Pc qui rame

Résolu
Bonjour,
voila mon pc rame ,par moment il se bloque pendant quelque seconde que ce soit sur internet ou pas merci de votre aide voici un rapport hijackthis ,encore merci
Logfile of HijackThis v1.99.1
Scan saved at 07:26:53, on 01/11/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe
C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
c:\APPS\Powercinema\Kernel\TV\CLCapSvc.exe
C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe
C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLService.exe
C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
c:\APPS\HIDSERVICE\HIDSERVICE.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
C:\Program Files\Fichiers communs\Ulead Systems\AutoDetector\monitor.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Apps\Powercinema\PCMService.exe
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIADE.EXE
C:\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\apps\ABoard\ABoard.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Orange\Systray\SystrayApp.exe
C:\apps\ABoard\AOSD.exe
c:\PROGRA~1\FICHIE~1\mcafee\mna\mcnasvc.exe
C:\Program Files\QuickTime\QTTask.exe
C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\AlertModule\0\AlertModule.exe
C:\Program Files\Orange\Launcher\Launcher.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
c:\PROGRA~1\FICHIE~1\mcafee\mcproxy\mcproxy.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\DAEMON Tools Lite\daemon.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
D:\CDBurnerXP\NMSAccessU.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Fichiers communs\Ulead Systems\DVD\ULCDRSvr.exe
c:\APPS\Powercinema\Kernel\TV\CLSched.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\Program Files\Orange\Deskboard\deskboard.exe
C:\Program Files\Orange\connectivity\connectivitymanager.exe
C:\Program Files\Orange\connectivity\CoreCom\CoreCom.exe
C:\Program Files\Orange\connectivity\CoreCom\OraConfigRecover.exe
C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTCOMModule\0\FTCOMModule.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
D:\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\wuauclt.exe
D:\Documents and Settings\patrice.ordimaison\Mes documents\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.orange.fr/portail
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://fr.search.yahoo.com/search?fr=mcafee&p=%s
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\Program Files\Orange\SearchURLHook\SearchPageURL.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - D:\SPYBOT~1\SDHelper.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.3.4501.1418\swg.dll
O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll
O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [Ulead AutoDetector v2] "C:\Program Files\Fichiers communs\Ulead Systems\AutoDetector\monitor.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [PHIME2002ASync] "C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" /SYNC
O4 - HKLM\..\Run: [PHIME2002A] "C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" /IMEName
O4 - HKLM\..\Run: [PCMService] "c:\Apps\Powercinema\PCMService.exe"
O4 - HKLM\..\Run: [mcagent_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE /Spoil /RemAdvDef /Migration32"
O4 - HKLM\..\Run: [EPSON Stylus DX4800 Series] "C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIADE.EXE" /P26 "EPSON Stylus DX4800 Series" /O6 "USB001" /M "Stylus DX4800"
O4 - HKLM\..\Run: [ATIPTA] "C:\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [ACTIVBOARD] c:\apps\ABoard\ABoard.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [SystrayORAHSS] "C:\Program Files\Orange\Systray\SystrayApp.exe"
O4 - HKLM\..\Run: [ORAHSSSessionManager] C:\Program Files\Orange\SessionManager\SessionManager.exe
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [DWQueuedReporting] "C:\PROGRA~1\FICHIE~1\MICROS~1\DW\dwtrig20.exe" -t
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] D:\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Mon Widget RMC] "C:\Program Files\Nosibay\Mon Widget RMC\launcher.exe"
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
O4 - HKCU\..\RunOnce: [Shockwave Updater] C:\WINDOWS\system32\Adobe\SHOCKW~1\SWHELP~2.EXE -Update -1100465 -"Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; GTB5; .NET CLR 1.1.4322; InfoPath.1; .NET CLR 2.0.50727)" -"http://playskillgames.bwin.com/t/v/client/info?action=gameClient&tournamentSessionId=20148225&pwd=NSSRYDPDIOIE"
O4 - Global Startup: Sagem - Utilitaire réseau pour Clé USB Wi-Fi 802.11g.lnk = ?
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\DOCUME~1\PATRIC~1.ORD\MESDOC~1\msoffice\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - D:\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - D:\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\program files\bonjour\mdnsnsp.dll
O11 - Options group: [INTERNATIONAL] International
O14 - IERESET.INF: START_PAGE_URL=file://C:\APPS\IE\offline\fr.htm
O15 - Trusted Zone: https://www.orange.fr/portail
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - https://www.kaspersky.fr/?domain=webscanner.kaspersky.fr
O16 - DPF: {104B0A37-AB99-4F06-8032-8BBDC3B77DDB} (Telechargement Control) - http://www4.photoweb.fr/telechargement/Photoweb_uploader.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
O16 - DPF: {1F83CD9E-505E-4F87-BECE-0832A763E36F} (Image Uploader 3.0 Control) - http://www.mypixmania.com/importer/MypixUploader.cab
O16 - DPF: {34DC6011-88B5-4EA9-BA7A-DC7B4F4437FE} (JordanUploader Class) - http://photoservice.fujicolor.de/ips-opdata/objects/jordan.cab
O16 - DPF: {3EA4FA88-E0BE-419A-A732-9B79B87A6ED0} (CTVUAxCtrl Object) - http://dl.tvunetworks.com/TVUAx.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by15fd.bay15.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {5D637FAD-E202-48D1-8F18-5B9C459BD1E3} (Image Uploader Control) - http://www.photoweb.fr/moncompte/Account/LogOn?ReturnUrl=%2ftransfert
O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} (Symantec Download Manager) - https://webdl.symantec.com/activex/symdlmgr.cab
O16 - DPF: {6E5E167B-1566-4316-B27F-0DDAB3484CF7} (Image Uploader Control) - http://www.mypix.com/importer/ImageUploader4.cab
O16 - DPF: {AE2B937E-EA7D-4A8D-888C-B68D7F72A3C4} (IPSUploader4 Control) - http://photoservice.fujicolor.de/ips-opdata/operator/27859021/activex/IPSUploader4.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{9269FBB6-E91A-4C38-AF73-012A2FE97739}: NameServer = 192.168.1.1
O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O20 - Winlogon Notify: dimsntfy - %SystemRoot%\System32\dimsntfy.dll (file missing)
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - c:\APPS\Powercinema\Kernel\TV\CLCapSvc.exe
O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - c:\APPS\Powercinema\Kernel\TV\CLSched.exe
O23 - Service: CyberLink Media Library Service - Cyberlink - C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe
O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom SA - C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
O23 - Service: Generic Service for HID Keyboard Input Collections (GenericHidService) - Unknown owner - c:\APPS\HIDSERVICE\HIDSERVICE.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Unknown owner - C:\Program Files\Java\jre6\bin\jqs.exe" -service -config "C:\Program Files\Java\jre6\lib\deploy\jqs\jqs.conf (file missing)
O23 - Service: McAfee SiteAdvisor Service - Unknown owner - C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\FICHIE~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\FICHIE~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: MysqlInventime - Unknown owner - C:\Apps\INVENT~1\mysql\bin\mysqld-nt.exe
O23 - Service: NMSAccessU - Unknown owner - D:\CDBurnerXP\NMSAccessU.exe
O23 - Service: Planificateur LiveUpdate automatique - Unknown owner - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe (file missing)
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Fichiers communs\Ulead Systems\DVD\ULCDRSvr.exe
Configuration: Windows XP Internet Explorer 7.0

26 réponses

Résumé de la discussion

Le sujet décrit un problème de ralentissement et de blocages intermittents, et inclut un rapport HijackThis détaillé destiné à diagnostiquer les éléments susceptibles d’encombrer le système. Le log recense de nombreux processus et services, incluant McAfee, AOL ACS, et divers BHO et utilitaires, ce qui peut expliquer les lenteurs et les blocages. Des suggestions essentielles tourneraient autour du nettoyage des éléments de démarrage et de la suppression des composants potentiellement indésirables présents dans le rapport, pour réduire les conflits logiciels et améliorer les performances globales. Cette situation est associée à Windows XP SP3 et à Internet Explorer 8, ce qui situe le cadre temporel et technique des éléments à corriger.

Bobot (l’IA à votre service)
  1. Contributeur sécurité
    bonjour

    version hijackthis non à jour

    fais ceci

    • Télécharge Random's System Information Tool (RSIT) de Random/Random.

    http://images.malwareremoval.com/random/RSIT.exe

    • Enregistre le sur ton Bureau.

    • Double clique sur RSIT.exe pour lancer l'outil.

    • Clique sur "Continue" à l'écran Disclaimer.

    • Si l'outil HijackThis n'est pas présent ou non détecté sur l'ordinateur, RSIT le téléchargera (autorise l'accès dans ton pare-feu s'il te le demande)

    et tu devras accepter la licence.

    • Une fois le scan terminé, deux rapports vont apparaître : poste les dans deux messages séparés stp
    1. premier rapport:
      Logfile of random's system information tool 1.06 (written by random/random)
      Run by patrice at 2009-11-01 17:53:13
      Microsoft Windows XP Édition familiale Service Pack 3
      System drive C: has 8 GB (25%) free of 31 GB
      Total RAM: 1023 MB (38% free)

      Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 18:01:15, on 01/11/2009
      Platform: Windows XP SP3 (WinNT 5.01.2600)
      MSIE: Internet Explorer v8.00 (8.00.6001.18702)
      Boot mode: Normal

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\Ati2evxx.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\WINDOWS\system32\Ati2evxx.exe
      C:\WINDOWS\Explorer.EXE
      C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe
      C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
      C:\Program Files\Bonjour\mDNSResponder.exe
      c:\APPS\Powercinema\Kernel\TV\CLCapSvc.exe
      C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe
      C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLService.exe
      C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
      c:\APPS\HIDSERVICE\HIDSERVICE.exe
      C:\Program Files\Java\jre6\bin\jqs.exe
      C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
      C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
      c:\PROGRA~1\FICHIE~1\mcafee\mna\mcnasvc.exe
      c:\PROGRA~1\FICHIE~1\mcafee\mcproxy\mcproxy.exe
      C:\Program Files\Fichiers communs\Ulead Systems\AutoDetector\monitor.exe
      C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
      C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
      C:\WINDOWS\SOUNDMAN.EXE
      C:\Program Files\McAfee\MPF\MPFSrv.exe
      C:\Apps\Powercinema\PCMService.exe
      C:\Program Files\McAfee.com\Agent\mcagent.exe
      C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIADE.EXE
      C:\ATI Technologies\ATI Control Panel\atiptaxx.exe
      C:\apps\ABoard\ABoard.exe
      C:\Program Files\Java\jre6\bin\jusched.exe
      C:\Program Files\Orange\Systray\SystrayApp.exe
      D:\CDBurnerXP\NMSAccessU.exe
      C:\Program Files\QuickTime\QTTask.exe
      C:\Program Files\iTunes\iTunesHelper.exe
      C:\apps\ABoard\AOSD.exe
      C:\WINDOWS\system32\ctfmon.exe
      C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
      D:\Spybot - Search & Destroy\TeaTimer.exe
      C:\Program Files\Messenger\msmsgs.exe
      C:\Program Files\DAEMON Tools Lite\daemon.exe
      C:\WINDOWS\system32\svchost.exe
      C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\AlertModule\0\AlertModule.exe
      C:\Program Files\Orange\Launcher\Launcher.exe
      C:\Program Files\Fichiers communs\Ulead Systems\DVD\ULCDRSvr.exe
      c:\APPS\Powercinema\Kernel\TV\CLSched.exe
      C:\Program Files\Orange\Deskboard\deskboard.exe
      C:\Program Files\Orange\connectivity\connectivitymanager.exe
      C:\Program Files\Orange\connectivity\CoreCom\CoreCom.exe
      C:\Program Files\iPod\bin\iPodService.exe
      C:\WINDOWS\system32\wbem\wmiapsrv.exe
      C:\Program Files\Orange\connectivity\CoreCom\OraConfigRecover.exe
      C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTCOMModule\0\FTCOMModule.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\wuauclt.exe
      C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
      D:\Documents and Settings\patrice.ordimaison\Bureau\RSIT.exe
      C:\PROGRA~1\McAfee.com\Agent\McUpdate.exe
      C:\Program Files\trend micro\patrice.exe
      C:\PROGRA~1\McAfee\MSM\McSmtFwk.exe

      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.orange.fr/portail
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
      R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://fr.search.yahoo.com/search?fr=mcafee&p=%s
      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
      R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\Program Files\Orange\SearchURLHook\SearchPageURL.dll
      O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
      O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - D:\SPYBOT~1\SDHelper.dll
      O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
      O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
      O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
      O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.3.4501.1418\swg.dll
      O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
      O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll
      O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
      O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
      O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
      O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
      O3 - Toolbar: DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll
      O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
      O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
      O4 - HKLM\..\Run: [Ulead AutoDetector v2] "C:\Program Files\Fichiers communs\Ulead Systems\AutoDetector\monitor.exe"
      O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
      O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
      O4 - HKLM\..\Run: [PHIME2002ASync] "C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" /SYNC
      O4 - HKLM\..\Run: [PHIME2002A] "C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" /IMEName
      O4 - HKLM\..\Run: [PCMService] "c:\Apps\Powercinema\PCMService.exe"
      O4 - HKLM\..\Run: [mcagent_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
      O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE /Spoil /RemAdvDef /Migration32"
      O4 - HKLM\..\Run: [EPSON Stylus DX4800 Series] "C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIADE.EXE" /P26 "EPSON Stylus DX4800 Series" /O6 "USB001" /M "Stylus DX4800"
      O4 - HKLM\..\Run: [ATIPTA] "C:\ATI Technologies\ATI Control Panel\atiptaxx.exe"
      O4 - HKLM\..\Run: [ACTIVBOARD] c:\apps\ABoard\ABoard.exe
      O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
      O4 - HKLM\..\Run: [SystrayORAHSS] "C:\Program Files\Orange\Systray\SystrayApp.exe"
      O4 - HKLM\..\Run: [ORAHSSSessionManager] C:\Program Files\Orange\SessionManager\SessionManager.exe
      O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
      O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
      O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
      O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
      O4 - HKCU\..\Run: [SpybotSD TeaTimer] D:\Spybot - Search & Destroy\TeaTimer.exe
      O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
      O4 - HKCU\..\Run: [Mon Widget RMC] "C:\Program Files\Nosibay\Mon Widget RMC\launcher.exe"
      O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
      O4 - HKCU\..\RunOnce: [Shockwave Updater] C:\WINDOWS\system32\Adobe\SHOCKW~1\SWHELP~2.EXE -Update -1100465 -"Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; GTB5; .NET CLR 1.1.4322; InfoPath.1; .NET CLR 2.0.50727)" -"http://playskillgames.bwin.com/t/v/client/info?action=gameClient&tournamentSessionId=20148225&pwd=NSSRYDPDIOIE"
      O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe (User 'SERVICE LOCAL')
      O4 - HKUS\S-1-5-19\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background (User 'SERVICE LOCAL')
      O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe (User 'SERVICE RÉSEAU')
      O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
      O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
      O4 - Global Startup: Sagem - Utilitaire réseau pour Clé USB Wi-Fi 802.11g.lnk = ?
      O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\DOCUME~1\PATRIC~1.ORD\MESDOC~1\msoffice\OFFICE11\REFIEBAR.DLL
      O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
      O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - D:\SPYBOT~1\SDHelper.dll
      O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - D:\SPYBOT~1\SDHelper.dll
      O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O14 - IERESET.INF: START_PAGE_URL=file://C:\APPS\IE\offline\fr.htm
      O15 - Trusted Zone: https://www.orange.fr/portail
      O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - https://www.kaspersky.fr/?domain=webscanner.kaspersky.fr
      O16 - DPF: {104B0A37-AB99-4F06-8032-8BBDC3B77DDB} (Telechargement Control) - http://www4.photoweb.fr/telechargement/Photoweb_uploader.cab
      O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
      O16 - DPF: {1F83CD9E-505E-4F87-BECE-0832A763E36F} (Image Uploader 3.0 Control) - http://www.mypixmania.com/importer/MypixUploader.cab
      O16 - DPF: {34DC6011-88B5-4EA9-BA7A-DC7B4F4437FE} (JordanUploader Class) - http://photoservice.fujicolor.de/ips-opdata/objects/jordan.cab
      O16 - DPF: {3EA4FA88-E0BE-419A-A732-9B79B87A6ED0} (CTVUAxCtrl Object) - http://dl.tvunetworks.com/TVUAx.cab
      O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by15fd.bay15.hotmail.msn.com/resources/MsnPUpld.cab
      O16 - DPF: {5D637FAD-E202-48D1-8F18-5B9C459BD1E3} (Image Uploader Control) - http://www.photoweb.fr/moncompte/Account/LogOn?ReturnUrl=%2ftransfert
      O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} (Symantec Download Manager) - https://webdl.symantec.com/activex/symdlmgr.cab
      O16 - DPF: {6E5E167B-1566-4316-B27F-0DDAB3484CF7} (Image Uploader Control) - http://www.mypix.com/importer/ImageUploader4.cab
      O16 - DPF: {AE2B937E-EA7D-4A8D-888C-B68D7F72A3C4} (IPSUploader4 Control) - http://photoservice.fujicolor.de/ips-opdata/operator/27859021/activex/IPSUploader4.cab
      O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
      O17 - HKLM\System\CCS\Services\Tcpip\..\{9269FBB6-E91A-4C38-AF73-012A2FE97739}: NameServer = 192.168.1.1
      O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
      O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe
      O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
      O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
      O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
      O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - c:\APPS\Powercinema\Kernel\TV\CLCapSvc.exe
      O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - c:\APPS\Powercinema\Kernel\TV\CLSched.exe
      O23 - Service: CyberLink Media Library Service - Cyberlink - C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe
      O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom SA - C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
      O23 - Service: Generic Service for HID Keyboard Input Collections (GenericHidService) - Unknown owner - c:\APPS\HIDSERVICE\HIDSERVICE.exe
      O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
      O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
      O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
      O23 - Service: McAfee SiteAdvisor Service - Unknown owner - C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
      O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
      O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\FICHIE~1\mcafee\mna\mcnasvc.exe
      O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
      O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\FICHIE~1\mcafee\mcproxy\mcproxy.exe
      O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
      O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
      O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
      O23 - Service: MysqlInventime - Unknown owner - C:\Apps\INVENT~1\mysql\bin\mysqld-nt.exe
      O23 - Service: NMSAccessU - Unknown owner - D:\CDBurnerXP\NMSAccessU.exe
      O23 - Service: Planificateur LiveUpdate automatique - Unknown owner - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe (file missing)
      O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcsvc.exe
      O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Fichiers communs\Ulead Systems\DVD\ULCDRSvr.exe
      O24 - Desktop Component 1: (no name) - https://www.ebay.fr/
      1. Contributeur sécurité
        deux infections apparement

        Téléchargez USBFIX de Chiquitine29, C_xx
        https://www.androidworld.fr/

        /!\ Utilisateur de vista et windows 7 : ne pas oublier de désactiver Le contrôle des comptes utilisateurs
        https://www.commentcamarche.net/faq/8343-vista-desactiver-l-uac

        /!\ Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) susceptible d'avoir été infectées sans les ouvrir

        • Double clic sur le raccourci UsbFix présent sur le bureau .

        • Choisir l'option 1 (Recherche)
        (d’autres options disponibles, voir le tutoriel).
        • Laissez travailler l'outil.

        • Ensuite postez le rapport UsbFix.txt qui apparaîtra.

        • Note : Le rapport UsbFix.txt est sauvegardé a la racine du disque. ( C:\UsbFix.txt )

        ( CTRL+A Pour tout sélectionner , CTRL+C pour copier et CTRL+V pour coller )

        • Note : "Process.exe", une composante de l'outil, est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool.
        Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.
        Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall...) d'où l'alerte émise par ces antivirus.

        • Tuto : http://pagesperso-orange.fr/NosTools/usbfix.html
        1. voici le rapport usbfix:

          ############################## | UsbFix V6.046 |

          User : patrice (Administrateurs) # ordimaison
          Update on 29/10/2009 by Chiquitine29, C_XX & Chimay8
          Start at: 18:27:42 | 01/11/2009
          Website : http://pagesperso-orange.fr/NosTools/index.html
          Contact : FindyKill.Contact@gmail.com

          AMD Athlon(tm) 64 Processor 3700+
          Microsoft Windows XP Édition familiale (5.1.2600 32-bit) # Service Pack 3
          Internet Explorer 8.0.6001.18702
          Windows Firewall Status : Disabled
          AV : McAfee VirusScan [ Enabled | Updated ]
          FW : Outpost Firewall Pro[ (!) Disabled ]4.0
          FW : McAfee Personal Firewall[ Enabled ]

          C:\ -> Disque fixe local # 29,99 Go (7,63 Go free) [HDD] # NTFS
          D:\ -> Disque fixe local # 195,08 Go (105,35 Go free) [DATA] # NTFS
          E:\ -> Disque CD-ROM
          F:\ -> Disque amovible # 7,45 Go (5,41 Go free) [USB DISK] # FAT32
          G:\ -> Disque amovible
          H:\ -> Disque amovible
          I:\ -> Disque amovible
          J:\ -> Disque amovible
          K:\ -> Disque amovible

          ############################## | Processus actifs |

          C:\WINDOWS\System32\smss.exe
          C:\WINDOWS\system32\csrss.exe
          C:\WINDOWS\system32\winlogon.exe
          C:\WINDOWS\system32\services.exe
          C:\WINDOWS\system32\lsass.exe
          C:\WINDOWS\system32\Ati2evxx.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\system32\spoolsv.exe
          C:\WINDOWS\system32\Ati2evxx.exe
          C:\WINDOWS\Explorer.EXE
          C:\WINDOWS\system32\svchost.exe
          C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe
          C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
          C:\Program Files\Bonjour\mDNSResponder.exe
          c:\APPS\Powercinema\Kernel\TV\CLCapSvc.exe
          C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe
          C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLService.exe
          C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
          c:\APPS\HIDSERVICE\HIDSERVICE.exe
          C:\Program Files\Java\jre6\bin\jqs.exe
          C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
          C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
          c:\PROGRA~1\FICHIE~1\mcafee\mna\mcnasvc.exe
          c:\PROGRA~1\FICHIE~1\mcafee\mcproxy\mcproxy.exe
          C:\Program Files\Fichiers communs\Ulead Systems\AutoDetector\monitor.exe
          C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
          C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
          C:\WINDOWS\SOUNDMAN.EXE
          C:\Program Files\McAfee\MPF\MPFSrv.exe
          C:\Apps\Powercinema\PCMService.exe
          C:\Program Files\McAfee.com\Agent\mcagent.exe
          C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIADE.EXE
          C:\ATI Technologies\ATI Control Panel\atiptaxx.exe
          C:\apps\ABoard\ABoard.exe
          C:\Program Files\Java\jre6\bin\jusched.exe
          C:\Program Files\Orange\Systray\SystrayApp.exe
          D:\CDBurnerXP\NMSAccessU.exe
          C:\Program Files\QuickTime\QTTask.exe
          C:\Program Files\iTunes\iTunesHelper.exe
          C:\apps\ABoard\AOSD.exe
          C:\WINDOWS\system32\ctfmon.exe
          C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
          D:\Spybot - Search & Destroy\TeaTimer.exe
          C:\Program Files\Messenger\msmsgs.exe
          C:\Program Files\DAEMON Tools Lite\daemon.exe
          C:\WINDOWS\system32\svchost.exe
          C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\AlertModule\0\AlertModule.exe
          C:\Program Files\Orange\Launcher\Launcher.exe
          C:\Program Files\Fichiers communs\Ulead Systems\DVD\ULCDRSvr.exe
          c:\APPS\Powercinema\Kernel\TV\CLSched.exe
          C:\WINDOWS\system32\wbem\wmiprvse.exe
          C:\Program Files\Orange\Deskboard\deskboard.exe
          C:\Program Files\Orange\connectivity\connectivitymanager.exe
          C:\Program Files\Orange\connectivity\CoreCom\CoreCom.exe
          C:\Program Files\iPod\bin\iPodService.exe
          C:\WINDOWS\system32\wbem\wmiapsrv.exe
          C:\WINDOWS\System32\alg.exe
          C:\Program Files\Orange\connectivity\CoreCom\OraConfigRecover.exe
          C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTCOMModule\0\FTCOMModule.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\system32\wuauclt.exe
          C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
          C:\WINDOWS\system32\wbem\wmiprvse.exe

          ################## | Fichiers # Dossiers infectieux |

          ################## | Registre # Clés Run infectieuses |

          ################## | Registre # Mountpoints2 |

          HKCU\..\..\Explorer\MountPoints2\{9957cfe6-6812-11de-922a-00038a000015}
          Shell\AutoRun\command =C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Phim_nguoi_lon.exe

          ################## | Suspect | https://www.virustotal.com/gui/ |

          ################## | Cracks / Keygens / Serials |

          ################## | ! Fin du rapport # UsbFix V6.046 ! |
          1. Contributeur sécurité
            tres bien

            ● Relance UsbFix
            ● Dans le menu principale cette fois choisit l'option2

            Le menu démarrer et les icônes vont à nouveau disparaître.. c'est normal.

            Si un message te demande de redémarrer l'ordinateur fait le ...

            ● Au redémarrage, le fix se relance... laisse l'opération s'effectuer.
            ● Le bloc note s'ouvre avec un rapport, envoie le dans la prochaine réponse
            1. bonjour voila le rapport:

              ############################## | UsbFix V6.046 |

              User : patrice (Administrateurs) # ordimaison
              Update on 29/10/2009 by Chiquitine29, C_XX & Chimay8
              Start at: 22:06:03 | 01/11/2009
              Website : http://pagesperso-orange.fr/NosTools/index.html
              Contact : FindyKill.Contact@gmail.com

              AMD Athlon(tm) 64 Processor 3700+
              Microsoft Windows XP Édition familiale (5.1.2600 32-bit) # Service Pack 3
              Internet Explorer 8.0.6001.18702
              Windows Firewall Status : Enabled
              AV : McAfee VirusScan [ Enabled | Updated ]
              FW : Outpost Firewall Pro[ (!) Disabled ]4.0
              FW : McAfee Personal Firewall[ Enabled ]

              C:\ -> Disque fixe local # 29,99 Go (7,63 Go free) [HDD] # NTFS
              D:\ -> Disque fixe local # 195,08 Go (105,36 Go free) [DATA] # NTFS
              E:\ -> Disque CD-ROM
              F:\ -> Disque amovible # 7,45 Go (5,41 Go free) [USB DISK] # FAT32
              G:\ -> Disque amovible
              H:\ -> Disque amovible
              I:\ -> Disque amovible
              J:\ -> Disque amovible
              K:\ -> Disque amovible

              ############################## | Processus actifs |

              C:\WINDOWS\System32\smss.exe
              C:\WINDOWS\system32\csrss.exe
              C:\WINDOWS\system32\winlogon.exe
              C:\WINDOWS\system32\services.exe
              C:\WINDOWS\system32\lsass.exe
              C:\WINDOWS\system32\Ati2evxx.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\System32\svchost.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\system32\spoolsv.exe
              C:\WINDOWS\system32\Ati2evxx.exe
              C:\WINDOWS\Explorer.EXE
              C:\WINDOWS\system32\svchost.exe
              C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe
              C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
              C:\Program Files\Bonjour\mDNSResponder.exe
              c:\APPS\Powercinema\Kernel\TV\CLCapSvc.exe
              C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe
              C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLService.exe
              C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
              c:\APPS\HIDSERVICE\HIDSERVICE.exe
              C:\Program Files\Java\jre6\bin\jqs.exe
              C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
              C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
              c:\PROGRA~1\FICHIE~1\mcafee\mna\mcnasvc.exe
              c:\PROGRA~1\FICHIE~1\mcafee\mcproxy\mcproxy.exe
              C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
              C:\Program Files\McAfee\MPF\MPFSrv.exe
              D:\CDBurnerXP\NMSAccessU.exe
              C:\WINDOWS\system32\svchost.exe
              C:\Program Files\Fichiers communs\Ulead Systems\DVD\ULCDRSvr.exe
              c:\APPS\Powercinema\Kernel\TV\CLSched.exe
              c:\PROGRA~1\mcafee.com\agent\mcagent.exe
              C:\WINDOWS\system32\wbem\wmiprvse.exe
              C:\WINDOWS\system32\wbem\wmiprvse.exe
              C:\WINDOWS\system32\wbem\wmiapsrv.exe
              C:\WINDOWS\System32\alg.exe

              ################## | Fichiers # Dossiers infectieux |

              ################## | Registre # Clés Run infectieuses |

              ################## | Registre # Mountpoints2 |

              Supprimé ! HKCU\...\Explorer\MountPoints2\{9957cfe6-6812-11de-922a-00038a000015}\Shell\AutoRun\Command

              ################## | Listing des fichiers présent |

              [18/11/2005 16:01|--a------|2855080] C:\aawsepersonal.exe
              [03/04/2009 13:54|-rahs----|296] C:\BOOT.INI
              [05/08/2004 13:00|-rahs----|4952] C:\Bootfont.bin
              [05/08/2004 13:00|-rahs----|263488] C:\cmldr
              [27/10/2005 14:59|--a------|6238] C:\DWNLOG.TXT
              [19/10/2006 16:01|--a------|3440] C:\egd.txt
              [?|?|?] C:\hiberfil.sys
              [15/09/2009 18:07|--a------|40960] C:\HTGD0003.exe
              [13/12/2007 12:54|--a------|1120] C:\INSTALL.LOG
              [09/11/2007 09:41|--a------|1612] C:\InstallHelper.log
              [27/10/2005 15:18|-rahs----|0] C:\IO.SYS
              [27/10/2005 15:20|--ah-----|839] C:\IPH.PH
              [08/01/2006 20:37|--a------|0] C:\Lemm_log.txt
              [15/09/2008 09:55|--a------|2786] C:\LGSInst.Log
              [27/10/2005 15:18|-rahs----|0] C:\MSDOS.SYS
              [27/10/2005 15:21|--a------|157] C:\MYInventimeSetup.log
              [05/08/2004 13:00|--a------|47564] C:\NTDETECT.COM
              [02/03/2009 20:07|--a------|252240] C:\NTLDR
              [?|?|?] C:\pagefile.sys
              [19/10/2007 21:02|--a------|680] C:\rapport_clean.txt
              [30/12/2006 16:51|--a------|664] C:\resolve.log
              [27/10/2005 12:48|--a------|1132] C:\SAUDIT.TXT
              [14/05/2009 20:33|--a------|159] C:\Setup.log
              [25/01/2008 22:07|--ah-----|232] C:\sqmdata00.sqm
              [25/01/2008 22:08|--ah-----|232] C:\sqmdata01.sqm
              [07/07/2009 07:55|--ah-----|232] C:\sqmdata02.sqm
              [25/01/2008 22:07|--ah-----|244] C:\sqmnoopt00.sqm
              [25/01/2008 22:08|--ah-----|244] C:\sqmnoopt01.sqm
              [07/07/2009 07:55|--ah-----|244] C:\sqmnoopt02.sqm
              [24/05/2001 12:59|--a------|162304] C:\UNWISE.EXE
              [07/11/2007 07:00|--a------|17734] D:\eula.1028.txt
              [07/11/2007 07:00|--a------|17734] D:\eula.1031.txt
              [07/11/2007 07:00|--a------|10134] D:\eula.1033.txt
              [07/11/2007 07:00|--a------|17734] D:\eula.1036.txt
              [07/11/2007 07:00|--a------|17734] D:\eula.1040.txt
              [07/11/2007 07:00|--a------|118] D:\eula.1041.txt
              [07/11/2007 07:00|--a------|17734] D:\eula.1042.txt
              [07/11/2007 07:00|--a------|17734] D:\eula.2052.txt
              [07/11/2007 07:00|--a------|17734] D:\eula.3082.txt
              [07/11/2007 07:00|--a------|1110] D:\globdata.ini
              [07/11/2007 07:03|--a------|562688] D:\install.exe
              [07/11/2007 07:00|--a------|843] D:\install.ini
              [07/11/2007 07:03|--a------|76304] D:\install.res.1028.dll
              [07/11/2007 07:03|--a------|96272] D:\install.res.1031.dll
              [07/11/2007 07:03|--a------|91152] D:\install.res.1033.dll
              [07/11/2007 07:03|--a------|97296] D:\install.res.1036.dll
              [07/11/2007 07:03|--a------|95248] D:\install.res.1040.dll
              [07/11/2007 07:03|--a------|81424] D:\install.res.1041.dll
              [07/11/2007 07:03|--a------|79888] D:\install.res.1042.dll
              [07/11/2007 07:03|--a------|75792] D:\install.res.2052.dll
              [07/11/2007 07:03|--a------|96272] D:\install.res.3082.dll
              [28/09/2007 05:22|--ah-----|268] D:\sqmdata00.sqm
              [28/09/2007 05:22|--ah-----|244] D:\sqmnoopt00.sqm
              [02/11/2009 05:01|--a------|5764] D:\UsbFix.txt
              [07/11/2007 07:00|--a------|5686] D:\vcredist.bmp
              [07/11/2007 07:09|--a------|1442522] D:\VC_RED.cab
              [07/11/2007 07:12|--a------|232960] D:\VC_RED.MSI
              [27/07/2009 18:10|--a------|729251840] F:\Cr‚ance De Sang (Clint Eastwood).avi
              [27/08/2009 11:28|--a------|735596544] F:\VOLT.(2009).Vraie.VF.Divx6.French.DVDRip.ARLBOUFFIARD.[emule-island.com].avi
              [15/09/2008 00:03|--a------|731736064] F:\Arthur.et.les.Minimoys.FRENCH.DVDRip.XviD-LRD-SaTaN.[emule-island.com].avi

              ################## | Vaccination |

              # C:\autorun.inf -> Dossier créé par UsbFix.
              # D:\autorun.inf -> Dossier créé par UsbFix.
              # F:\autorun.inf -> Dossier créé par UsbFix.

              ################## | Suspect | https://www.virustotal.com/gui/ |

              ################## | Cracks / Keygens / Serials |

              ################## | ! Fin du rapport # UsbFix V6.046 ! |
              1. Contributeur sécurité
                ok

                Téléchargez Toolbar-S&D ( Merci à Eric_71, Angel Dark, Sham_Rock et XmichouX ) sur le Bureau

                https://77b4795d-a-62cb3a1a-s-sites.googlegroups.com/site/eric71mespages/ToolBarSD.exe?attachauth=ANoY7cpVobGk5bHnxrhQ4yaoEUDJvOYNnEGyYjgqHZz5GqZLfutR3fMFPlsC3-CGIilfupPAguYATNyua3csodN_frdMK8sSzUpit10Yac-QJCOkMqJKkbdKcP6ySs8trWPgoNVIq4TGGWCe6o0txXQv-ZueJF9vZzw3RXsGwFYIqN2lvF2LPdQzS8mE1d5kWOVOz6EMzQuE5-lClSJM869uq3oc7-t7yg%3D%3D&attredirects=3

                Lancez l'installation du programme en exécutant le fichier téléchargé.
                Double-cliquez maintenant sur le raccourci de Toolbar-S&D.
                Sélectionnez la langue souhaitée en tapant la lettre de ton choix puis en validant avec la touche Entrée.
                Choisir maintenant l'option 1 (Recherche). Patientez jusqu'à la fin de la recherche.
                Postez le rapport généré. (C:\TB.txt)

                Tuto: https://sites.google.com/site/toolbarsd/aideenimages
                1. petit souci ,a chaque fois que je veut installe toolbarSD ,mc afee le bloque en disant que c'est un virus(spybot worm)
                  1. voila le rapport toolbar:

                    -----------\\ ToolBar S&D 1.2.9 XP/Vista

                    Microsoft Windows XP Édition familiale ( v5.1.2600 ) Service Pack 3
                    X86-based PC ( Uniprocessor Free : AMD Athlon(tm) 64 Processor 3700+ )
                    BIOS : BIOS Date: 07/20/05 11:46:51 Ver: 08.00.12
                    USER : patrice ( Administrator )
                    BOOT : Normal boot
                    Antivirus : McAfee VirusScan (Not Activated)
                    Firewall : McAfee Personal Firewall (Activated)
                    C:\ (Local Disk) - NTFS - Total:29 Go (Free:7 Go)
                    D:\ (Local Disk) - NTFS - Total:195 Go (Free:109 Go)
                    E:\ (CD or DVD)
                    G:\ (USB)
                    H:\ (USB)
                    I:\ (USB)
                    J:\ (USB)
                    K:\ (USB)

                    "C:\ToolBar SD" ( MAJ : 22-08-2009|18:42 )
                    Option : [1] ( 02/11/2009|18:08 )

                    -----------\\ Recherche de Fichiers / Dossiers ...

                    C:\Program Files\DAEMON Tools Toolbar
                    C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll
                    C:\Program Files\DAEMON Tools Toolbar\Resources
                    C:\Program Files\DAEMON Tools Toolbar\uninst.exe
                    C:\Program Files\DAEMON Tools Toolbar\_DTLite.xml
                    C:\Program Files\DAEMON Tools Toolbar\Resources\about.ico
                    C:\Program Files\DAEMON Tools Toolbar\Resources\as.ico
                    C:\Program Files\DAEMON Tools Toolbar\Resources\as.png
                    C:\Program Files\DAEMON Tools Toolbar\Resources\astro.ico
                    C:\Program Files\DAEMON Tools Toolbar\Resources\b1.bmp
                    C:\Program Files\DAEMON Tools Toolbar\Resources\b1.png
                    C:\Program Files\DAEMON Tools Toolbar\Resources\BurnImage.ico
                    C:\Program Files\DAEMON Tools Toolbar\Resources\buy.ico
                    C:\Program Files\DAEMON Tools Toolbar\Resources\cond000.gif
                    C:\Program Files\DAEMON Tools Toolbar\Resources\cond001.gif
                    C:\Program Files\DAEMON Tools Toolbar\Resources\cond003.gif
                    C:\Program Files\DAEMON Tools Toolbar\Resources\cond004.gif
                    C:\Program Files\DAEMON Tools Toolbar\Resources\cond005.gif
                    C:\Program Files\DAEMON Tools Toolbar\Resources\cond006.gif
                    C:\Program Files\DAEMON Tools Toolbar\Resources\cond007.gif
                    C:\Program Files\DAEMON Tools Toolbar\Resources\cond008.gif
                    C:\Program Files\DAEMON Tools Toolbar\Resources\cond009.gif
                    C:\Program Files\DAEMON Tools Toolbar\Resources\cond010.gif
                    C:\Program Files\DAEMON Tools Toolbar\Resources\cond011.gif
                    C:\Program Files\DAEMON Tools Toolbar\Resources\cond019.gif
                    C:\Program Files\DAEMON Tools Toolbar\Resources\cond020.gif
                    C:\Program Files\DAEMON Tools Toolbar\Resources\cond021.gif
                    C:\Program Files\DAEMON Tools Toolbar\Resources\cond022.gif
                    C:\Program Files\DAEMON Tools Toolbar\Resources\cond023.gif
                    C:\Program Files\DAEMON Tools Toolbar\Resources\cond024.gif
                    C:\Program Files\DAEMON Tools Toolbar\Resources\cond025.gif
                    C:\Program Files\DAEMON Tools Toolbar\Resources\cond026.gif
                    C:\Program Files\DAEMON Tools Toolbar\Resources\cond037.gif
                    C:\Program Files\DAEMON Tools Toolbar\Resources\cond038.gif
                    C:\Program Files\DAEMON Tools Toolbar\Resources\cond039.gif
                    C:\Program Files\DAEMON Tools Toolbar\Resources\cond040.gif
                    C:\Program Files\DAEMON Tools Toolbar\Resources\cond041.gif
                    C:\Program Files\DAEMON Tools Toolbar\Resources\cond046.gif
                    C:\Program Files\DAEMON Tools Toolbar\Resources\cond048.gif
                    C:\Program Files\DAEMON Tools Toolbar\Resources\cond050.gif
                    C:\Program Files\DAEMON Tools Toolbar\Resources\cond051.gif
                    C:\Program Files\DAEMON Tools Toolbar\Resources\cond052.gif
                    C:\Program Files\DAEMON Tools Toolbar\Resources\cond053.gif
                    C:\Program Files\DAEMON Tools Toolbar\Resources\cond054.gif
                    C:\Program Files\DAEMON Tools Toolbar\Resources\cond055.gif
                    C:\Program Files\DAEMON Tools Toolbar\Resources\cond056.gif
                    C:\Program Files\DAEMON Tools Toolbar\Resources\cond057.gif
                    C:\Program Files\DAEMON Tools Toolbar\Resources\cond058.gif
                    C:\Program Files\DAEMON Tools Toolbar\Resources\cond059.gif
                    C:\Program Files\DAEMON Tools Toolbar\Resources\cond060.gif
                    C:\Program Files\DAEMON Tools Toolbar\Resources\cond061.gif
                    C:\Program Files\DAEMON Tools Toolbar\Resources\cond062.gif
                    C:\Program Files\DAEMON Tools Toolbar\Resources\cond063.gif
                    C:\Program Files\DAEMON Tools Toolbar\Resources\cond064.gif
                    C:\Program Files\DAEMON Tools Toolbar\Resources\cond065.gif
                    C:\Program Files\DAEMON Tools Toolbar\Resources\cond066.gif
                    C:\Program Files\DAEMON Tools Toolbar\Resources\cond067.gif
                    C:\Program Files\DAEMON Tools Toolbar\Resources\cond068.gif
                    C:\Program Files\DAEMON Tools Toolbar\Resources\cond069.gif
                    C:\Program Files\DAEMON Tools Toolbar\Resources\cond075.gif
                    C:\Program Files\DAEMON Tools Toolbar\Resources\cond076.gif
                    C:\Program Files\DAEMON Tools Toolbar\Resources\cond077.gif
                    C:\Program Files\DAEMON Tools Toolbar\Resources\cond078.gif
                    C:\Program Files\DAEMON Tools Toolbar\Resources\cond079.gif
                    C:\Program Files\DAEMON Tools Toolbar\Resources\cond080.gif
                    C:\Program Files\DAEMON Tools Toolbar\Resources\cond084.gif
                    C:\Program Files\DAEMON Tools Toolbar\Resources\cond085.gif
                    C:\Program Files\DAEMON Tools Toolbar\Resources\cond086.gif
                    C:\Program Files\DAEMON Tools Toolbar\Resources\cond087.gif
                    C:\Program Files\DAEMON Tools Toolbar\Resources\cond088.gif
                    C:\Program Files\DAEMON Tools Toolbar\Resources\cond089.gif
                    C:\Program Files\DAEMON Tools Toolbar\Resources\cond090.gif
                    C:\Program Files\DAEMON Tools Toolbar\Resources\cond091.gif
                    C:\Program Files\DAEMON Tools Toolbar\Resources\cond092.gif
                    C:\Program Files\DAEMON Tools Toolbar\Resources\cond093.gif
                    C:\Program Files\DAEMON Tools Toolbar\Resources\cond094.gif
                    C:\Program Files\DAEMON Tools Toolbar\Resources\cond095.gif
                    C:\Program Files\DAEMON Tools Toolbar\Resources\cond108.gif
                    C:\Program Files\DAEMON Tools Toolbar\Resources\cond109.gif
                    C:\Program Files\DAEMON Tools Toolbar\Resources\cond110.gif
                    C:\Program Files\DAEMON Tools Toolbar\Resources\cond111.gif
                    C:\Program Files\DAEMON Tools Toolbar\Resources\cond112.gif
                    C:\Program Files\DAEMON Tools Toolbar\Resources\cond113.gif
                    C:\Program Files\DAEMON Tools Toolbar\Resources\cond120.gif
                    C:\Program Files\DAEMON Tools Toolbar\Resources\cond121.gif
                    C:\Program Files\DAEMON Tools Toolbar\Resources\cond122.gif
                    C:\Program Files\DAEMON Tools Toolbar\Resources\cond126.gif
                    C:\Program Files\DAEMON Tools Toolbar\Resources\cond127.gif
                    C:\Program Files\DAEMON Tools Toolbar\Resources\cond128.gif
                    C:\Program Files\DAEMON Tools Toolbar\Resources\cond129.gif
                    C:\Program Files\DAEMON Tools Toolbar\Resources\cond130.gif
                    C:\Program Files\DAEMON Tools Toolbar\Resources\cond131.gif
                    C:\Program Files\DAEMON Tools Toolbar\Resources\cond132.gif
                    C:\Program Files\DAEMON Tools Toolbar\Resources\cond133.gif
                    C:\Program Files\DAEMON Tools Toolbar\Resources\cond134.gif
                    C:\Program Files\DAEMON Tools Toolbar\Resources\cond135.gif
                    C:\Program Files\DAEMON Tools Toolbar\Resources\cond136.gif
                    C:\Program Files\DAEMON Tools Toolbar\Resources\cond137.gif
                    C:\Program Files\DAEMON Tools Toolbar\Resources\cond138.gif
                    C:\Program Files\DAEMON Tools Toolbar\Resources\cond140.gif
                    C:\Program Files\DAEMON Tools Toolbar\Resources\cond141.gif
                    C:\Program Files\DAEMON Tools Toolbar\Resources\cond142.gif
                    C:\Program Files\DAEMON Tools Toolbar\Resources\cond143.gif
                    C:\Program Files\DAEMON Tools Toolbar\Resources\cond148.gif
                    C:\Program Files\DAEMON Tools Toolbar\Resources\cond149.gif
                    C:\Program Files\DAEMON Tools Toolbar\Resources\cond152.gif
                    C:\Program Files\DAEMON Tools Toolbar\Resources\cond154.gif
                    C:\Program Files\DAEMON Tools Toolbar\Resources\cond155.gif
                    C:\Program Files\DAEMON Tools Toolbar\Resources\cond156.gif
                    C:\Program Files\DAEMON Tools Toolbar\Resources\cond157.gif
                    C:\Program Files\DAEMON Tools Toolbar\Resources\d.ico
                    C:\Program Files\DAEMON Tools Toolbar\Resources\d2.ico
                    C:\Program Files\DAEMON Tools Toolbar\Resources\daemon.ico
                    C:\Program Files\DAEMON Tools Toolbar\Resources\ds.ico
                    C:\Program Files\DAEMON Tools Toolbar\Resources\dsearch.ico
                    C:\Program Files\DAEMON Tools Toolbar\Resources\dt.ico
                    C:\Program Files\DAEMON Tools Toolbar\Resources\DTPro.ico
                    C:\Program Files\DAEMON Tools Toolbar\Resources\Dwnl.ico
                    C:\Program Files\DAEMON Tools Toolbar\Resources\emulation.ico
                    C:\Program Files\DAEMON Tools Toolbar\Resources\features.ico
                    C:\Program Files\DAEMON Tools Toolbar\Resources\gd.ico
                    C:\Program Files\DAEMON Tools Toolbar\Resources\globe.ico
                    C:\Program Files\DAEMON Tools Toolbar\Resources\GrabImage.ico
                    C:\Program Files\DAEMON Tools Toolbar\Resources\hb.bmp
                    C:\Program Files\DAEMON Tools Toolbar\Resources\hb.ico
                    C:\Program Files\DAEMON Tools Toolbar\Resources\help.ico
                    C:\Program Files\DAEMON Tools Toolbar\Resources\ip.ico
                    C:\Program Files\DAEMON Tools Toolbar\Resources\lang.xml
                    C:\Program Files\DAEMON Tools Toolbar\Resources\lingvo.ico
                    C:\Program Files\DAEMON Tools Toolbar\Resources\m.ico
                    C:\Program Files\DAEMON Tools Toolbar\Resources\mail.bmp
                    C:\Program Files\DAEMON Tools Toolbar\Resources\mailc.bmp
                    C:\Program Files\DAEMON Tools Toolbar\Resources\mailc_disable.bmp
                    C:\Program Files\DAEMON Tools Toolbar\Resources\mailc_down.bmp
                    C:\Program Files\DAEMON Tools Toolbar\Resources\mailc_m.bmp
                    C:\Program Files\DAEMON Tools Toolbar\Resources\mailc_under.bmp
                    C:\Program Files\DAEMON Tools Toolbar\Resources\mail_disable.bmp
                    C:\Program Files\DAEMON Tools Toolbar\Resources\mail_down.bmp
                    C:\Program Files\DAEMON Tools Toolbar\Resources\mail_m.bmp
                    C:\Program Files\DAEMON Tools Toolbar\Resources\mail_under.bmp
                    C:\Program Files\DAEMON Tools Toolbar\Resources\next.bmp
                    C:\Program Files\DAEMON Tools Toolbar\Resources\next_down.bmp
                    C:\Program Files\DAEMON Tools Toolbar\Resources\next_m.bmp
                    C:\Program Files\DAEMON Tools Toolbar\Resources\next_under.bmp
                    C:\Program Files\DAEMON Tools Toolbar\Resources\none.bmp
                    C:\Program Files\DAEMON Tools Toolbar\Resources\none_m.bmp
                    C:\Program Files\DAEMON Tools Toolbar\Resources\noW.gif
                    C:\Program Files\DAEMON Tools Toolbar\Resources\op.ico
                    C:\Program Files\DAEMON Tools Toolbar\Resources\pragma.ico
                    C:\Program Files\DAEMON Tools Toolbar\Resources\prev.bmp
                    C:\Program Files\DAEMON Tools Toolbar\Resources\prev_down.bmp
                    C:\Program Files\DAEMON Tools Toolbar\Resources\prev_m.bmp
                    C:\Program Files\DAEMON Tools Toolbar\Resources\prev_under.bmp
                    C:\Program Files\DAEMON Tools Toolbar\Resources\prod.ico
                    C:\Program Files\DAEMON Tools Toolbar\Resources\refresh.bmp
                    C:\Program Files\DAEMON Tools Toolbar\Resources\refresh_down.bmp
                    C:\Program Files\DAEMON Tools Toolbar\Resources\refresh_m.bmp
                    C:\Program Files\DAEMON Tools Toolbar\Resources\refresh_under.bmp
                    C:\Program Files\DAEMON Tools Toolbar\Resources\Rss.ico
                    C:\Program Files\DAEMON Tools Toolbar\Resources\Rss1.ico
                    C:\Program Files\DAEMON Tools Toolbar\Resources\rssClose.ico
                    C:\Program Files\DAEMON Tools Toolbar\Resources\rssL.bmp
                    C:\Program Files\DAEMON Tools Toolbar\Resources\rssOpen.ico
                    C:\Program Files\DAEMON Tools Toolbar\Resources\size.bmp
                    C:\Program Files\DAEMON Tools Toolbar\Resources\size_m.bmp
                    C:\Program Files\DAEMON Tools Toolbar\Resources\skins.ico
                    C:\Program Files\DAEMON Tools Toolbar\Resources\spt.ico
                    C:\Program Files\DAEMON Tools Toolbar\Resources\SupportRequest.ico
                    C:\Program Files\DAEMON Tools Toolbar\Resources\time.ico
                    C:\Program Files\DAEMON Tools Toolbar\Resources\TitleIcon.ico
                    C:\Program Files\DAEMON Tools Toolbar\Resources\toolbar.xml
                    C:\Program Files\DAEMON Tools Toolbar\Resources\trans.ico
                    C:\Program Files\DAEMON Tools Toolbar\Resources\Trash.bmp
                    C:\Program Files\DAEMON Tools Toolbar\Resources\Trash_disable.bmp
                    C:\Program Files\DAEMON Tools Toolbar\Resources\Trash_down.bmp
                    C:\Program Files\DAEMON Tools Toolbar\Resources\Trash_m.bmp
                    C:\Program Files\DAEMON Tools Toolbar\Resources\Trash_under.bmp
                    C:\Program Files\DAEMON Tools Toolbar\Resources\u.ico
                    C:\Program Files\DAEMON Tools Toolbar\Resources\wb.bmp
                    C:\Program Files\DAEMON Tools Toolbar\Resources\wBtClose.bmp
                    C:\Program Files\DAEMON Tools Toolbar\Resources\wBtClose_down.bmp
                    C:\Program Files\DAEMON Tools Toolbar\Resources\wBtClose_m.bmp
                    C:\Program Files\DAEMON Tools Toolbar\Resources\wBtClose_under.bmp
                    C:\Program Files\DAEMON Tools Toolbar\Resources\wBtText.bmp
                    C:\Program Files\DAEMON Tools Toolbar\Resources\wBtText_down.bmp
                    C:\Program Files\DAEMON Tools Toolbar\Resources\wBtText_m.bmp
                    C:\Program Files\DAEMON Tools Toolbar\Resources\wBtText_under.bmp
                    C:\Program Files\DAEMON Tools Toolbar\Resources\Weather_m42.bmp
                    C:\Program Files\DAEMON Tools Toolbar\Resources\Weather_m43.bmp
                    C:\Program Files\DAEMON Tools Toolbar\Resources\wi.ico
                    C:\Program Files\DAEMON Tools Toolbar\Resources\wi0.ico
                    C:\Program Files\DAEMON Tools Toolbar\Resources\wi1.ico
                    C:\Program Files\DAEMON Tools Toolbar\Resources\wi10.ico
                    C:\Program Files\DAEMON Tools Toolbar\Resources\wi11.ico
                    C:\Program Files\DAEMON Tools Toolbar\Resources\wi12.ico
                    C:\Program Files\DAEMON Tools Toolbar\Resources\wi13.ico
                    C:\Program Files\DAEMON Tools Toolbar\Resources\wi2.ico
                    C:\Program Files\DAEMON Tools Toolbar\Resources\wi3.ico
                    C:\Program Files\DAEMON Tools Toolbar\Resources\wi4.ico
                    C:\Program Files\DAEMON Tools Toolbar\Resources\wi5.ico
                    C:\Program Files\DAEMON Tools Toolbar\Resources\wi6.ico
                    C:\Program Files\DAEMON Tools Toolbar\Resources\wi7.ico
                    C:\Program Files\DAEMON Tools Toolbar\Resources\wi8.ico
                    C:\Program Files\DAEMON Tools Toolbar\Resources\wi9.ico
                    C:\Program Files\Multi_Media_France
                    C:\Program Files\Multi_Media_France\INSTALL.LOG

                    -----------\\ [..\Internet Explorer\Main]

                    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
                    "Search Page"="https://www.google.com/?gws_rd=ssl"
                    "SearchMigratedDefaultURL"="https://www.google.com/webhp?gws_rd=ssl{searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8"
                    "Start Page"="https://www.orange.fr/portail"
                    "Default_Page_URL"="https://www.msn.com/fr-fr/?ocid=iehp"
                    "Url"="http://www.microsoft.com/athome/community/rss.xml"
                    "Url"="http://rss.msn.com/en-us/?feedoutput=rss&ocid=iehrs&unsub=true"
                    "Url"="http://www.microsoft.com/atwork/community/rss.xml"

                    [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
                    "Default_Search_URL"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
                    "Search Page"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
                    "Start Page"="https://www.msn.com/fr-fr"
                    "Default_Page_URL"="https://www.msn.com/fr-fr/?ocid=iehp"

                    --------------------\\ Recherche d'autres infections

                    C:\WINDOWS\Pack.epk
                    [b]==> EGDACCESS <==/b

                    --------------------\\ Cracks & Keygens ..

                    D:\DOCUME~1\PATRIC~1.ORD\Bureau\IDM\Crack_UnReal

                    1 - "C:\ToolBar SD\TB_1.txt" - 02/11/2009|18:10 - Option : [1]

                    -----------\\ Fin du rapport a 18:10:37,76
                    1. voila le dernier rapport:

                      -----------\\ ToolBar S&D 1.2.9 XP/Vista

                      Microsoft Windows XP Édition familiale ( v5.1.2600 ) Service Pack 3
                      X86-based PC ( Uniprocessor Free : AMD Athlon(tm) 64 Processor 3700+ )
                      BIOS : BIOS Date: 07/20/05 11:46:51 Ver: 08.00.12
                      USER : patrice ( Administrator )
                      BOOT : Normal boot
                      Antivirus : McAfee VirusScan (Not Activated)
                      Firewall : McAfee Personal Firewall (Activated)
                      C:\ (Local Disk) - NTFS - Total:29 Go (Free:7 Go)
                      D:\ (Local Disk) - NTFS - Total:195 Go (Free:109 Go)
                      E:\ (CD or DVD)
                      G:\ (USB)
                      H:\ (USB)
                      I:\ (USB)
                      J:\ (USB)
                      K:\ (USB)

                      "C:\ToolBar SD" ( MAJ : 22-08-2009|18:42 )
                      Option : [1] ( 02/11/2009|18:08 )

                      -----------\\ Recherche de Fichiers / Dossiers ...

                      C:\Program Files\DAEMON Tools Toolbar
                      C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll
                      C:\Program Files\DAEMON Tools Toolbar\Resources
                      C:\Program Files\DAEMON Tools Toolbar\uninst.exe
                      C:\Program Files\DAEMON Tools Toolbar\_DTLite.xml
                      C:\Program Files\DAEMON Tools Toolbar\Resources\about.ico
                      C:\Program Files\DAEMON Tools Toolbar\Resources\as.ico
                      C:\Program Files\DAEMON Tools Toolbar\Resources\as.png
                      C:\Program Files\DAEMON Tools Toolbar\Resources\astro.ico
                      C:\Program Files\DAEMON Tools Toolbar\Resources\b1.bmp
                      C:\Program Files\DAEMON Tools Toolbar\Resources\b1.png
                      C:\Program Files\DAEMON Tools Toolbar\Resources\BurnImage.ico
                      C:\Program Files\DAEMON Tools Toolbar\Resources\buy.ico
                      C:\Program Files\DAEMON Tools Toolbar\Resources\cond000.gif
                      C:\Program Files\DAEMON Tools Toolbar\Resources\cond001.gif
                      C:\Program Files\DAEMON Tools Toolbar\Resources\cond003.gif
                      C:\Program Files\DAEMON Tools Toolbar\Resources\cond004.gif
                      C:\Program Files\DAEMON Tools Toolbar\Resources\cond005.gif
                      C:\Program Files\DAEMON Tools Toolbar\Resources\cond006.gif
                      C:\Program Files\DAEMON Tools Toolbar\Resources\cond007.gif
                      C:\Program Files\DAEMON Tools Toolbar\Resources\cond008.gif
                      C:\Program Files\DAEMON Tools Toolbar\Resources\cond009.gif
                      C:\Program Files\DAEMON Tools Toolbar\Resources\cond010.gif
                      C:\Program Files\DAEMON Tools Toolbar\Resources\cond011.gif
                      C:\Program Files\DAEMON Tools Toolbar\Resources\cond019.gif
                      C:\Program Files\DAEMON Tools Toolbar\Resources\cond020.gif
                      C:\Program Files\DAEMON Tools Toolbar\Resources\cond021.gif
                      C:\Program Files\DAEMON Tools Toolbar\Resources\cond022.gif
                      C:\Program Files\DAEMON Tools Toolbar\Resources\cond023.gif
                      C:\Program Files\DAEMON Tools Toolbar\Resources\cond024.gif
                      C:\Program Files\DAEMON Tools Toolbar\Resources\cond025.gif
                      C:\Program Files\DAEMON Tools Toolbar\Resources\cond026.gif
                      C:\Program Files\DAEMON Tools Toolbar\Resources\cond037.gif
                      C:\Program Files\DAEMON Tools Toolbar\Resources\cond038.gif
                      C:\Program Files\DAEMON Tools Toolbar\Resources\cond039.gif
                      C:\Program Files\DAEMON Tools Toolbar\Resources\cond040.gif
                      C:\Program Files\DAEMON Tools Toolbar\Resources\cond041.gif
                      C:\Program Files\DAEMON Tools Toolbar\Resources\cond046.gif
                      C:\Program Files\DAEMON Tools Toolbar\Resources\cond048.gif
                      C:\Program Files\DAEMON Tools Toolbar\Resources\cond050.gif
                      C:\Program Files\DAEMON Tools Toolbar\Resources\cond051.gif
                      C:\Program Files\DAEMON Tools Toolbar\Resources\cond052.gif
                      C:\Program Files\DAEMON Tools Toolbar\Resources\cond053.gif
                      C:\Program Files\DAEMON Tools Toolbar\Resources\cond054.gif
                      C:\Program Files\DAEMON Tools Toolbar\Resources\cond055.gif
                      C:\Program Files\DAEMON Tools Toolbar\Resources\cond056.gif
                      C:\Program Files\DAEMON Tools Toolbar\Resources\cond057.gif
                      C:\Program Files\DAEMON Tools Toolbar\Resources\cond058.gif
                      C:\Program Files\DAEMON Tools Toolbar\Resources\cond059.gif
                      C:\Program Files\DAEMON Tools Toolbar\Resources\cond060.gif
                      C:\Program Files\DAEMON Tools Toolbar\Resources\cond061.gif
                      C:\Program Files\DAEMON Tools Toolbar\Resources\cond062.gif
                      C:\Program Files\DAEMON Tools Toolbar\Resources\cond063.gif
                      C:\Program Files\DAEMON Tools Toolbar\Resources\cond064.gif
                      C:\Program Files\DAEMON Tools Toolbar\Resources\cond065.gif
                      C:\Program Files\DAEMON Tools Toolbar\Resources\cond066.gif
                      C:\Program Files\DAEMON Tools Toolbar\Resources\cond067.gif
                      C:\Program Files\DAEMON Tools Toolbar\Resources\cond068.gif
                      C:\Program Files\DAEMON Tools Toolbar\Resources\cond069.gif
                      C:\Program Files\DAEMON Tools Toolbar\Resources\cond075.gif
                      C:\Program Files\DAEMON Tools Toolbar\Resources\cond076.gif
                      C:\Program Files\DAEMON Tools Toolbar\Resources\cond077.gif
                      C:\Program Files\DAEMON Tools Toolbar\Resources\cond078.gif
                      C:\Program Files\DAEMON Tools Toolbar\Resources\cond079.gif
                      C:\Program Files\DAEMON Tools Toolbar\Resources\cond080.gif
                      C:\Program Files\DAEMON Tools Toolbar\Resources\cond084.gif
                      C:\Program Files\DAEMON Tools Toolbar\Resources\cond085.gif
                      C:\Program Files\DAEMON Tools Toolbar\Resources\cond086.gif
                      C:\Program Files\DAEMON Tools Toolbar\Resources\cond087.gif
                      C:\Program Files\DAEMON Tools Toolbar\Resources\cond088.gif
                      C:\Program Files\DAEMON Tools Toolbar\Resources\cond089.gif
                      C:\Program Files\DAEMON Tools Toolbar\Resources\cond090.gif
                      C:\Program Files\DAEMON Tools Toolbar\Resources\cond091.gif
                      C:\Program Files\DAEMON Tools Toolbar\Resources\cond092.gif
                      C:\Program Files\DAEMON Tools Toolbar\Resources\cond093.gif
                      C:\Program Files\DAEMON Tools Toolbar\Resources\cond094.gif
                      C:\Program Files\DAEMON Tools Toolbar\Resources\cond095.gif
                      C:\Program Files\DAEMON Tools Toolbar\Resources\cond108.gif
                      C:\Program Files\DAEMON Tools Toolbar\Resources\cond109.gif
                      C:\Program Files\DAEMON Tools Toolbar\Resources\cond110.gif
                      C:\Program Files\DAEMON Tools Toolbar\Resources\cond111.gif
                      C:\Program Files\DAEMON Tools Toolbar\Resources\cond112.gif
                      C:\Program Files\DAEMON Tools Toolbar\Resources\cond113.gif
                      C:\Program Files\DAEMON Tools Toolbar\Resources\cond120.gif
                      C:\Program Files\DAEMON Tools Toolbar\Resources\cond121.gif
                      C:\Program Files\DAEMON Tools Toolbar\Resources\cond122.gif
                      C:\Program Files\DAEMON Tools Toolbar\Resources\cond126.gif
                      C:\Program Files\DAEMON Tools Toolbar\Resources\cond127.gif
                      C:\Program Files\DAEMON Tools Toolbar\Resources\cond128.gif
                      C:\Program Files\DAEMON Tools Toolbar\Resources\cond129.gif
                      C:\Program Files\DAEMON Tools Toolbar\Resources\cond130.gif
                      C:\Program Files\DAEMON Tools Toolbar\Resources\cond131.gif
                      C:\Program Files\DAEMON Tools Toolbar\Resources\cond132.gif
                      C:\Program Files\DAEMON Tools Toolbar\Resources\cond133.gif
                      C:\Program Files\DAEMON Tools Toolbar\Resources\cond134.gif
                      C:\Program Files\DAEMON Tools Toolbar\Resources\cond135.gif
                      C:\Program Files\DAEMON Tools Toolbar\Resources\cond136.gif
                      C:\Program Files\DAEMON Tools Toolbar\Resources\cond137.gif
                      C:\Program Files\DAEMON Tools Toolbar\Resources\cond138.gif
                      C:\Program Files\DAEMON Tools Toolbar\Resources\cond140.gif
                      C:\Program Files\DAEMON Tools Toolbar\Resources\cond141.gif
                      C:\Program Files\DAEMON Tools Toolbar\Resources\cond142.gif
                      C:\Program Files\DAEMON Tools Toolbar\Resources\cond143.gif
                      C:\Program Files\DAEMON Tools Toolbar\Resources\cond148.gif
                      C:\Program Files\DAEMON Tools Toolbar\Resources\cond149.gif
                      C:\Program Files\DAEMON Tools Toolbar\Resources\cond152.gif
                      C:\Program Files\DAEMON Tools Toolbar\Resources\cond154.gif
                      C:\Program Files\DAEMON Tools Toolbar\Resources\cond155.gif
                      C:\Program Files\DAEMON Tools Toolbar\Resources\cond156.gif
                      C:\Program Files\DAEMON Tools Toolbar\Resources\cond157.gif
                      C:\Program Files\DAEMON Tools Toolbar\Resources\d.ico
                      C:\Program Files\DAEMON Tools Toolbar\Resources\d2.ico
                      C:\Program Files\DAEMON Tools Toolbar\Resources\daemon.ico
                      C:\Program Files\DAEMON Tools Toolbar\Resources\ds.ico
                      C:\Program Files\DAEMON Tools Toolbar\Resources\dsearch.ico
                      C:\Program Files\DAEMON Tools Toolbar\Resources\dt.ico
                      C:\Program Files\DAEMON Tools Toolbar\Resources\DTPro.ico
                      C:\Program Files\DAEMON Tools Toolbar\Resources\Dwnl.ico
                      C:\Program Files\DAEMON Tools Toolbar\Resources\emulation.ico
                      C:\Program Files\DAEMON Tools Toolbar\Resources\features.ico
                      C:\Program Files\DAEMON Tools Toolbar\Resources\gd.ico
                      C:\Program Files\DAEMON Tools Toolbar\Resources\globe.ico
                      C:\Program Files\DAEMON Tools Toolbar\Resources\GrabImage.ico
                      C:\Program Files\DAEMON Tools Toolbar\Resources\hb.bmp
                      C:\Program Files\DAEMON Tools Toolbar\Resources\hb.ico
                      C:\Program Files\DAEMON Tools Toolbar\Resources\help.ico
                      C:\Program Files\DAEMON Tools Toolbar\Resources\ip.ico
                      C:\Program Files\DAEMON Tools Toolbar\Resources\lang.xml
                      C:\Program Files\DAEMON Tools Toolbar\Resources\lingvo.ico
                      C:\Program Files\DAEMON Tools Toolbar\Resources\m.ico
                      C:\Program Files\DAEMON Tools Toolbar\Resources\mail.bmp
                      C:\Program Files\DAEMON Tools Toolbar\Resources\mailc.bmp
                      C:\Program Files\DAEMON Tools Toolbar\Resources\mailc_disable.bmp
                      C:\Program Files\DAEMON Tools Toolbar\Resources\mailc_down.bmp
                      C:\Program Files\DAEMON Tools Toolbar\Resources\mailc_m.bmp
                      C:\Program Files\DAEMON Tools Toolbar\Resources\mailc_under.bmp
                      C:\Program Files\DAEMON Tools Toolbar\Resources\mail_disable.bmp
                      C:\Program Files\DAEMON Tools Toolbar\Resources\mail_down.bmp
                      C:\Program Files\DAEMON Tools Toolbar\Resources\mail_m.bmp
                      C:\Program Files\DAEMON Tools Toolbar\Resources\mail_under.bmp
                      C:\Program Files\DAEMON Tools Toolbar\Resources\next.bmp
                      C:\Program Files\DAEMON Tools Toolbar\Resources\next_down.bmp
                      C:\Program Files\DAEMON Tools Toolbar\Resources\next_m.bmp
                      C:\Program Files\DAEMON Tools Toolbar\Resources\next_under.bmp
                      C:\Program Files\DAEMON Tools Toolbar\Resources\none.bmp
                      C:\Program Files\DAEMON Tools Toolbar\Resources\none_m.bmp
                      C:\Program Files\DAEMON Tools Toolbar\Resources\noW.gif
                      C:\Program Files\DAEMON Tools Toolbar\Resources\op.ico
                      C:\Program Files\DAEMON Tools Toolbar\Resources\pragma.ico
                      C:\Program Files\DAEMON Tools Toolbar\Resources\prev.bmp
                      C:\Program Files\DAEMON Tools Toolbar\Resources\prev_down.bmp
                      C:\Program Files\DAEMON Tools Toolbar\Resources\prev_m.bmp
                      C:\Program Files\DAEMON Tools Toolbar\Resources\prev_under.bmp
                      C:\Program Files\DAEMON Tools Toolbar\Resources\prod.ico
                      C:\Program Files\DAEMON Tools Toolbar\Resources\refresh.bmp
                      C:\Program Files\DAEMON Tools Toolbar\Resources\refresh_down.bmp
                      C:\Program Files\DAEMON Tools Toolbar\Resources\refresh_m.bmp
                      C:\Program Files\DAEMON Tools Toolbar\Resources\refresh_under.bmp
                      C:\Program Files\DAEMON Tools Toolbar\Resources\Rss.ico
                      C:\Program Files\DAEMON Tools Toolbar\Resources\Rss1.ico
                      C:\Program Files\DAEMON Tools Toolbar\Resources\rssClose.ico
                      C:\Program Files\DAEMON Tools Toolbar\Resources\rssL.bmp
                      C:\Program Files\DAEMON Tools Toolbar\Resources\rssOpen.ico
                      C:\Program Files\DAEMON Tools Toolbar\Resources\size.bmp
                      C:\Program Files\DAEMON Tools Toolbar\Resources\size_m.bmp
                      C:\Program Files\DAEMON Tools Toolbar\Resources\skins.ico
                      C:\Program Files\DAEMON Tools Toolbar\Resources\spt.ico
                      C:\Program Files\DAEMON Tools Toolbar\Resources\SupportRequest.ico
                      C:\Program Files\DAEMON Tools Toolbar\Resources\time.ico
                      C:\Program Files\DAEMON Tools Toolbar\Resources\TitleIcon.ico
                      C:\Program Files\DAEMON Tools Toolbar\Resources\toolbar.xml
                      C:\Program Files\DAEMON Tools Toolbar\Resources\trans.ico
                      C:\Program Files\DAEMON Tools Toolbar\Resources\Trash.bmp
                      C:\Program Files\DAEMON Tools Toolbar\Resources\Trash_disable.bmp
                      C:\Program Files\DAEMON Tools Toolbar\Resources\Trash_down.bmp
                      C:\Program Files\DAEMON Tools Toolbar\Resources\Trash_m.bmp
                      C:\Program Files\DAEMON Tools Toolbar\Resources\Trash_under.bmp
                      C:\Program Files\DAEMON Tools Toolbar\Resources\u.ico
                      C:\Program Files\DAEMON Tools Toolbar\Resources\wb.bmp
                      C:\Program Files\DAEMON Tools Toolbar\Resources\wBtClose.bmp
                      C:\Program Files\DAEMON Tools Toolbar\Resources\wBtClose_down.bmp
                      C:\Program Files\DAEMON Tools Toolbar\Resources\wBtClose_m.bmp
                      C:\Program Files\DAEMON Tools Toolbar\Resources\wBtClose_under.bmp
                      C:\Program Files\DAEMON Tools Toolbar\Resources\wBtText.bmp
                      C:\Program Files\DAEMON Tools Toolbar\Resources\wBtText_down.bmp
                      C:\Program Files\DAEMON Tools Toolbar\Resources\wBtText_m.bmp
                      C:\Program Files\DAEMON Tools Toolbar\Resources\wBtText_under.bmp
                      C:\Program Files\DAEMON Tools Toolbar\Resources\Weather_m42.bmp
                      C:\Program Files\DAEMON Tools Toolbar\Resources\Weather_m43.bmp
                      C:\Program Files\DAEMON Tools Toolbar\Resources\wi.ico
                      C:\Program Files\DAEMON Tools Toolbar\Resources\wi0.ico
                      C:\Program Files\DAEMON Tools Toolbar\Resources\wi1.ico
                      C:\Program Files\DAEMON Tools Toolbar\Resources\wi10.ico
                      C:\Program Files\DAEMON Tools Toolbar\Resources\wi11.ico
                      C:\Program Files\DAEMON Tools Toolbar\Resources\wi12.ico
                      C:\Program Files\DAEMON Tools Toolbar\Resources\wi13.ico
                      C:\Program Files\DAEMON Tools Toolbar\Resources\wi2.ico
                      C:\Program Files\DAEMON Tools Toolbar\Resources\wi3.ico
                      C:\Program Files\DAEMON Tools Toolbar\Resources\wi4.ico
                      C:\Program Files\DAEMON Tools Toolbar\Resources\wi5.ico
                      C:\Program Files\DAEMON Tools Toolbar\Resources\wi6.ico
                      C:\Program Files\DAEMON Tools Toolbar\Resources\wi7.ico
                      C:\Program Files\DAEMON Tools Toolbar\Resources\wi8.ico
                      C:\Program Files\DAEMON Tools Toolbar\Resources\wi9.ico
                      C:\Program Files\Multi_Media_France
                      C:\Program Files\Multi_Media_France\INSTALL.LOG

                      -----------\\ [..\Internet Explorer\Main]

                      [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
                      "Search Page"="https://www.google.com/?gws_rd=ssl"
                      "SearchMigratedDefaultURL"="https://www.google.com/webhp?gws_rd=ssl{searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8"
                      "Start Page"="https://www.orange.fr/portail"
                      "Default_Page_URL"="https://www.msn.com/fr-fr/?ocid=iehp"
                      "Url"="http://www.microsoft.com/athome/community/rss.xml"
                      "Url"="http://rss.msn.com/en-us/?feedoutput=rss&ocid=iehrs&unsub=true"
                      "Url"="http://www.microsoft.com/atwork/community/rss.xml"

                      [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
                      "Default_Search_URL"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
                      "Search Page"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
                      "Start Page"="https://www.msn.com/fr-fr"
                      "Default_Page_URL"="https://www.msn.com/fr-fr/?ocid=iehp"

                      --------------------\\ Recherche d'autres infections

                      C:\WINDOWS\Pack.epk
                      [b]==> EGDACCESS <==/b

                      --------------------\\ Cracks & Keygens ..

                      D:\DOCUME~1\PATRIC~1.ORD\Bureau\IDM\Crack_UnReal

                      1 - "C:\ToolBar SD\TB_1.txt" - 02/11/2009|18:10 - Option : [1]

                      -----------\\ Fin du rapport a 18:10:37,76
                      1. oups desole c'est celui la:

                        -----------\\ ToolBar S&D 1.2.9 XP/Vista

                        Microsoft Windows XP Édition familiale ( v5.1.2600 ) Service Pack 3
                        X86-based PC ( Uniprocessor Free : AMD Athlon(tm) 64 Processor 3700+ )
                        BIOS : BIOS Date: 07/20/05 11:46:51 Ver: 08.00.12
                        USER : patrice ( Administrator )
                        BOOT : Normal boot
                        Antivirus : McAfee VirusScan (Not Activated)
                        Firewall : McAfee Personal Firewall (Activated)
                        C:\ (Local Disk) - NTFS - Total:29 Go (Free:7 Go)
                        D:\ (Local Disk) - NTFS - Total:195 Go (Free:109 Go)
                        E:\ (CD or DVD)
                        G:\ (USB)
                        H:\ (USB)
                        I:\ (USB)
                        J:\ (USB)

                        "C:\ToolBar SD" ( MAJ : 22-08-2009|18:42 )
                        Option : [2] ( 02/11/2009|22:16 )

                        -----------\\ SUPPRESSION

                        Supprime! - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll
                        Supprime! - C:\Program Files\DAEMON Tools Toolbar\Resources
                        Supprime! - C:\Program Files\DAEMON Tools Toolbar\uninst.exe
                        Supprime! - C:\Program Files\DAEMON Tools Toolbar\_DTLite.xml
                        Supprime! - C:\Program Files\Multi_Media_France\INSTALL.LOG
                        Supprime! - C:\Program Files\DAEMON Tools Toolbar
                        Supprime! - C:\Program Files\Multi_Media_France

                        -----------\\ Recherche de Fichiers / Dossiers ...

                        -----------\\ [..\Internet Explorer\Main]

                        [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
                        "Search Page"="https://www.google.com/?gws_rd=ssl"
                        "SearchMigratedDefaultURL"="https://www.google.com/webhp?gws_rd=ssl{searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8"
                        "Start Page"="https://www.orange.fr/portail"
                        "Default_Page_URL"="https://www.msn.com/fr-fr/?ocid=iehp"
                        "Url"="http://www.microsoft.com/athome/community/rss.xml"
                        "Url"="http://rss.msn.com/en-us/?feedoutput=rss&ocid=iehrs&unsub=true"
                        "Url"="http://www.microsoft.com/atwork/community/rss.xml"

                        [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
                        "Default_Search_URL"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
                        "Search Page"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
                        "Start Page"="https://www.msn.com/fr-fr/"
                        "Default_Page_URL"="https://www.msn.com/fr-fr/?ocid=iehp"

                        --------------------\\ Recherche d'autres infections

                        C:\WINDOWS\Pack.epk
                        [b]==> EGDACCESS <==/b

                        --------------------\\ Cracks & Keygens ..

                        D:\DOCUME~1\PATRIC~1.ORD\Bureau\IDM\Crack_UnReal

                        1 - "C:\ToolBar SD\TB_1.txt" - 02/11/2009|18:10 - Option : [1]
                        2 - "C:\ToolBar SD\TB_2.txt" - 02/11/2009|22:18 - Option : [2]

                        -----------\\ Fin du rapport a 22:18:54,42
                        1. Contributeur sécurité
                          bien ca sent bon maintenant...

                          Téléchargez MalwareByte's Anti-Malware
                          https://www.majorgeeks.com/files/details/malwarebytes_anti_malware.html

                          . sur la page cliques sur Télécharger Malwarebyte's Anti-Malware
                          . enregistres le sur le bureau
                          . Double cliques sur le fichier téléchargé pour lancer le processus d'installation.
                          . Dans l'onglet "mise à jour", cliques sur le bouton Recherche de mise à jour
                          . si le pare-feu demande l'autorisation de se connecter pour malwarebytes, acceptes
                          . Une fois la mise à jour terminé
                          . rend-toi dans l'onglet, Recherche
                          . Sélectionnes Exécuter un examen complet
                          . Cliques sur Rechercher
                          . Le scan démarre.
                          . A la fin de l'analyse, un message s'affiche : L'examen s'est terminé normalement. Cliquez sur 'Afficher les résultats' pour afficher tous les objets trouvés.
                          . Cliques sur Ok pour poursuivre.
                          . Si des malwares ont été détectés, cliques sur Afficher les résultats
                          . Sélectionnes tout (ou laisses cochés) et cliques sur Supprimer la sélection Malwarebytes va détruire les fichiers et clés de registre et en mettre une copie dans la quarantaine.
                          . Malwarebytes va ouvrir le bloc-notes et y copier le rapport d'analyse.
                          . rends toi dans l'onglet rapport/log
                          . tu cliques dessus pour l'afficher une fois affiché
                          . tu cliques sur edition en haut du boc notes,et puis sur sélectionner tous
                          . tu recliques sur edition et puis sur copier et tu reviens sur le forum et dans ta réponse
                          . tu cliques droit dans le cadre de la reponse et coller

                          Si tu as besoin d'aide regarde ces tutoriels :
                          Aide: https://www.malekal.com/tutoriel-malwarebyte-anti-malware/
                          http://www.infos-du-net.com/forum/278396-11-tuto-malwarebytes-anti-malware-mbam
                          1. voila le rapport antimalware:
                            Malwarebytes' Anti-Malware 1.41
                            Version de la base de données: 3089
                            Windows 5.1.2600 Service Pack 3

                            03/11/2009 06:47:55
                            mbam-log-2009-11-03 (06-47-55).txt

                            Type de recherche: Examen complet (C:\|D:\|)
                            Eléments examinés: 306172
                            Temps écoulé: 1 hour(s), 26 minute(s), 53 second(s)

                            Processus mémoire infecté(s): 0
                            Module(s) mémoire infecté(s): 0
                            Clé(s) du Registre infectée(s): 1
                            Valeur(s) du Registre infectée(s): 0
                            Elément(s) de données du Registre infecté(s): 2
                            Dossier(s) infecté(s): 0
                            Fichier(s) infecté(s): 0

                            Processus mémoire infecté(s):
                            (Aucun élément nuisible détecté)

                            Module(s) mémoire infecté(s):
                            (Aucun élément nuisible détecté)

                            Clé(s) du Registre infectée(s):
                            HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\office one 450 fonts_is1 (Worm.Archive) -> Quarantined and deleted successfully.

                            Valeur(s) du Registre infectée(s):
                            (Aucun élément nuisible détecté)

                            Elément(s) de données du Registre infecté(s):
                            HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
                            HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

                            Dossier(s) infecté(s):
                            (Aucun élément nuisible détecté)

                            Fichier(s) infecté(s):
                            (Aucun élément nuisible détecté)
                            1. je n'ai que un rapport qui apparait celui la:
                              Logfile of random's system information tool 1.06 (written by random/random)
                              Run by patrice at 2009-11-03 18:04:48
                              Microsoft Windows XP Édition familiale Service Pack 3
                              System drive C: has 8 GB (25%) free of 31 GB
                              Total RAM: 1023 MB (32% free)

                              Logfile of Trend Micro HijackThis v2.0.2
                              Scan saved at 18:04:57, on 03/11/2009
                              Platform: Windows XP SP3 (WinNT 5.01.2600)
                              MSIE: Internet Explorer v8.00 (8.00.6001.18702)
                              Boot mode: Normal

                              Running processes:
                              C:\WINDOWS\System32\smss.exe
                              C:\WINDOWS\system32\winlogon.exe
                              C:\WINDOWS\system32\services.exe
                              C:\WINDOWS\system32\lsass.exe
                              C:\WINDOWS\system32\Ati2evxx.exe
                              C:\WINDOWS\system32\svchost.exe
                              C:\WINDOWS\System32\svchost.exe
                              C:\WINDOWS\system32\svchost.exe
                              C:\WINDOWS\system32\spoolsv.exe
                              C:\WINDOWS\system32\Ati2evxx.exe
                              C:\WINDOWS\Explorer.EXE
                              C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe
                              C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                              C:\Program Files\Bonjour\mDNSResponder.exe
                              c:\APPS\Powercinema\Kernel\TV\CLCapSvc.exe
                              C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe
                              C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLService.exe
                              C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
                              c:\APPS\HIDSERVICE\HIDSERVICE.exe
                              C:\Program Files\Java\jre6\bin\jqs.exe
                              C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
                              C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
                              C:\Program Files\Fichiers communs\Ulead Systems\AutoDetector\monitor.exe
                              C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
                              C:\WINDOWS\SOUNDMAN.EXE
                              C:\Apps\Powercinema\PCMService.exe
                              C:\Program Files\McAfee.com\Agent\mcagent.exe
                              C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIADE.EXE
                              C:\ATI Technologies\ATI Control Panel\atiptaxx.exe
                              C:\apps\ABoard\ABoard.exe
                              c:\PROGRA~1\FICHIE~1\mcafee\mna\mcnasvc.exe
                              C:\Program Files\Java\jre6\bin\jusched.exe
                              C:\apps\ABoard\AOSD.exe
                              C:\Program Files\Orange\Systray\SystrayApp.exe
                              C:\Program Files\QuickTime\QTTask.exe
                              C:\Program Files\iTunes\iTunesHelper.exe
                              c:\PROGRA~1\FICHIE~1\mcafee\mcproxy\mcproxy.exe
                              C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\AlertModule\0\AlertModule.exe
                              C:\WINDOWS\system32\ctfmon.exe
                              C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                              C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
                              C:\Program Files\McAfee\MPF\MPFSrv.exe
                              D:\Spybot - Search & Destroy\TeaTimer.exe
                              C:\Program Files\Orange\Launcher\Launcher.exe
                              C:\Program Files\Messenger\msmsgs.exe
                              C:\Program Files\DAEMON Tools Lite\daemon.exe
                              D:\CDBurnerXP\NMSAccessU.exe
                              C:\WINDOWS\system32\svchost.exe
                              C:\Program Files\Fichiers communs\Ulead Systems\DVD\ULCDRSvr.exe
                              c:\APPS\Powercinema\Kernel\TV\CLSched.exe
                              C:\Program Files\Orange\Deskboard\deskboard.exe
                              C:\Program Files\Orange\connectivity\connectivitymanager.exe
                              C:\Program Files\Orange\connectivity\CoreCom\CoreCom.exe
                              C:\Program Files\iPod\bin\iPodService.exe
                              C:\WINDOWS\system32\wbem\wmiapsrv.exe
                              C:\Program Files\Orange\connectivity\CoreCom\OraConfigRecover.exe
                              C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTCOMModule\0\FTCOMModule.exe
                              C:\WINDOWS\system32\wuauclt.exe
                              C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
                              C:\Program Files\Internet Explorer\iexplore.exe
                              C:\Program Files\Internet Explorer\iexplore.exe
                              D:\Documents and Settings\patrice.ordimaison\Bureau\RSIT.exe
                              C:\Program Files\trend micro\patrice.exe

                              R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                              R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.orange.fr/portail
                              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                              R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
                              R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
                              R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://fr.search.yahoo.com/search?fr=mcafee&p=%s
                              R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
                              R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
                              R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer
                              R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\Program Files\Orange\SearchURLHook\SearchPageURL.dll
                              O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
                              O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - D:\SPYBOT~1\SDHelper.dll
                              O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
                              O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                              O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
                              O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.3.4501.1418\swg.dll
                              O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
                              O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll
                              O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
                              O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
                              O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
                              O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
                              O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
                              O4 - HKLM\..\Run: [Ulead AutoDetector v2] "C:\Program Files\Fichiers communs\Ulead Systems\AutoDetector\monitor.exe"
                              O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
                              O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
                              O4 - HKLM\..\Run: [PHIME2002ASync] "C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" /SYNC
                              O4 - HKLM\..\Run: [PHIME2002A] "C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" /IMEName
                              O4 - HKLM\..\Run: [PCMService] "c:\Apps\Powercinema\PCMService.exe"
                              O4 - HKLM\..\Run: [mcagent_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
                              O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE /Spoil /RemAdvDef /Migration32"
                              O4 - HKLM\..\Run: [EPSON Stylus DX4800 Series] "C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIADE.EXE" /P26 "EPSON Stylus DX4800 Series" /O6 "USB001" /M "Stylus DX4800"
                              O4 - HKLM\..\Run: [ATIPTA] "C:\ATI Technologies\ATI Control Panel\atiptaxx.exe"
                              O4 - HKLM\..\Run: [ACTIVBOARD] c:\apps\ABoard\ABoard.exe
                              O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
                              O4 - HKLM\..\Run: [SystrayORAHSS] "C:\Program Files\Orange\Systray\SystrayApp.exe"
                              O4 - HKLM\..\Run: [ORAHSSSessionManager] C:\Program Files\Orange\SessionManager\SessionManager.exe
                              O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
                              O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
                              O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
                              O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
                              O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                              O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
                              O4 - HKCU\..\Run: [SpybotSD TeaTimer] D:\Spybot - Search & Destroy\TeaTimer.exe
                              O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
                              O4 - HKCU\..\Run: [Mon Widget RMC] "C:\Program Files\Nosibay\Mon Widget RMC\launcher.exe"
                              O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
                              O4 - HKCU\..\RunOnce: [Shockwave Updater] C:\WINDOWS\system32\Adobe\SHOCKW~1\SWHELP~2.EXE -Update -1100465 -"Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; GTB5; .NET CLR 1.1.4322; InfoPath.1; .NET CLR 2.0.50727)" -"http://playskillgames.bwin.com/t/v/client/info?action=gameClient&tournamentSessionId=20148225&pwd=NSSRYDPDIOIE"
                              O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe (User 'SERVICE LOCAL')
                              O4 - HKUS\S-1-5-19\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background (User 'SERVICE LOCAL')
                              O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe (User 'SERVICE RÉSEAU')
                              O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
                              O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
                              O4 - Global Startup: Sagem - Utilitaire réseau pour Clé USB Wi-Fi 802.11g.lnk = ?
                              O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\DOCUME~1\PATRIC~1.ORD\MESDOC~1\msoffice\OFFICE11\REFIEBAR.DLL
                              O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
                              O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - D:\SPYBOT~1\SDHelper.dll
                              O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - D:\SPYBOT~1\SDHelper.dll
                              O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                              O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                              O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                              O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                              O14 - IERESET.INF: START_PAGE_URL=file://C:\APPS\IE\offline\fr.htm
                              O15 - Trusted Zone: https://www.orange.fr/portail
                              O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - https://www.kaspersky.fr/?domain=webscanner.kaspersky.fr
                              O16 - DPF: {104B0A37-AB99-4F06-8032-8BBDC3B77DDB} (Telechargement Control) - http://www4.photoweb.fr/telechargement/Photoweb_uploader.cab
                              O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
                              O16 - DPF: {1F83CD9E-505E-4F87-BECE-0832A763E36F} (Image Uploader 3.0 Control) - http://www.mypixmania.com/importer/MypixUploader.cab
                              O16 - DPF: {34DC6011-88B5-4EA9-BA7A-DC7B4F4437FE} (JordanUploader Class) - http://photoservice.fujicolor.de/ips-opdata/objects/jordan.cab
                              O16 - DPF: {3EA4FA88-E0BE-419A-A732-9B79B87A6ED0} (CTVUAxCtrl Object) - http://dl.tvunetworks.com/TVUAx.cab
                              O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by15fd.bay15.hotmail.msn.com/resources/MsnPUpld.cab
                              O16 - DPF: {5D637FAD-E202-48D1-8F18-5B9C459BD1E3} (Image Uploader Control) - http://www.photoweb.fr/moncompte/Account/LogOn?ReturnUrl=%2ftransfert
                              O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} (Symantec Download Manager) - https://webdl.symantec.com/activex/symdlmgr.cab
                              O16 - DPF: {6E5E167B-1566-4316-B27F-0DDAB3484CF7} (Image Uploader Control) - http://www.mypix.com/importer/ImageUploader4.cab
                              O16 - DPF: {AE2B937E-EA7D-4A8D-888C-B68D7F72A3C4} (IPSUploader4 Control) - http://photoservice.fujicolor.de/ips-opdata/operator/27859021/activex/IPSUploader4.cab
                              O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
                              O17 - HKLM\System\CCS\Services\Tcpip\..\{9269FBB6-E91A-4C38-AF73-012A2FE97739}: NameServer = 192.168.1.1
                              O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
                              O23 - Service: McAfee Application Installer Cleanup (0182071257250760) (0182071257250760mcinstcleanup) - McAfee, Inc. - C:\WINDOWS\TEMP\018207~1.EXE
                              O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe
                              O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                              O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
                              O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
                              O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - c:\APPS\Powercinema\Kernel\TV\CLCapSvc.exe
                              O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - c:\APPS\Powercinema\Kernel\TV\CLSched.exe
                              O23 - Service: CyberLink Media Library Service - Cyberlink - C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe
                              O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom SA - C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
                              O23 - Service: Generic Service for HID Keyboard Input Collections (GenericHidService) - Unknown owner - c:\APPS\HIDSERVICE\HIDSERVICE.exe
                              O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                              O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
                              O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
                              O23 - Service: McAfee SiteAdvisor Service - Unknown owner - C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
                              O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
                              O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\FICHIE~1\mcafee\mna\mcnasvc.exe
                              O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
                              O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\FICHIE~1\mcafee\mcproxy\mcproxy.exe
                              O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
                              O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
                              O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
                              O23 - Service: MysqlInventime - Unknown owner - C:\Apps\INVENT~1\mysql\bin\mysqld-nt.exe
                              O23 - Service: NMSAccessU - Unknown owner - D:\CDBurnerXP\NMSAccessU.exe
                              O23 - Service: Planificateur LiveUpdate automatique - Unknown owner - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe (file missing)
                              O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcsvc.exe
                              O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Fichiers communs\Ulead Systems\DVD\ULCDRSvr.exe
                              O24 - Desktop Component 1: (no name) - https://www.ebay.fr/
                              1. Contributeur sécurité
                                pour moi c'est tout bon

                                retélécharges Hijackthis
                                lances Hijackthis
                                Au menu principal, choisir do a scan only, puis cocher la case devant les lignes suivantes à corriger et cliquer en bas sur Fix Checked

                                R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
                                R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
                                O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - D:\SPYBOT~1\SDHelper.dll
                                O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
                                O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
                                O4 - Global Startup: Sagem - Utilitaire réseau pour Clé USB Wi-Fi 802.11g.lnk = ?
                                O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - D:\SPYBOT~1\SDHelper.dll
                                O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - D:\SPYBOT~1\SDHelper.dll
                                O23 - Service: McAfee Application Installer Cleanup (0182071257250760) (0182071257250760mcinstcleanup) - McAfee, Inc. - C:\WINDOWS\TEMP\018207~1.EXE
                                O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
                                O4 - HKLM\..\Run: [PHIME2002ASync] "C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" /SYNC
                                O4 - HKLM\..\Run: [PHIME2002A] "C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" /IMEName
                                O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE /Spoil /RemAdvDef /Migration32"
                                O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
                                O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                                O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
                                O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe (User 'SERVICE LOCAL')
                                O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe (User 'SERVICE RÉSEAU')
                                O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
                                O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
                                O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe

                                ensuite purge de la restauration

                                http://www.bibou0007.com/windows-xp-f101/purger-la-restauration-du-systeme-sous-windows-xp-t151.htm

                                et me dire comment va le pc
                                1. alors j'ai fait ce que tu m'as dit dans hijackthis mais apres tu me dit purge de la restauration ,c'est quoi??? sinon l'ordinateur ne rame plus ,et derniere question est ce que je peut reinstalle la barre google?
                                  1. Contributeur sécurité
                                    purger la restauration est important, car dans "l'historique" de ton pc se cachent des virus...il faut les eliminer ainsi

                                    ensuite nettoyage des outils de désinfection

                                    ▶---> Télécharge ToolsCleaner2sur ton Bureau.
                                    https://www.commentcamarche.net/telecharger/securite/22061-toolscleaner/

                                    * Double-clique (clic droit "en tant qu'administrateur" pour Vista) sur ToolsCleaner2.exe pour le lancer.
                                    * Clique sur Recherche et laisse le scan agir.
                                    * Clique sur Suppression pour finaliser.
                                    * Tu peux, si tu le souhaites, te servir des Options Facultatives.
                                    * Clique sur Quitter pour obtenir le rapport.
                                    * Poste le rapport (TCleaner.txt) qui se trouve à la racine de ton disque dur (C:\).
                                    • 1
                                    • 2