo - C:\Program Files\Fichiers communs\InterVideo\RegMgr\iviRegMgr.exe
              O23 - Service: BitDefender Desktop Update Service (LIVESRV) - BitDefender SRL - C:\Program Files\Fichiers communs\BitDefender\BitDefender Update Service\livesrv.exe
              O23 - Service: PC Angel (PCA) - SoftThinks - C:\WINDOWS\SMINST\PCAngel.exe
              O23 - Service: PDF Document Manager (pdfcDispatcher) - PDF Complete Inc - C:\Program Files\PDF Complete\pdfsvc.exe
              O23 - Service: BitDefender Virus Shield (VSSERV) - BitDefender S. R. L. - C:\Program Files\BitDefender\BitDefender 2009\vsserv.exe
              1. Contributeur sécurité
                télécharge OTMoveIt
                http://oldtimer.geekstogo.com/OTMoveIt3.exe (de Old_Timer) sur ton Bureau.

                double-clique sur OTMoveIt.exe pour le lancer.
                copie la liste qui se trouve en citation ci-dessous,
                et colle-la dans le cadre de gauche de OTMoveIt :Paste instruction for items to be moved.
                (attention bien mettre :files)

                :processes
                explorer.exe
                :files
                C:\windows\ld08.exe
                C:\windows\pp06.exe
                C:\windows\mstre18.exe
                C:\windows\freddy41.exe
                C:\WINDOWS\system32\219198\219198.dll
                C:\WINDOWS\system32\dll32.exe
                C:\WINDOWS\system32\219198
                C:\WINDOWS\system32\179223\179223.dll
                C:\WINDOWS\system32\179223
                :reg
                [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5B452B01-12C9-4286-81D9-2308AEB3CD94}]
                [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7E853D72-626A-48EC-A868-BA8D5E23E045}]
                [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B3FA56CF-B3F9-4328-9802-CFAACEA86646}]
                [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
                "sysldtray"=-
                "pp"=-
                "sysmstray"=-
                "sysfbtray"=-
                [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
                "dll32"=-
                :commands
                [purity]
                [emptytemp]
                [start explorer]

                clique sur MoveIt! pour lancer la suppression.
                le résultat apparaitra dans le cadre "Results".
                clique sur Exit pour fermer.
                poste le rapport situé dans C:\_OTMoveIt\MovedFiles.

                il te sera peut-être demander de redémarrer le pc pour achever la suppression.si c'est le cas accepte par Yes.

                ___________________________

                scan avec malwarebyte , fais un scan rapide et colle le rapport obtenu et vire ce qui est trouvé:

                https://www.malekal.com/tutoriel-malwarebyte-anti-malware/­

                ______________________

                mettre à jour adobe reader puis supprimer les anciennes version via le panneau de configuration
                https://acrobat.adobe.com/fr/fr/acrobat/pdf-reader.html

                _____________

                Mettre a jour java:
                https://javara.fr.malavida.com/

                Télécharge JavaRa.zip de Paul 'Prm753' McLain et Fred de Vries.
                Décompresse le fichier sur ton bureau (clique droit > Extraire tout.)
                Double-clique sur le répertoire JavaRa obtenu.
                Puis double-clique sur le fichier JavaRa.exe (le .exe peut ne pas s'afficher)
                Clique sur Search For Updates.
                Sélectionne Update Using jucheck.exe puis clique sur Search.
                Autorise le processus à se connecter s'il te le demande, clique sur Install et suis les instructions d'installation. Cela prendra quelques minutes.
                Quand l'installation est terminée, revient à l'écran de JavaRa et clique sur Remove Older Versions.
                Clique sur Oui pour confirmer. L'outil va travailler, clique ensuite sur Ok, puis une deuxième fois sur Ok.
                Un rapport va s'ouvrir, copie-colle le dans ta prochaine réponse.
                Note : le rapport se trouve aussi à la racine de la partition système, en général C:\ sous le nom JavaRa.log
                (c:\JavaRa.log)
                Ferme l'application.

                si cela ne fonctionne pas

                https://www.java.com/fr/download/windows_manual.jsp?locale=fr&host=www.java.com:80

                tu peux désinstaller les vieilles versions.
                _______________________

                remets un rapport RSIT pour verifier
                1. Re

                  apres avoir utilise Moveit et redemarré impossible d'aller sur le net. Je te reponds d'un autre ordinateur

                  Je reprends le chmilbick dès demain matin et te posterai les info que tu me demandes

                  Merci bcp de ton aide précieuse!!!
                  1. Contributeur sécurité
                    pour remettre le net
                    essaye dans l'ordre

                    1/
                    # Cliquez sur le bouton Démarrer.
                    # Cliquez sur l'option de menu Paramètres.
                    # Cliquez sur l'option Panneau de configuration.
                    # Après l'ouverture du Panneau de configuration, faites un double clic sur l'icône Connexions réseau. Si votre Panneau de configuration est paramétré pour un affichage en catégories, faites un double clic sur Connexions réseau et Internet puis cliquez sur Connexions réseau tout en bas.
                    # Vous verrez alors une liste de toutes les connexions réseau disponibles. Repérez la connexion vers votre adaptateur Sans Fil ou Réseau local et faites un clic droit dessus.
                    # Cliquez simplement sur l'option de menu Réparer.

                    2/
                    utilise lspfix
                    https://www.01net.com/telecharger/windows/Utilitaire/reseau/fiches/33379.html
                    http://lanceyien-info.com/index.php?page=utilitaires#lspfix
                    http://www.zdnet.fr/telecharger/windows/fiche/0,39021313,39138667s,00.htm

                    3/
                    -Télécharge cet outil d'ici:
                    WinSockFix
                    http://www.softpedia.com/progDownload/WinS...load-15337.html
                    (prends le deuxieme miroir)
                    -Une fois téléchargé,tu le lances

                    -Tu cliques sur"ReG-Backup" pour créer une sauvegarde du registre,dans un dossier de ton choix.

                    -Une fois la sauvegarde éffectuée,clique sur "Fix", au méssage "WinsockFix will now attempt to Repair your connection" tu reponds par "OUI"

                    -Il va travailler,tu le laisse faire,à la fin des corrections tu auras le méssage suivant"Repair completed Please Reboot", tu cliques sur "OK"

                    -Le PC va redémarrer,

                    -Communique les résultats.

                    ___________________

                    4/
                    erreur 1068 - Suite à infection virale de votre ordinateur avec un virus du type "bagle" ou "beagle" ...

                    Vous n'arrivez plus a vous connecter avec votre wifi. Si vous allez dans les outils administration sur la page "services" pour activer "configuration automatique sans fil" vous avez l'erreur 1068.

                    Si c'est votre cas et que vous vous etes arraché les cheveux, voici la solution:

                    Vous devez aller dans la base de registre avec regedit ou autre.

                    1. Demarrer > executer > Tapez : "regedit" en ok

                    2. Allez sur HKEY Local Machine > system > CurrentControlSet > Services > Ndisuio

                    Dans cette clé il y a une entrée nommée "START", double cliquez dessus. Cette entrée doit être 3 pour que le protocole NDIS E/S demarre correctement.

                    Un virus comme "bagle / Beagle" change cette entrée et la met sur 4 (disable) et cause le probleme que vous avez.

                    Reboutez ensuite votre PC et tout devrait rentrer dans l'ordre.

                    5/ utilise ZEB RESTORE

                    http://telechargement.zebulon.fr/zeb-restore.html

                    ____________

                    6/
                    ou repare windows

                    http://www.informatruc.com/reparer-windows-xp/

                    _____________
                    7/ restaure ton ordi avant l'utilisation de otmovit puis refais le message 7 en sautant la procedure otmovit
                    http://www.infoprat.net/astuces/windows2k_xp/astuces/divers_004.php
                    1. Alors voilà le resultat

                      J'ai fais comme tu m'as dit, je n'ai toujours pas internet. IE cherche a detecter les paramètres proxy, puis se connecte et au final ne peux lancer la page. Ce qu'il y a de surprenant c'est que MSN fonctionne tres bien.
                      1. Autre chose j'avais egalement fait un scan avec malwarebit dont voici le resultat que j'avais oublié de posté

                        Malwarebytes' Anti-Malware 1.36
                        Version de la base de données: 1945
                        Windows 5.1.2600 Service Pack 3

                        23/04/2009 08:24:16
                        mbam-log-2009-04-23 (08-24-12).txt

                        Type de recherche: Examen rapide
                        Eléments examinés: 81530
                        Temps écoulé: 2 minute(s), 52 second(s)

                        Processus mémoire infecté(s): 0
                        Module(s) mémoire infecté(s): 0
                        Clé(s) du Registre infectée(s): 0
                        Valeur(s) du Registre infectée(s): 4
                        Elément(s) de données du Registre infecté(s): 0
                        Dossier(s) infecté(s): 0
                        Fichier(s) infecté(s): 9

                        Processus mémoire infecté(s):
                        (Aucun élément nuisible détecté)

                        Module(s) mémoire infecté(s):
                        (Aucun élément nuisible détecté)

                        Clé(s) du Registre infectée(s):
                        (Aucun élément nuisible détecté)

                        Valeur(s) du Registre infectée(s):
                        HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\sysmstray (Trojan.KoobFace) -> No action taken.
                        HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\sysfbtray (Trojan.KoobFace) -> No action taken.
                        HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\pp (Backdoor.Bot) -> No action taken.
                        HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\sysldtray (Backdoor.Bot) -> No action taken.

                        Elément(s) de données du Registre infecté(s):
                        (Aucun élément nuisible détecté)

                        Dossier(s) infecté(s):
                        (Aucun élément nuisible détecté)

                        Fichier(s) infecté(s):
                        C:\WINDOWS\msmark2.dat (Trojan.KoobFace) -> No action taken.
                        C:\WINDOWS\t55ft2804f44.dat (Trojan.KoobFace) -> No action taken.
                        C:\WINDOWS\t55ft2832f44.dat (Trojan.KoobFace) -> No action taken.
                        C:\WINDOWS\t55ft3021f44.dat (Trojan.KoobFace) -> No action taken.
                        C:\WINDOWS\t55ft3242f44.dat (Trojan.KoobFace) -> No action taken.
                        C:\WINDOWS\st_1240404967.exe (Backdoor.Bot) -> No action taken.
                        C:\WINDOWS\st_1240413104.exe (Backdoor.Bot) -> No action taken.
                        C:\WINDOWS\st_1240418165.exe (Backdoor.Bot) -> No action taken.
                        C:\WINDOWS\st_1240437326.exe (Backdoor.Bot) -> No action taken.
                        1. Pour mon probleme internet, je suppose que cela vient du fait que IE est infesté, car j'ai installé Mozilla Firefox et internet fonctionne tres bien maintenant
                          1. voila le resultat du scan panda

                            ;***********************************************************************************************************************************************************************************
                            ANALYSIS: 2009-04-23 11:51:50
                            PROTECTIONS: 1
                            MALWARE: 3
                            SUSPECTS: 0
                            ;***********************************************************************************************************************************************************************************
                            PROTECTIONS
                            Description Version Active Updated
                            ;===================================================================================================================================================================================
                            BitDefender Antivirus 12.0 Yes Yes
                            ;===================================================================================================================================================================================
                            MALWARE
                            Id Description Type Active Severity Disinfectable Disinfected Location
                            ;===================================================================================================================================================================================
                            00139061 Cookie/Doubleclick TrackingCookie No 0 Yes No C:\Documents and Settings\Administrateur\Cookies\administrateur@doubleclick[1].txt
                            03074964 Trj/CI.A Virus/Trojan No 0 Yes No C:\_OTMoveIt\MovedFiles\04222009_190409\windows\ld08.exe
                            03074964 Trj/CI.A Virus/Trojan No 0 Yes No C:\_OTMoveIt\MovedFiles\04222009_190409\windows\system32\dll32.exe
                            05428699 W32/Boface.C.worm Virus/Worm No 0 Yes No C:\_OTMoveIt\MovedFiles\04222009_190409\windows\pp06.exe
                            ;===================================================================================================================================================================================
                            SUSPECTS
                            Sent Location \
                            ;===================================================================================================================================================================================
                            ;===================================================================================================================================================================================
                            VULNERABILITIES
                            Id Severity Description \
                            ;===================================================================================================================================================================================
                            ;===================================================================================================================================================================================

                            Puis voici le rapport RSIT

                            Logfile of random's system information tool 1.06 (written by random/random)
                            Run by direction at 2009-04-23 11:52:35
                            Microsoft Windows XP Professionnel Service Pack 3
                            System drive C: has 167 GB (73%) free of 228 GB
                            Total RAM: 2021 MB (61% free)

                            Logfile of Trend Micro HijackThis v2.0.2
                            Scan saved at 11:52:39, on 23/04/2009
                            Platform: Windows XP SP3 (WinNT 5.01.2600)
                            MSIE: Internet Explorer v7.00 (7.00.6000.16827)
                            Boot mode: Normal

                            Running processes:
                            C:\WINDOWS\System32\smss.exe
                            C:\WINDOWS\system32\winlogon.exe
                            C:\WINDOWS\system32\services.exe
                            C:\WINDOWS\system32\lsass.exe
                            C:\WINDOWS\system32\svchost.exe
                            C:\Program Files\Fichiers communs\BitDefender\BitDefender Update Service\livesrv.exe
                            C:\Program Files\BitDefender\BitDefender 2009\vsserv.exe
                            C:\WINDOWS\System32\svchost.exe
                            C:\WINDOWS\system32\svchost.exe
                            C:\WINDOWS\system32\spoolsv.exe
                            C:\WINDOWS\Explorer.EXE
                            C:\WINDOWS\system32\igfxtray.exe
                            C:\WINDOWS\system32\hkcmd.exe
                            C:\WINDOWS\system32\igfxpers.exe
                            C:\Program Files\Analog Devices\Core\smax4pnp.exe
                            C:\WINDOWS\system32\igfxsrvc.exe
                            C:\Program Files\Analog Devices\SoundMAX\Smax4.exe
                            C:\WINDOWS\SMINST\Scheduler.exe
                            C:\Program Files\D-Link\AirPlus G\AirGCFG.exe
                            C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
                            C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
                            C:\Program Files\Winamp\winampa.exe
                            C:\Program Files\BitDefender\BitDefender 2009\bdagent.exe
                            C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                            C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe
                            C:\Program Files\Bonjour\mDNSResponder.exe
                            C:\Program Files\Fichiers communs\InterVideo\RegMgr\iviRegMgr.exe
                            C:\Program Files\iTunes\iTunesHelper.exe
                            C:\Program Files\PDF Complete\pdfsvc.exe
                            C:\WINDOWS\system32\ctfmon.exe
                            C:\Program Files\Brother\ControlCenter3\brccMCtl.exe
                            C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
                            C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
                            C:\Program Files\BitDefender\BitDefender 2009\seccenter.exe
                            C:\Program Files\Windows Desktop Search\WindowsSearch.exe
                            c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
                            C:\WINDOWS\system32\svchost.exe
                            C:\WINDOWS\system32\SearchIndexer.exe
                            C:\Program Files\iPod\bin\iPodService.exe
                            C:\Program Files\Windows Live\Messenger\usnsvc.exe
                            C:\Program Files\Mozilla Firefox\firefox.exe
                            C:\WINDOWS\system32\SearchProtocolHost.exe
                            C:\WINDOWS\system32\NOTEPAD.EXE
                            C:\Documents and Settings\direction\Bureau\Utilitaire pour te sauver de la merde\RSIT.exe
                            C:\Program Files\Trend Micro\HijackThis\direction.exe

                            R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                            R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
                            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                            R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
                            R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
                            R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
                            R1 - HKCU\Software\Microsoft\Internet Explorer\Main,First Home Page = https://support.microsoft.com/en-US/topic/internet-explorer-downloads-d49e1f0d-571c-9a7b-d97e-be248806ca70
                            R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=localhost:7171
                            R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local;<local>
                            R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                            O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
                            O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
                            O2 - BHO: AOL Toolbar BHO - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll
                            O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                            O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file)
                            O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll
                            O3 - Toolbar: BitDefender Toolbar - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - C:\Program Files\BitDefender\BitDefender 2009\IEToolbar.dll
                            O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
                            O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
                            O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
                            O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
                            O4 - HKLM\..\Run: [SoundMAX] "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray
                            O4 - HKLM\..\Run: [PDF Complete] C:\Program Files\PDF Complete\pdfsty.exe
                            O4 - HKLM\..\Run: [SetRefresh] C:\Program Files\Compaq\SetRefresh\SetRefresh.exe
                            O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\Sminst\Recguard.exe
                            O4 - HKLM\..\Run: [Reminder] C:\WINDOWS\Creator\Remind_XP.exe
                            O4 - HKLM\..\Run: [Scheduler] C:\WINDOWS\SMINST\Scheduler.exe
                            O4 - HKLM\..\Run: [D-Link AirPlus G] C:\Program Files\D-Link\AirPlus G\AirGCFG.exe
                            O4 - HKLM\..\Run: [ANIWZCS2Service] C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
                            O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Fichiers communs\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
                            O4 - HKLM\..\Run: [PaperPort PTD] "C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe"
                            O4 - HKLM\..\Run: [IndexSearch] "C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe"
                            O4 - HKLM\..\Run: [PPort11reminder] "C:\Program Files\ScanSoft\PaperPort\Ereg\Ereg.exe" -r "C:\Documents and Settings\All Users\Application Data\ScanSoft\PaperPort\11\Config\Ereg\Ereg.ini
                            O4 - HKLM\..\Run: [BrMfcWnd] C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe /AUTORUN
                            O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
                            O4 - HKLM\..\Run: [BDAgent] "C:\Program Files\BitDefender\BitDefender 2009\bdagent.exe"
                            O4 - HKLM\..\Run: [BitDefender Antiphishing Helper] "C:\Program Files\BitDefender\BitDefender 2009\IEShow.exe"
                            O4 - HKLM\..\Run: [ControlCenter3] C:\Program Files\Brother\ControlCenter3\brctrcen.exe /autorun
                            O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
                            O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                            O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
                            O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
                            O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
                            O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
                            O4 - HKCU\..\RunOnce: [Shockwave Updater] C:\WINDOWS\system32\Adobe\SHOCKW~1\SWHELP~1.EXE -Update -1103471 -"Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 1.1.4322; .NET CLR 2.0.50727)" -"https://www.voodoo.com/?domain=absoluflash.com&http_host=www.absoluflash.com"
                            O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
                            O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
                            O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
                            O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
                            O4 - Global Startup: Logiciel Kodak EasyShare.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
                            O4 - Global Startup: Windows Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
                            O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
                            O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
                            O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
                            O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll
                            O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
                            O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                            O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                            O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                            O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                            O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
                            O14 - IERESET.INF: START_PAGE_URL=https://www8.hp.com/fr/fr/home.html
                            O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/...
                            O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
                            O23 - Service: McAfee Application Installer Cleanup (0146531225189889) (0146531225189889mcinstcleanup) - Unknown owner - C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\014653~1.EXE (file missing)
                            O23 - Service: ANIWZCSd Service (ANIWZCSdService) - Alpha Networks Inc. - C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe
                            O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                            O23 - Service: BitDefender Arrakis Server (Arrakis3) - BitDefender S.R.L. https://www.bitdefender.fr/ - C:\Program Files\Fichiers communs\BitDefender\BitDefender Arrakis Server\bin\Arrakis3.exe
                            O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
                            O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
                            O23 - Service: IviRegMgr - InterVideo - C:\Program Files\Fichiers communs\InterVideo\RegMgr\iviRegMgr.exe
                            O23 - Service: BitDefender Desktop Update Service (LIVESRV) - BitDefender SRL - C:\Program Files\Fichiers communs\BitDefender\BitDefender Update Service\livesrv.exe
                            O23 - Service: PC Angel (PCA) - SoftThinks - C:\WINDOWS\SMINST\PCAngel.exe
                            O23 - Service: PDF Document Manager (pdfcDispatcher) - PDF Complete Inc - C:\Program Files\PDF Complete\pdfsvc.exe
                            O23 - Service: BitDefender Virus Shield (VSSERV) - BitDefender S. R. L. - C:\Program Files\BitDefender\BitDefender 2009\vsserv.exe
                            1. voici le resultat de panda scan

                              ;***********************************************************************************************************************************************************************************
                              ANALYSIS: 2009-04-23 11:51:50
                              PROTECTIONS: 1
                              MALWARE: 3
                              SUSPECTS: 0
                              ;***********************************************************************************************************************************************************************************
                              PROTECTIONS
                              Description Version Active Updated
                              ;===================================================================================================================================================================================
                              BitDefender Antivirus 12.0 Yes Yes
                              ;===================================================================================================================================================================================
                              MALWARE
                              Id Description Type Active Severity Disinfectable Disinfected Location
                              ;===================================================================================================================================================================================
                              00139061 Cookie/Doubleclick TrackingCookie No 0 Yes No C:\Documents and Settings\Administrateur\Cookies\administrateur@doubleclick[1].txt
                              03074964 Trj/CI.A Virus/Trojan No 0 Yes No C:\_OTMoveIt\MovedFiles\04222009_190409\windows\ld08.exe
                              03074964 Trj/CI.A Virus/Trojan No 0 Yes No C:\_OTMoveIt\MovedFiles\04222009_190409\windows\system32\dll32.exe
                              05428699 W32/Boface.C.worm Virus/Worm No 0 Yes No C:\_OTMoveIt\MovedFiles\04222009_190409\windows\pp06.exe
                              ;===================================================================================================================================================================================
                              SUSPECTS
                              Sent Location \
                              ;===================================================================================================================================================================================
                              ;===================================================================================================================================================================================
                              VULNERABILITIES
                              Id Severity Description \
                              ;===================================================================================================================================================================================
                              ;===================================================================================================================================================================================

                              et le resultat de rsit

                              Logfile of random's system information tool 1.06 (written by random/random)
                              Run by direction at 2009-04-23 12:01:01
                              Microsoft Windows XP Professionnel Service Pack 3
                              System drive C: has 167 GB (73%) free of 228 GB
                              Total RAM: 2021 MB (63% free)

                              Logfile of Trend Micro HijackThis v2.0.2
                              Scan saved at 12:01:07, on 23/04/2009
                              Platform: Windows XP SP3 (WinNT 5.01.2600)
                              MSIE: Internet Explorer v7.00 (7.00.6000.16827)
                              Boot mode: Normal

                              Running processes:
                              C:\WINDOWS\System32\smss.exe
                              C:\WINDOWS\system32\winlogon.exe
                              C:\WINDOWS\system32\services.exe
                              C:\WINDOWS\system32\lsass.exe
                              C:\WINDOWS\system32\svchost.exe
                              C:\Program Files\Fichiers communs\BitDefender\BitDefender Update Service\livesrv.exe
                              C:\Program Files\BitDefender\BitDefender 2009\vsserv.exe
                              C:\WINDOWS\System32\svchost.exe
                              C:\WINDOWS\system32\svchost.exe
                              C:\WINDOWS\system32\spoolsv.exe
                              C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                              C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe
                              C:\Program Files\Bonjour\mDNSResponder.exe
                              C:\Program Files\Fichiers communs\InterVideo\RegMgr\iviRegMgr.exe
                              C:\Program Files\PDF Complete\pdfsvc.exe
                              c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
                              C:\WINDOWS\system32\svchost.exe
                              C:\WINDOWS\system32\SearchIndexer.exe
                              C:\WINDOWS\Explorer.EXE
                              C:\WINDOWS\system32\igfxtray.exe
                              C:\WINDOWS\system32\igfxsrvc.exe
                              C:\WINDOWS\system32\hkcmd.exe
                              C:\WINDOWS\system32\igfxpers.exe
                              C:\Program Files\Analog Devices\Core\smax4pnp.exe
                              C:\Program Files\Analog Devices\SoundMAX\Smax4.exe
                              C:\WINDOWS\system32\wuauclt.exe
                              C:\WINDOWS\SMINST\Scheduler.exe
                              C:\Program Files\D-Link\AirPlus G\AirGCFG.exe
                              C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
                              C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
                              C:\Program Files\Winamp\winampa.exe
                              C:\Program Files\BitDefender\BitDefender 2009\bdagent.exe
                              C:\Program Files\Brother\ControlCenter3\brccMCtl.exe
                              C:\Program Files\BitDefender\BitDefender 2009\seccenter.exe
                              C:\Program Files\iTunes\iTunesHelper.exe
                              C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe
                              C:\WINDOWS\system32\ctfmon.exe
                              C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
                              C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
                              C:\Program Files\Windows Desktop Search\WindowsSearch.exe
                              C:\WINDOWS\system32\SearchProtocolHost.exe
                              C:\Program Files\iPod\bin\iPodService.exe
                              C:\WINDOWS\system32\SearchProtocolHost.exe
                              C:\Program Files\Mozilla Firefox\firefox.exe
                              C:\Documents and Settings\direction\Bureau\Utilitaire pour te sauver de la merde\RSIT.exe
                              C:\Program Files\Trend Micro\HijackThis\direction.exe

                              R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                              R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
                              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                              R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
                              R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
                              R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
                              R1 - HKCU\Software\Microsoft\Internet Explorer\Main,First Home Page = https://support.microsoft.com/en-US/topic/internet-explorer-downloads-d49e1f0d-571c-9a7b-d97e-be248806ca70
                              R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=localhost:7171
                              R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local;<local>
                              R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                              O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
                              O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
                              O2 - BHO: AOL Toolbar BHO - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll
                              O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                              O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file)
                              O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll
                              O3 - Toolbar: BitDefender Toolbar - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - C:\Program Files\BitDefender\BitDefender 2009\IEToolbar.dll
                              O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
                              O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
                              O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
                              O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
                              O4 - HKLM\..\Run: [SoundMAX] "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray
                              O4 - HKLM\..\Run: [PDF Complete] C:\Program Files\PDF Complete\pdfsty.exe
                              O4 - HKLM\..\Run: [SetRefresh] C:\Program Files\Compaq\SetRefresh\SetRefresh.exe
                              O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\Sminst\Recguard.exe
                              O4 - HKLM\..\Run: [Reminder] C:\WINDOWS\Creator\Remind_XP.exe
                              O4 - HKLM\..\Run: [Scheduler] C:\WINDOWS\SMINST\Scheduler.exe
                              O4 - HKLM\..\Run: [D-Link AirPlus G] C:\Program Files\D-Link\AirPlus G\AirGCFG.exe
                              O4 - HKLM\..\Run: [ANIWZCS2Service] C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
                              O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Fichiers communs\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
                              O4 - HKLM\..\Run: [PaperPort PTD] "C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe"
                              O4 - HKLM\..\Run: [IndexSearch] "C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe"
                              O4 - HKLM\..\Run: [PPort11reminder] "C:\Program Files\ScanSoft\PaperPort\Ereg\Ereg.exe" -r "C:\Documents and Settings\All Users\Application Data\ScanSoft\PaperPort\11\Config\Ereg\Ereg.ini
                              O4 - HKLM\..\Run: [BrMfcWnd] C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe /AUTORUN
                              O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
                              O4 - HKLM\..\Run: [BDAgent] "C:\Program Files\BitDefender\BitDefender 2009\bdagent.exe"
                              O4 - HKLM\..\Run: [BitDefender Antiphishing Helper] "C:\Program Files\BitDefender\BitDefender 2009\IEShow.exe"
                              O4 - HKLM\..\Run: [ControlCenter3] C:\Program Files\Brother\ControlCenter3\brctrcen.exe /autorun
                              O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
                              O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                              O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
                              O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
                              O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
                              O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
                              O4 - HKCU\..\RunOnce: [Shockwave Updater] C:\WINDOWS\system32\Adobe\SHOCKW~1\SWHELP~1.EXE -Update -1103471 -"Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 1.1.4322; .NET CLR 2.0.50727)" -"https://www.voodoo.com/?domain=absoluflash.com&http_host=www.absoluflash.com"
                              O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
                              O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
                              O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
                              O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
                              O4 - Global Startup: Logiciel Kodak EasyShare.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
                              O4 - Global Startup: Windows Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
                              O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
                              O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
                              O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
                              O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll
                              O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
                              O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                              O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                              O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                              O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                              O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
                              O14 - IERESET.INF: START_PAGE_URL=https://www8.hp.com/fr/fr/home.html
                              O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/...
                              O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
                              O23 - Service: McAfee Application Installer Cleanup (0146531225189889) (0146531225189889mcinstcleanup) - Unknown owner - C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\014653~1.EXE (file missing)
                              O23 - Service: ANIWZCSd Service (ANIWZCSdService) - Alpha Networks Inc. - C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe
                              O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                              O23 - Service: BitDefender Arrakis Server (Arrakis3) - BitDefender S.R.L. https://www.bitdefender.fr/ - C:\Program Files\Fichiers communs\BitDefender\BitDefender Arrakis Server\bin\Arrakis3.exe
                              O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
                              O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
                              O23 - Service: IviRegMgr - InterVideo - C:\Program Files\Fichiers communs\InterVideo\RegMgr\iviRegMgr.exe
                              O23 - Service: BitDefender Desktop Update Service (LIVESRV) - BitDefender SRL - C:\Program Files\Fichiers communs\BitDefender\BitDefender Update Service\livesrv.exe
                              O23 - Service: PC Angel (PCA) - SoftThinks - C:\WINDOWS\SMINST\PCAngel.exe
                              O23 - Service: PDF Document Manager (pdfcDispatcher) - PDF Complete Inc - C:\Program Files\PDF Complete\pdfsvc.exe
                              O23 - Service: BitDefender Virus Shield (VSSERV) - BitDefender S. R. L. - C:\Program Files\BitDefender\BitDefender 2009\vsserv.exe
                              1. Contributeur sécurité
                                Télécharge OTMoveIt
                                http://oldtimer.geekstogo.com/OTMoveIt3.exe (de Old_Timer) sur ton Bureau.

                                double-clique sur OTMoveIt.exe pour le lancer.
                                copie la liste qui se trouve en citation ci-dessous,
                                et colle-la dans le cadre de gauche de OTMoveIt :Paste instruction for items to be moved.
                                (attention bien mettre :files)

                                :processes
                                explorer.exe
                                :files
                                C:\dll32.bat
                                :commands
                                [purity]
                                [emptytemp]
                                [start explorer]

                                clique sur MoveIt! pour lancer la suppression.
                                le résultat apparaitra dans le cadre "Results".
                                clique sur Exit pour fermer.
                                poste le rapport situé dans C:\_OTMoveIt\MovedFiles.

                                il te sera peut-être demander de redémarrer le pc pour achever la suppression.si c'est le cas accepte par Yes.

                                _____________________

                                vire ce qui est en quarantaine dans malwarebyte que tu gardera en complement de bitdefender
                                _____________________

                                désactive ta restauration puis redemarre ton ordi puis réactive la:

                                http://service1.symantec.com/support/inter/tsgeninfointl.Nsf/fr_docid/20020830101856924
                                ______________________

                                mettre à jour adobe reader
                                https://acrobat.adobe.com/fr/fr/acrobat/pdf-reader.html

                                Mettre a jour java:

                                Télécharge JavaRa.zip de Paul 'Prm753' McLain et Fred de Vries.
                                Décompresse le fichier sur ton bureau (clique droit > Extraire tout.)
                                Double-clique sur le répertoire JavaRa obtenu.
                                Puis double-clique sur le fichier JavaRa.exe (le .exe peut ne pas s'afficher)
                                Clique sur Search For Updates.
                                Sélectionne Update Using jucheck.exe puis clique sur Search.
                                Autorise le processus à se connecter s'il te le demande, clique sur Install et suis les instructions d'installation. Cela prendra quelques minutes.
                                Quand l'installation est terminée, revient à l'écran de JavaRa et clique sur Remove Older Versions.
                                Clique sur Oui pour confirmer. L'outil va travailler, clique ensuite sur Ok, puis une deuxième fois sur Ok.
                                Un rapport va s'ouvrir, copie-colle le dans ta prochaine réponse.
                                Note : le rapport se trouve aussi à la racine de la partition système, en général C:\ sous le nom JavaRa.log
                                (c:\JavaRa.log)
                                Ferme l'application.

                                si cela ne fonctionne pas

                                https://www.java.com/fr/download/windows_manual.jsp?locale=fr&host=www.java.com:80

                                tu peux désinstaller les vieilles versions.

                                ____________________

                                lance tool cleaner pour virer ce qui a été utilisé et colle le rapport

                                http://www.commentcamarche.net/telecharger/telecharger 34055291 toolscleaner
                                ___________________________

                                voila

                                encore des soucis avec ton pc?
                                1. Voila le premier post

                                  ========== PROCESSES ==========
                                  Process explorer.exe killed successfully.
                                  ========== FILES ==========
                                  C:\dll32.bat moved successfully.
                                  ========== COMMANDS ==========
                                  File delete failed. C:\DOCUME~1\DIRECT~1\LOCALS~1\Temp\etilqs_CR7nDCQUeEVYcSAJm71L scheduled to be deleted on reboot.
                                  User's Temp folder emptied.
                                  User's Internet Explorer cache folder emptied.
                                  File delete failed. C:\Documents and Settings\direction\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
                                  User's Temporary Internet Files folder emptied.
                                  Local Service Temp folder emptied.
                                  File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
                                  Local Service Temporary Internet Files folder emptied.
                                  Network Service Temp folder emptied.
                                  Network Service Temporary Internet Files folder emptied.
                                  Windows Temp folder emptied.
                                  Java cache emptied.
                                  File delete failed. C:\Documents and Settings\direction\Local Settings\Application Data\Mozilla\Firefox\Profiles\dbzwfelh.default\Cache\_CACHE_001_ scheduled to be deleted on reboot.
                                  File delete failed. C:\Documents and Settings\direction\Local Settings\Application Data\Mozilla\Firefox\Profiles\dbzwfelh.default\Cache\_CACHE_002_ scheduled to be deleted on reboot.
                                  File delete failed. C:\Documents and Settings\direction\Local Settings\Application Data\Mozilla\Firefox\Profiles\dbzwfelh.default\Cache\_CACHE_003_ scheduled to be deleted on reboot.
                                  File delete failed. C:\Documents and Settings\direction\Local Settings\Application Data\Mozilla\Firefox\Profiles\dbzwfelh.default\Cache\_CACHE_MAP_ scheduled to be deleted on reboot.
                                  File delete failed. C:\Documents and Settings\direction\Local Settings\Application Data\Mozilla\Firefox\Profiles\dbzwfelh.default\urlclassifier3.sqlite scheduled to be deleted on reboot.
                                  FireFox cache emptied.
                                  Temp folders emptied.
                                  Explorer started successfully

                                  OTMoveIt3 by OldTimer - Version 1.0.11.0 log created on 04232009_125607

                                  Files moved on Reboot...
                                  File C:\DOCUME~1\DIRECT~1\LOCALS~1\Temp\etilqs_CR7nDCQUeEVYcSAJm71L not found!
                                  C:\Documents and Settings\direction\Local Settings\Application Data\Mozilla\Firefox\Profiles\dbzwfelh.default\Cache\_CACHE_001_ moved successfully.
                                  C:\Documents and Settings\direction\Local Settings\Application Data\Mozilla\Firefox\Profiles\dbzwfelh.default\Cache\_CACHE_002_ moved successfully.
                                  C:\Documents and Settings\direction\Local Settings\Application Data\Mozilla\Firefox\Profiles\dbzwfelh.default\Cache\_CACHE_003_ moved successfully.
                                  C:\Documents and Settings\direction\Local Settings\Application Data\Mozilla\Firefox\Profiles\dbzwfelh.default\Cache\_CACHE_MAP_ moved successfully.
                                  C:\Documents and Settings\direction\Local Settings\Application Data\Mozilla\Firefox\Profiles\dbzwfelh.default\urlclassifier3.sqlite moved successfully.
                                  1. voici le rapport malwarebyte

                                    Malwarebytes' Anti-Malware 1.36
                                    Version de la base de données: 1945
                                    Windows 5.1.2600 Service Pack 3

                                    23/04/2009 13:05:03
                                    mbam-log-2009-04-23 (13-05-03).txt

                                    Type de recherche: Examen rapide
                                    Eléments examinés: 81522
                                    Temps écoulé: 3 minute(s), 23 second(s)

                                    Processus mémoire infecté(s): 0
                                    Module(s) mémoire infecté(s): 0
                                    Clé(s) du Registre infectée(s): 0
                                    Valeur(s) du Registre infectée(s): 0
                                    Elément(s) de données du Registre infecté(s): 0
                                    Dossier(s) infecté(s): 0
                                    Fichier(s) infecté(s): 0

                                    Processus mémoire infecté(s):
                                    (Aucun élément nuisible détecté)

                                    Module(s) mémoire infecté(s):
                                    (Aucun élément nuisible détecté)

                                    Clé(s) du Registre infectée(s):
                                    (Aucun élément nuisible détecté)

                                    Valeur(s) du Registre infectée(s):
                                    (Aucun élément nuisible détecté)

                                    Elément(s) de données du Registre infecté(s):
                                    (Aucun élément nuisible détecté)

                                    Dossier(s) infecté(s):
                                    (Aucun élément nuisible détecté)

                                    Fichier(s) infecté(s):
                                    (Aucun élément nuisible détecté)
                                    1. Contributeur sécurité
                                      non j'avais pas mis de faire un scan malwarebyte mais de virer ce qui est en quarantiane dedans!
                                      • 1
                                      • 2
                                      • 3