Malware defense infection

Bonjour,

J'ai un problème avec mon ordinateur portable!
Je n'était pas chez moi, j'ai donc laisser mon ordinateur a mes parents, or une fenêtre est apparut disant que le PC courait des risques, mes parent ont donc cru bien faire en installant un logiciel!

Depuis ceci, des page de pub incessantes, des messages d'erreurs, msn bloquer...

Que faire?

Merci d'avance pour votre aide

A bientot
Configuration: Windows XP
Firefox 3.0.16

33 réponses

Résumé de la discussion

Un problème d'infection informatique survient après qu'une fenêtre signale des risques et pousse à installer un logiciel, provoquant des publicités incessantes et des messages d'erreur. Plusieurs signes d'infection apparaissent et la solution préconisée consiste à déconnecter l'ordinateur du réseau et à lancer une désinfection avec un outil comme ComboFix, en suivant les étapes proposées. Le processus comprend la suppression des programmes indésirables, le nettoyage du registre, puis la réactivation des protections antivirus et antispyware une fois le nettoyage terminé. Des rapports et outils complémentaires comme USBFix permettent de vérifier l'état du système et de prévenir les résurgences, notamment en identifiant des éléments persistants et des programmes démarrés automatiquement.

Bobot (l’IA à votre service)
  1. Contributeur sécurité
    slt restaure le pc avant le souci

    http://www.infoprat.net/astuces/windows2k_xp/astuces/divers_004.php

    puis dis si cela persiste

    et

    Télécharge ici :

    http://images.malwareremoval.com/random/RSIT.exe

    random's system information tool (RSIT) par andom/random et sauvegarde-le sur le Bureau.

    Double-clique sur RSIT.exe afin de lancer RSIT.

    Clique Continue à l'écran Disclaimer.

    Si l'outil HijackThis (version à jour) n'est pas présent ou non détecté sur l'ordinateur, RSIT le téléchargera (autorise l'accès dans ton pare-feu, si demandé) et tu devras accepter la licence.

    Lorsque l'analyse sera terminée, deux fichiers texte s'ouvriront.

    Poste le contenu de log.txt (<<qui sera affiché)
    ainsi que de info.txt (<<qui sera réduit dans la Barre des Tâches).

    NB : Les rapports sont sauvegardés dans le dossier C:\rsit
    0
    1. slt, je ne suis pa specialiste mais je pense en savoir asser pour te dire ke ton ordi est infecté .
      as tu un anti-virus anti-spyware ...

      si oui les quels ?
      0
      1. je n'arive a rien, mon ordinateur se bloque,tout est bloquer,souris, clavierbbb
        j'etein en le forcan,je ralume et je tente de restaure mais ca bloque avant que j'ai le temps de valider,et quand j'ai le temps je clik sur suivant mais rien ne se passe,que faire? je nai aucun souci sur les autre session.
        0
        1. Désolé pour l'orthographe de mon message précédent, j'ai écrit depuis mon portable!
          Le problème existe uniquement sur ma session (mes parents l'utilise également), rien ne se passe lorsque je valide la restauration, il n'y a plus le logo de mon antivirus antivirus!
          Par moment l'ordinateur se bloque après l'affichage d'une fenêtre me disant que j'ai un virus "Virus.Win32.Hala.a"!
          Je doit faire quoi?
          merci de votre aide
          0
          1. info.txt logfile of random's system information tool 1.06 2010-01-02 22:31:02

            ======Uninstall list======

            -->C:\WINDOWS\IsUn040c.exe -fC:\WINDOWS\orun32.isu
            -->C:\WINDOWS\system32\\MSIEXEC.EXE /x {075473F5-846A-448B-BCB3-104AA1760205}
            -->C:\WINDOWS\system32\\MSIEXEC.EXE /x {AB708C9B-97C8-4AC9-899B-DBF226AC9382}
            -->C:\WINDOWS\system32\\MSIEXEC.EXE /x {B12665F4-4E93-4AB4-B7FC-37053B524629}
            -->MsiExec /X{E2BE1618-AF5F-4F7D-8484-42E080EDF609}
            -->MsiExec.exe /X{69495273-FCDC-4A86-BCB7-49B504D3FB0E}
            -->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{939F8208-C8CE-4AFF-B7BA-ACEB2E74A6CB}\Setup.exe"
            -->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
            Adobe Acrobat 5.0-->C:\WINDOWS\ISUN040C.EXE -f"C:\Program Files\Fichiers communs\Adobe\Acrobat 5.0\NT\Uninst.isu" -c"C:\Program Files\Fichiers communs\Adobe\Acrobat 5.0\NT\Uninst.dll"
            Adobe Flash Player 10 ActiveX-->C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
            Adobe Flash Player 10 Plugin-->C:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe
            Adobe Flash Player 9 ActiveX-->C:\WINDOWS\system32\Macromed\Flash\FlashUtil9b.exe -uninstallDelete
            Adobe Reader 7.1.0 - Français-->MsiExec.exe /I{AC76BA86-7AD7-1036-7B44-A71000000002}
            Adobe Shockwave Player 11-->C:\WINDOWS\system32\adobe\SHOCKW~1\UNWISE.EXE C:\WINDOWS\system32\Adobe\SHOCKW~1\Install.log
            Age of Empires III - The WarChiefs-->C:\PROGRA~1\FICHIE~1\INSTAL~1\Driver\11\INTEL3~1\IDriver.exe /M{1C08A24C-B168-407E-A826-68FAF5F20710}
            Age of Empires III-->C:\PROGRA~1\FICHIE~1\INSTAL~1\Driver\11\INTEL3~1\IDriver.exe /M{485775E8-AEB8-46BD-922B-242879E03DD5}
            AGEIA PhysX v7.01.12-->MsiExec.exe /X{E2BE1618-AF5F-4F7D-8484-42E080EDF609}
            Alien Arena 2007-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{5F0EADB2-0E9B-4A8E-8FE4-ADE6BC47253B}\setup.exe" -l0x9
            Amélioration de nos services-->C:\PROGRA~1\FICHIE~1\INSTAL~1\Driver\1050\INTEL3~1\IDriver.exe /M{23012310-3E05-46A5-88A9-C6CBCABCAC79} /l1036
            Application Suite-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{A8C3A9E8-07F4-4D44-BB9D-C4AE5D230468}\Setup.exe" -l0x40c
            Archiveur WinRAR-->C:\Program Files\WinRAR\uninstall.exe
            ArcSoft PhotoImpression 4-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{68D5CEF9-0DA8-47FE-B0EB-4CBFB5AAF662}\setup.exe" -l0x40c
            Ares 2.1.1-->"C:\Program Files\Ares\uninstall.exe"
            Assistant de connexion Windows Live-->MsiExec.exe /I{D3116CC7-24DC-4CA3-9CE1-23FED836E9F2}
            Avira AntiVir Personal - Free Antivirus-->C:\Program Files\Avira\AntiVir PersonalEdition Classic\SETUP.EXE /REMOVE
            Brother MFL-Pro Suite-->"C:\Program Files\InstallShield Installation Information\{A3FEC306-FBFF-4B0D-95B9-F9C67C65079E}\Setup.exe" -runfromtemp -l0x040c Brunin03.dll -removeonly
            Celtx (0.9.9.1)-->C:\Program Files\Celtx\uninstall\uninst.exe
            Chaos-League-->C:\Program Files\Cyanide\Chaos-League\uninstall.exe
            Condition Zero-->"C:\Program Files\Steam\steam.exe" steam://uninstall/80
            Conexant HD Audio-->C:\Program Files\CONEXANT\CNXT_HDAUDIO\HXFSETUP.EXE -U -IAt8VEN5a.inf
            Connexion Facile à Internet-->C:\PROGRA~1\FICHIE~1\INSTAL~1\Driver\1050\INTEL3~1\IDriver.exe /M{8105684D-8CA6-440D-8F58-7E5FD67A499D} /l1036
            Correctif pour Lecteur Windows Media 11 (KB939683)-->"C:\WINDOWS\$NtUninstallKB939683$\spuninst\spuninst.exe"
            Correctif pour Windows Internet Explorer 7 (KB947864)-->"C:\WINDOWS\ie7updates\KB947864-IE7\spuninst\spuninst.exe"
            Correctif pour Windows XP (KB952287)-->"C:\WINDOWS\$NtUninstallKB952287$\spuninst\spuninst.exe"
            Correctif pour Windows XP (KB961118)-->"C:\WINDOWS\$NtUninstallKB961118$\spuninst\spuninst.exe"
            Correctif pour Windows XP (KB970653-v3)-->"C:\WINDOWS\$NtUninstallKB970653-v3$\spuninst\spuninst.exe"
            Correctif pour Windows XP (KB976098-v2)-->"C:\WINDOWS\$NtUninstallKB976098-v2$\spuninst\spuninst.exe"
            Crawler Toolbar-->C:\PROGRA~1\Crawler\CToolbar.exe uninst
            CSI-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\0700\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{3BA044B0-A5E4-428E-8731-63BD5DD4FDB2}\setup.exe" -l0x40c
            Dawn of War - Dark Crusade-->C:\Program Files\InstallShield Installation Information\{FF39FC01-819B-42E4-AE49-1968AF12DDD4}\setup.exe -runfromtemp -l0x040c -removeonly
            Day of Defeat: Source-->"C:\Program Files\Steam\steam.exe" steam://uninstall/300
            Disc2Phone-->MsiExec.exe /X{1C75E8E0-29D5-4298-AE16-B8604FD9DDE4}
            ESET Online Scanner-->C:\WINDOWS\system32\OnlineScannerUninstaller.exe
            Everest Poker (Remove Only)-->C:\Program Files\Everest Poker\cstart.exe /uninstall
            Galerie de photos Windows Live-->MsiExec.exe /X{B131E59D-202C-43C6-84C9-68F0C37541F1}
            GameCenter-->C:\Program Files\Cyanide\GameCenter\uninstall.exe
            GemMaster Mystic-->"C:\Program Files\GemMasterFrench\uninstallgemmaster.exe"
            GIMP 2.6.4-->"C:\Program Files\GIMP-2.0\setup\unins000.exe"
            Google Update Helper-->MsiExec.exe /I{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}
            Google Earth-->MsiExec.exe /X{C084BC61-E537-11DE-8616-005056806466}
            GTK+ 2.10.13 runtime environment-->"C:\Program Files\Fichiers communs\GTK\2.0\setup\unins000.exe"
            Half-Life 2: Deathmatch-->"C:\Program Files\Steam\steam.exe" steam://uninstall/320
            Half-Life 2: Lost Coast-->"C:\Program Files\Steam\steam.exe" steam://uninstall/340
            HijackThis 2.0.2-->"C:\Program Files\Trend Micro\HijackThis\HijackThis.exe" /uninstall
            Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)-->C:\WINDOWS\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall /qb+ REBOOTPROMPT=""
            Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)-->C:\WINDOWS\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {A7EEA2F2-BFCD-4A54-A575-7B81A786E658} /qb+ REBOOTPROMPT=""
            Hotfix for Windows Media Format 11 SDK (KB929399)-->"C:\WINDOWS\$NtUninstallKB929399$\spuninst\spuninst.exe"
            HP Help and Support-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\10\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{A93C4E94-1005-489D-BEAA-B873C1AA6CFC}\setup.exe" -l0x40c -removeonly
            HP Imaging Device Functions 6.0-->C:\Program Files\HP\Digital Imaging\DigitalImagingMonitor\hpzscr01.exe -datfile hpqbud01.dat
            HP Photosmart Premier Software 6.0-->C:\Program Files\HP\Digital Imaging\uninstall\hpzscr01.exe -datfile hpqscr01.dat
            HP Quick Launch Buttons 6.10 A2-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{34D2AB40-150D-475D-AE32-BD23FB5EE355}\setup.exe" -l0x40c -removeonly uninst
            HP QuickPlay 2.3-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{45D707E9-F3C4-11D9-A373-0050BAE317E1}\setup.exe" -uninstall
            HP Update-->MsiExec.exe /X{818ABC3C-635C-4651-8183-D0E9640B7DD1}
            HP User Guides 0035-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\10\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{BE247E71-C143-40BB-ADF2-A465DF062BAB}\Setup.exe" -l0x40c -removeonly
            HP Wireless Assistant 2.00 G2-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{4302B2DD-D958-40E3-BAF3-B07FFE1978CE}\setup.exe" -l0x40c hpquninst
            Installation Windows Live-->C:\Program Files\Windows Live\Installer\wlarp.exe
            Installation Windows Live-->MsiExec.exe /I{46ABBC54-1872-4AA3-95E2-F2C063A63F31}
            Intel(R) PRO Network Connections Drivers-->Prounstl.exe
            iPod Updater 2004-11-15-->C:\Program Files\Fichiers communs\InstallShield\Driver\8\Intel 32\IDriver.exe /M{06E73C0B-7DE7-4F41-860B-587033B75BD9} /l1036
            iTunes-->C:\Program Files\Fichiers communs\InstallShield\Driver\8\Intel 32\IDriver.exe /M{BE20E2F5-1903-4AAE-B1AF-2046E586C925}
            J2SE Runtime Environment 5.0 Update 6-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0150060}
            Java(TM) 6 Update 17-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216011FF}
            Java(TM) 6 Update 3-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160030}
            Java(TM) 6 Update 5-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160050}
            Java(TM) 6 Update 7-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160070}
            Jazz Jackrabbit 2-->C:\Games\Jazz2\UnInst.exe C:\Games\Jazz2\UnInst.j2
            Junk Mail filter update-->MsiExec.exe /I{E2DFE069-083E-4631-9B6C-43C48E991DE5}
            Kaspersky Online Scanner-->C:\WINDOWS\system32\KASPER~1\KASPER~1\kavuninstall.exe
            KC Softwares VideoInspector-->"C:\Program Files\KC Softwares\VideoInspector\unins000.exe"
            Lecteur Windows Media 11-->"C:\Program Files\Windows Media Player\Setup_wm.exe" /Uninstall
            Macromedia Flash Player 8-->MsiExec.exe /X{6815FCDD-401D-481E-BA88-31B4754C2B46}
            Macromedia Shockwave Player-->MsiExec.exe /X{838A1BC9-95CA-4880-9BE3-2A7D23600A2B}
            MAIET entertainment - Gunz-->C:\Program Files\MAIET\Gunz\Uninstall.exe
            Malware Defense-->C:\Program Files\Malware Defense\Uninstall.exe
            Malwarebytes' Anti-Malware-->"C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
            MegaCam-->C:\Program Files\InstallShield Installation Information\{77F69001-4D35-4BEA-A074-26DA04EA0CDA}\setup.exe -runfromtemp -l0x040c -removeonly
            Microsoft .NET Framework 1.0 Hotfix (KB953295)-->"C:\WINDOWS\$NtUninstallKB953295$\spuninst\spuninst.exe"
            Microsoft .NET Framework 1.1 French Language Pack-->MsiExec.exe /X{9A394342-4A68-4EBA-85A6-55B559F4E700}
            Microsoft .NET Framework 1.1 Security Update (KB953297)-->"C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\hotfix.exe" "C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\M953297\M953297Uninstall.msp"
            Microsoft .NET Framework 1.1-->msiexec.exe /X {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
            Microsoft .NET Framework 1.1-->MsiExec.exe /X{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
            Microsoft .NET Framework 2.0 Service Pack 2-->MsiExec.exe /I{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}
            Microsoft .NET Framework 3.0 Service Pack 2-->MsiExec.exe /I{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}
            Microsoft .NET Framework 3.5 SP1-->C:\WINDOWS\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setup.exe
            Microsoft .NET Framework 3.5 SP1-->MsiExec.exe /I{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}
            Microsoft ActiveSync-->MsiExec.exe /I{99052DB7-9592-4522-A558-5417BBAD48EE}
            Microsoft Choice Guard-->MsiExec.exe /X{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}
            Microsoft Compression Client Pack 1.0 for Windows XP-->"C:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe"
            Microsoft Internationalized Domain Names Mitigation APIs-->"C:\WINDOWS\$NtServicePackUninstallIDNMitigationAPIs$\spuninst\spuninst.exe"
            Microsoft National Language Support Downlevel APIs-->"C:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$\spuninst\spuninst.exe"
            Microsoft Search Enhancement Pack-->MsiExec.exe /X{4CBA3D4C-8F51-4D60-B27E-F6B641C571E7}
            Microsoft Silverlight-->MsiExec.exe /X{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
            Microsoft SQL Server 2005 Compact Edition [ENU]-->MsiExec.exe /I{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}
            Microsoft Sync Framework Runtime Native v1.0 (x86)-->MsiExec.exe /I{8A74E887-8F0F-4017-AF53-CBA42211AAA5}
            Microsoft Sync Framework Services Native v1.0 (x86)-->MsiExec.exe /I{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}
            Microsoft User-Mode Driver Framework Feature Pack 1.0-->"C:\WINDOWS\$NtUninstallWudf01000$\spuninst\spuninst.exe"
            Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053-->MsiExec.exe /X{770657D0-A123-3C07-8E44-1C83EC895118}
            Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
            Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{A49F249F-0C91-497F-86DF-B2585E8E76B7}
            Microsoft Works-->MsiExec.exe /I{A059DE09-1B49-4450-B340-7AE097EC3F04}
            Mini Rally-->C:\WINDOWS\IsUn040c.exe -f"C:\Sierra\Mini Rally\Uninst.isu"
            Mise à jour critique pour Lecteur Windows Media 11 (KB959772)-->"C:\WINDOWS\$NtUninstallKB959772_WM11$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Lecteur Windows Media (KB952069)-->"C:\WINDOWS\$NtUninstallKB952069_WM9$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Lecteur Windows Media (KB954155)-->"C:\WINDOWS\$NtUninstallKB954155_WM9$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Lecteur Windows Media (KB968816)-->"C:\WINDOWS\$NtUninstallKB968816_WM9$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Lecteur Windows Media (KB973540)-->"C:\WINDOWS\$NtUninstallKB973540_WM9$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Lecteur Windows Media 10 (KB911565)-->"C:\WINDOWS\$NtUninstallKB911565$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Lecteur Windows Media 10 (KB917734)-->"C:\WINDOWS\$NtUninstallKB917734_WMP10$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Lecteur Windows Media 10 (KB936782)-->"C:\WINDOWS\$NtUninstallKB936782_WMP10$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Lecteur Windows Media 11 (KB936782)-->"C:\WINDOWS\$NtUninstallKB936782_WMP11$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Lecteur Windows Media 11 (KB954154)-->"C:\WINDOWS\$NtUninstallKB954154_WM11$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Step by Step Interactive Training (KB923723)-->"C:\WINDOWS\$NtUninstallKB923723$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows Internet Explorer 7 (KB938127)-->"C:\WINDOWS\ie7updates\KB938127-IE7\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows Internet Explorer 7 (KB939653)-->"C:\WINDOWS\ie7updates\KB939653-IE7\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows Internet Explorer 7 (KB942615)-->"C:\WINDOWS\ie7updates\KB942615-IE7\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows Internet Explorer 7 (KB944533)-->"C:\WINDOWS\ie7updates\KB944533-IE7\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows Internet Explorer 7 (KB950759)-->"C:\WINDOWS\ie7updates\KB950759-IE7\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows Internet Explorer 7 (KB953838)-->"C:\WINDOWS\ie7updates\KB953838-IE7\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows Internet Explorer 7 (KB956390)-->"C:\WINDOWS\ie7updates\KB956390-IE7\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows Internet Explorer 7 (KB958215)-->"C:\WINDOWS\ie7updates\KB958215-IE7\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows Internet Explorer 7 (KB960714)-->"C:\WINDOWS\ie7updates\KB960714-IE7\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows Internet Explorer 7 (KB961260)-->"C:\WINDOWS\ie7updates\KB961260-IE7\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows Internet Explorer 7 (KB963027)-->"C:\WINDOWS\ie7updates\KB963027-IE7\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows Internet Explorer 7 (KB969897)-->"C:\WINDOWS\ie7updates\KB969897-IE7\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows Internet Explorer 8 (KB969897)-->"C:\WINDOWS\ie8updates\KB969897-IE8\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows Internet Explorer 8 (KB971961)-->"C:\WINDOWS\ie8updates\KB971961-IE8\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows Internet Explorer 8 (KB972260)-->"C:\WINDOWS\ie8updates\KB972260-IE8\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows Internet Explorer 8 (KB974455)-->"C:\WINDOWS\ie8updates\KB974455-IE8\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows Internet Explorer 8 (KB976325)-->"C:\WINDOWS\ie8updates\KB976325-IE8\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB923561)-->"C:\WINDOWS\$NtUninstallKB923561$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB938464)-->"C:\WINDOWS\$NtUninstallKB938464$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB941569)-->"C:\WINDOWS\$NtUninstallKB941569$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB946648)-->"C:\WINDOWS\$NtUninstallKB946648$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB950760)-->"C:\WINDOWS\$NtUninstallKB950760$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB950762)-->"C:\WINDOWS\$NtUninstallKB950762$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB950974)-->"C:\WINDOWS\$NtUninstallKB950974$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB951066)-->"C:\WINDOWS\$NtUninstallKB951066$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB951376)-->"C:\WINDOWS\$NtUninstallKB951376$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB951376-v2)-->"C:\WINDOWS\$NtUninstallKB951376-v2$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB951698)-->"C:\WINDOWS\$NtUninstallKB951698$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB951748)-->"C:\WINDOWS\$NtUninstallKB951748$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB952004)-->"C:\WINDOWS\$NtUninstallKB952004$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB952954)-->"C:\WINDOWS\$NtUninstallKB952954$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB953839)-->"C:\WINDOWS\$NtUninstallKB953839$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB954211)-->"C:\WINDOWS\$NtUninstallKB954211$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB954459)-->"C:\WINDOWS\$NtUninstallKB954459$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB954600)-->"C:\WINDOWS\$NtUninstallKB954600$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB955069)-->"C:\WINDOWS\$NtUninstallKB955069$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB956391)-->"C:\WINDOWS\$NtUninstallKB956391$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB956572)-->"C:\WINDOWS\$NtUninstallKB956572$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB956744)-->"C:\WINDOWS\$NtUninstallKB956744$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB956802)-->"C:\WINDOWS\$NtUninstallKB956802$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB956803)-->"C:\WINDOWS\$NtUninstallKB956803$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB956841)-->"C:\WINDOWS\$NtUninstallKB956841$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB956844)-->"C:\WINDOWS\$NtUninstallKB956844$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB957095)-->"C:\WINDOWS\$NtUninstallKB957095$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB957097)-->"C:\WINDOWS\$NtUninstallKB957097$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB958644)-->"C:\WINDOWS\$NtUninstallKB958644$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB958687)-->"C:\WINDOWS\$NtUninstallKB958687$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB958690)-->"C:\WINDOWS\$NtUninstallKB958690$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB958869)-->"C:\WINDOWS\$NtUninstallKB958869$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB959426)-->"C:\WINDOWS\$NtUninstallKB959426$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB960225)-->"C:\WINDOWS\$NtUninstallKB960225$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB960715)-->"C:\WINDOWS\$NtUninstallKB960715$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB960803)-->"C:\WINDOWS\$NtUninstallKB960803$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB960859)-->"C:\WINDOWS\$NtUninstallKB960859$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB961371)-->"C:\WINDOWS\$NtUninstallKB961371$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB961373)-->"C:\WINDOWS\$NtUninstallKB961373$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB961501)-->"C:\WINDOWS\$NtUninstallKB961501$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB968537)-->"C:\WINDOWS\$NtUninstallKB968537$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB969059)-->"C:\WINDOWS\$NtUninstallKB969059$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB969898)-->"C:\WINDOWS\$NtUninstallKB969898$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB969947)-->"C:\WINDOWS\$NtUninstallKB969947$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB970238)-->"C:\WINDOWS\$NtUninstallKB970238$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB970430)-->"C:\WINDOWS\$NtUninstallKB970430$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB971486)-->"C:\WINDOWS\$NtUninstallKB971486$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB971557)-->"C:\WINDOWS\$NtUninstallKB971557$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB971633)-->"C:\WINDOWS\$NtUninstallKB971633$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB971657)-->"C:\WINDOWS\$NtUninstallKB971657$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB973346)-->"C:\WINDOWS\$NtUninstallKB973346$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB973354)-->"C:\WINDOWS\$NtUninstallKB973354$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB973507)-->"C:\WINDOWS\$NtUninstallKB973507$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB973525)-->"C:\WINDOWS\$NtUninstallKB973525$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB973869)-->"C:\WINDOWS\$NtUninstallKB973869$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB973904)-->"C:\WINDOWS\$NtUninstallKB973904$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB974112)-->"C:\WINDOWS\$NtUninstallKB974112$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB974318)-->"C:\WINDOWS\$NtUninstallKB974318$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB974392)-->"C:\WINDOWS\$NtUninstallKB974392$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB974571)-->"C:\WINDOWS\$NtUninstallKB974571$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB975025)-->"C:\WINDOWS\$NtUninstallKB975025$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB975467)-->"C:\WINDOWS\$NtUninstallKB975467$\spuninst\spuninst.exe"
            Mise à jour pour Lecteur Windows Media 10 (KB910393)-->"C:\WINDOWS\$NtUninstallKB910393$\spuninst\spuninst.exe"
            Mise à jour pour Lecteur Windows Media 10 (KB913800)-->"C:\WINDOWS\$NtUninstallKB913800$\spuninst\spuninst.exe"
            Mise à jour pour Lecteur Windows Media 10 (KB926251)-->"C:\WINDOWS\$NtUninstallKB926251$\spuninst\spuninst.exe"
            Mise à jour pour Windows Internet Explorer 8 (KB971180)-->"C:\WINDOWS\ie8updates\KB971180-IE8\spuninst\spuninst.exe"
            Mise à jour pour Windows Internet Explorer 8 (KB976749)-->"C:\WINDOWS\ie8updates\KB976749-IE8\spuninst\spuninst.exe"
            Mise à jour pour Windows XP (KB951072-v2)-->"C:\WINDOWS\$NtUninstallKB951072-v2$\spuninst\spuninst.exe"
            Mise à jour pour Windows XP (KB951978)-->"C:\WINDOWS\$NtUninstallKB951978$\spuninst\spuninst.exe"
            Mise à jour pour Windows XP (KB955839)-->"C:\WINDOWS\$NtUninstallKB955839$\spuninst\spuninst.exe"
            Mise à jour pour Windows XP (KB961503)-->"C:\WINDOWS\$NtUninstallKB961503$\spuninst\spuninst.exe"
            Mise à jour pour Windows XP (KB967715)-->"C:\WINDOWS\$NtUninstallKB967715$\spuninst\spuninst.exe"
            Mise à jour pour Windows XP (KB968389)-->"C:\WINDOWS\$NtUninstallKB968389$\spuninst\spuninst.exe"
            Mise à jour pour Windows XP (KB971737)-->"C:\WINDOWS\$NtUninstallKB971737$\spuninst\spuninst.exe"
            Mise à jour pour Windows XP (KB973687)-->"C:\WINDOWS\$NtUninstallKB973687$\spuninst\spuninst.exe"
            Mise à jour pour Windows XP (KB973815)-->"C:\WINDOWS\$NtUninstallKB973815$\spuninst\spuninst.exe"
            Mozilla Firefox (3.0.16)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
            Mp3tag v2.43-->C:\Program Files\Mp3tag\Mp3tagUninstall.EXE
            MS Access 97 SP2-->C:\Program Files\Microsoft Office\setup\setup.exe
            MSVCRT-->MsiExec.exe /I{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}
            MSXML 4.0 SP2 (KB927978)-->MsiExec.exe /I{37477865-A3F1-4772-AD43-AAFC6BCFF99F}
            MSXML 4.0 SP2 (KB936181)-->MsiExec.exe /I{C04E32E0-0416-434D-AFB9-6969D703A9EF}
            MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
            MSXML 4.0 SP2 (KB973688)-->MsiExec.exe /I{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}
            NetWaiting-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{3F92ABBB-6BBF-11D5-B229-002078017FBF}\setup.exe" -l0x40c ControlPanel
            Norton Security Scan-->MsiExec.exe /I{1A8A214F-6BAC-4E01-A27D-25C19A484908}
            NVIDIA Drivers-->C:\WINDOWS\system32\nvudisp.exe UninstallGUI
            OpenOffice.org Installer 1.0-->MsiExec.exe /X{3A2AF807-9F9F-43C9-A24A-17B617238B74}
            Orange - Logiciels Internet-->C:\Program Files\Orange\installation\core\Installgui.exe -u
            Otto-->"C:\Program Files\FrenchOtto\uninstallotto.exe"
            Outil de mise à jour Google-->"C:\Program Files\Google\Google Updater\GoogleUpdater.exe" -uninstall
            Outil de téléchargement Windows Live-->MsiExec.exe /I{205C6BDD-7B73-42DE-8505-9A093F35A238}
            PakMan 2008-->"C:\Program Files\FreeGamePick.com\PakMan 2008\unins000.exe"
            PaperPort Image Printer-->MsiExec.exe /X{332CC6BF-E6C7-48EE-BA3D-435E576AD67F}
            PokerStars.net-->"C:\Program Files\PokerStars.NET\PokerStarsUninstall.exe" /u:PokerStars.net
            Project64 1.6-->MsiExec.exe /X{9559F7CA-5E34-4237-A2D9-D856464AD727}
            QuickTime-->C:\WINDOWS\unvise32qt.exe C:\WINDOWS\system32\QuickTime\Uninstall.log
            Ressources Windows Mobile-->C:\Program Files\Ressources Windows Mobile\Windows Mobile Device Handbook\Bin\DHUninstall.exe
            RGSS de RMXP version 1.0.1-->"C:\Program Files\Bodom-Child - RaBBi\RGSS\unins000.exe"
            RMXP version 1.0.0.1-->"C:\Program Files\Bodom-Child - RaBBi\RMXP\unins000.exe"
            RPG Maker 2003-->C:\Documents and Settings\nolwen boucher\Mes documents\My Games\CREA JEU\Désinstaller.exe
            SAMSUNG CDMA Modem Driver Set-->C:\WINDOWS\system32\Samsung_USB_Drivers\3\SSCDUninstall.exe
            Samsung Digital Camera-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{8B79684C-6DAC-438C-8F30-10DF65C2068F}\Setup.exe"
            Samsung Master-->C:\Program Files\InstallShield Installation Information\{AEC0CEBC-0FC7-4716-8222-1C4A742719B1}\Setup.exe -runfromtemp -l0x040c -removeonly
            SAMSUNG Mobile USB Modem 1.0 Software-->C:\WINDOWS\system32\Samsung_USB_Drivers\1\SS_Uninstall.exe
            SAMSUNG Mobile USB Modem Software-->C:\WINDOWS\system32\Samsung_USB_Drivers\2\SSM_Uninstall.exe
            Samsung PC Studio 3 USB Driver Installer-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\10\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{EBA29752-DDD2-4B62-B2E3-9841F92A3E3A}\setup.exe" -l0x40c -removeonly
            ScanSoft PaperPort 11-->MsiExec.exe /I{B6C89654-A6A2-477C-873B-724EC1C56407}
            Security Update for CAPICOM (KB931906)-->MsiExec.exe /I{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
            Security Update for CAPICOM (KB931906)-->MsiExec.exe /X{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
            Segoe UI-->MsiExec.exe /I{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}
            Soft Data Fax Modem with SmartCP-->C:\Program Files\CONEXANT\CNXT_MODEM_PCI_VEN_14F1&DEV_5045_at8ven5m\HXFSETUP.EXE -U -IAt8VEN5m.inf
            Sonic Audio Module-->MsiExec.exe /I{AB708C9B-97C8-4AC9-899B-DBF226AC9382}
            Sonic Copy Module-->MsiExec.exe /I{B12665F4-4E93-4AB4-B7FC-37053B524629}
            Sonic Data Module-->MsiExec.exe /I{075473F5-846A-448B-BCB3-104AA1760205}
            Sonic Express Labeler-->MsiExec.exe /I{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}
            Sonic MyDVD Plus-->MsiExec.exe /I{21657574-BD54-48A2-9450-EB03B2C7FC29}
            Sonic Update Manager-->MsiExec.exe /I{30465B6C-B53F-49A1-9EBA-A3F187AD502E}
            SonicAC3Encoder-->MsiExec.exe /I{52FBAE98-D389-4281-8C14-21B4046CCB4E}
            SonicMPEGEncoder-->MsiExec.exe /I{B16AF568-A644-483C-A6DA-5028CD019C8C}
            SopCast 1.1.2-->C:\Program Files\SopCast\uninst.exe
            Sprite Backup HTC-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{52D3199D-2858-4216-AA1D-B2A9BB9FA31B}\setup.exe" -l0x40c
            Steam(TM)-->MsiExec.exe /X{048298C9-A4D3-490B-9FF9-AB023A9238F3}
            SweetIM for Messenger 2.8-->MsiExec.exe /X{DF6F459C-8B89-4F88-B63F-A2E136BB6B79}
            SweetIM Toolbar for Internet Explorer 3.6-->MsiExec.exe /X{31CF6C0E-51F0-41D2-B088-A6A143C4303C}
            Switch Uninstall-->C:\Program Files\NCH Swift Sound\Switch\uninst.exe
            Synaptics Pointing Device Driver-->rundll32.exe "C:\Program Files\Synaptics\SynTP\SynISDLL.dll",standAloneUninstall
            Thoosje Sidebar V2.3-->C:\Program Files\Thoosje Sidebar V2.3\Uninstall.exe
            TmNationsForever-->"C:\Program Files\TmNationsForever\unins000.exe"
            Ulead Photo Express 4.0 SE-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{BBC0D330-C37B-4472-BFB9-AA217CF0C95F}\setup.exe" -l0x40c
            Update for Microsoft .NET Framework 3.5 SP1 (KB963707)-->C:\WINDOWS\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {B2AE9C82-DC7B-3641-BFC8-87275C4F3607} /qb+ REBOOTPROMPT=""
            VDownloader 0.77-->"C:\Program Files\VDOWNLOADER\unins000.exe"
            VideoLAN VLC media player 0.8.6h-->C:\Program Files\VideoLAN\VLC\uninstall.exe
            Vodafone 804SS USB driver Software-->C:\WINDOWS\system32\Samsung_USB_Drivers\4\SSVDUninstall.exe
            Windows Internet Explorer 8-->"C:\WINDOWS\ie8\spuninst\spuninst.exe"
            Windows Live Call-->MsiExec.exe /I{82C7B308-0BDD-49D8-8EA5-9CD3A3F9DF41}
            Windows Live Communications Platform-->MsiExec.exe /I{3B4E636E-9D65-4D67-BA61-189800823F52}
            Windows Live Contrôle parental-->MsiExec.exe /X{D5D81435-B8DE-4CAF-867F-7998F2B92CFC}
            Windows Live FolderShare-->MsiExec.exe /X{2075CB0A-D26F-4DAA-B424-5079296B43BA}
            Windows Live Mail-->MsiExec.exe /I{5DD76286-9BE7-4894-A990-E905E91AC818}
            Windows Live Messenger-->MsiExec.exe /X{770F1BEC-2871-4E70-B837-FB8525FFA3B1}
            Windows Live OneCare safety scanner-->RunDll32.exe "C:\Program Files\Windows Live Safety Center\wlscCore.dll",UninstallFunction WLSC_SCANNER_PRODUCT
            Windows Live Toolbar-->MsiExec.exe /X{F7D27C70-90F5-49B9-B188-0A133C0CE353}
            Windows Live Writer-->MsiExec.exe /X{4634B21A-CC07-4396-890C-2B8168661FEA}
            Windows Media Connect-->"C:\WINDOWS\$NtUninstallWMCSetup$\spuninst\spuninst.exe"
            Windows Media Format 11 runtime-->"C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll
            Windows Media Format 11 runtime-->"C:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe"
            Windows Media Player 11-->"C:\WINDOWS\$NtUninstallwmp11$\spuninst\spuninst.exe"
            Windows XP Media Center Edition 2005 KB925766-->"C:\WINDOWS\$NtUninstallKB925766$\spuninst\spuninst.exe"
            Windows XP Media Center Edition 2005 KB973768-->"C:\WINDOWS\$NtUninstallKB973768$\spuninst\spuninst.exe"
            Windows XP Service Pack 3-->"C:\WINDOWS\$NtServicePackUninstall$\spuninst\spuninst.exe"

            ======Hosts File======

            127.0.0.1 localhost

            ======Security center information======

            AV: Malware Defense (outdated)
            AV: Avira AntiVir PersonalEdition

            ======System event log======

            Computer Name: PC563316784159
            Event Code: 7035
            Message: Un contrôle Démarrer a correctement été envoyé au service Gestionnaire de connexion automatique d'accès distant.

            Record Number: 60536
            Source Name: Service Control Manager
            Time Written: 20091129104406.000000+060
            Event Type: Informations
            User: AUTORITE NT\SYSTEM

            Computer Name: PC563316784159
            Event Code: 7035
            Message: Un contrôle Démarrer a correctement été envoyé au service PCANDIS5 NDIS Protocol Driver.

            Record Number: 60535
            Source Name: Service Control Manager
            Time Written: 20091129104404.000000+060
            Event Type: Informations
            User: PC563316784159\nolwen boucher

            Computer Name: PC563316784159
            Event Code: 16384
            Message: L'administrateur AUTORITE NT\SYSTEM a annulé le travail "C:\WINDOWS\TEMP\GUR3.exe" au nom de PC563316784159\nolwen boucher. L'ID de travail était {A87031A2-C689-4985-A3C0-9083D214B78C}.

            Record Number: 60534
            Source Name: BITS
            Time Written: 20091129104242.000000+060
            Event Type: Informations
            User:

            Computer Name: PC563316784159
            Event Code: 7036
            Message: Le service iPod Service est entré dans l'état : en cours d'exécution.

            Record Number: 60533
            Source Name: Service Control Manager
            Time Written: 20091129104216.000000+060
            Event Type: Informations
            User:

            Computer Name: PC563316784159
            Event Code: 7035
            Message: Un contrôle Démarrer a correctement été envoyé au service iPod Service.

            Record Number: 60532
            Source Name: Service Control Manager
            Time Written: 20091129104216.000000+060
            Event Type: Informations
            User: AUTORITE NT\SYSTEM

            =====Application event log=====

            Computer Name: PC563316784159
            Event Code: 0
            Message:
            Record Number: 14341
            Source Name: gupdate1c98e1ba61181d0
            Time Written: 20090622114323.000000+120
            Event Type: Informations
            User:

            Computer Name: PC563316784159
            Event Code: 2444
            Message: MS DTC a été lancé avec les paramètres suivants :

            Configuration de la sécurité (Désactivée = 0 et Activée = 1) :

            Administration réseau des transactions = 0,

            Clients réseau = 0,

            Transactions entrantes distribuées à l'aide du protocole MSDTC natif = 0,

            Transactions sortantes distribuées à l'aide du protocole MSDTC natif = 0,

            TIP (Transaction Internet Protocol) = 0,

            Transactions XA = 0
            Record Number: 14340
            Source Name: MSDTC
            Time Written: 20090622114314.000000+120
            Event Type: Informations
            User:

            Computer Name: PC563316784159
            Event Code: 4096
            Message:
            Record Number: 14339
            Source Name: Avira AntiVir
            Time Written: 20090622114259.000000+120
            Event Type: Informations
            User: AUTORITE NT\SYSTEM

            Computer Name: PC563316784159
            Event Code: 0
            Message:
            Record Number: 14338
            Source Name: gusvc
            Time Written: 20090622001612.000000+120
            Event Type: Informations
            User:

            Computer Name: PC563316784159
            Event Code: 0
            Message:
            Record Number: 14337
            Source Name: gusvc
            Time Written: 20090622001501.000000+120
            Event Type: Informations
            User:

            ======Environment variables======

            "ComSpec"=%SystemRoot%\system32\cmd.exe
            "Path"=C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\System32\Wbem;C:\Program Files\Fichiers communs\GTK\2.0\bin;C:\Program Files\Fichiers communs\Teleca Shared
            "windir"=%SystemRoot%
            "FP_NO_HOST_CHECK"=NO
            "OS"=Windows_NT
            "PROCESSOR_ARCHITECTURE"=x86
            "PROCESSOR_LEVEL"=6
            "PROCESSOR_IDENTIFIER"=x86 Family 6 Model 14 Stepping 8, GenuineIntel
            "PROCESSOR_REVISION"=0e08
            "NUMBER_OF_PROCESSORS"=2
            "PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
            "TEMP"=%SystemRoot%\TEMP
            "TMP"=%SystemRoot%\TEMP
            "SonicCentral"=C:\Program Files\Fichiers communs\Sonic Shared\Sonic Central\
            "PCTYPE"=PAVILION
            "PLATFORM"=MCD
            "LANG"=fr

            -----------------EOF-----------------

            Logfile of random's system information tool 1.06 (written by random/random)
            Run by nolwen boucher at 2010-01-02 22:30:54
            Microsoft Windows XP Professionnel Service Pack 3
            System drive C: has 8 GB (8%) free of 105 GB
            Total RAM: 1022 MB (36% free)

            Logfile of Trend Micro HijackThis v2.0.2
            Scan saved at 22:30:58, on 02/01/2010
            Platform: Windows XP SP3 (WinNT 5.01.2600)
            MSIE: Internet Explorer v8.00 (8.00.6001.18702)
            Boot mode: Normal

            Running processes:
            C:\WINDOWS\System32\smss.exe
            C:\WINDOWS\system32\winlogon.exe
            C:\WINDOWS\system32\services.exe
            C:\WINDOWS\system32\lsass.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\System32\svchost.exe
            C:\WINDOWS\system32\spoolsv.exe
            C:\WINDOWS\eHome\ehRecvr.exe
            C:\WINDOWS\eHome\ehSched.exe
            C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\1\FTRTSVC.exe
            C:\WINDOWS\System32\svchost.exe
            C:\Program Files\Java\jre6\bin\jqs.exe
            C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
            C:\WINDOWS\system32\nvsvc32.exe
            C:\WINDOWS\system32\PnkBstrA.exe
            C:\WINDOWS\system32\PnkBstrB.exe
            C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\system32\mqsvc.exe
            C:\WINDOWS\system32\mqtgsvc.exe
            C:\WINDOWS\system32\dllhost.exe
            C:\WINDOWS\system32\wbem\wmiapsrv.exe
            C:\WINDOWS\Explorer.EXE
            C:\WINDOWS\ehome\ehtray.exe
            C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
            C:\WINDOWS\system32\RUNDLL32.EXE
            C:\Program Files\HP\QuickPlay\QPService.exe
            C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe
            C:\Program Files\iTunes\iTunesHelper.exe
            C:\Program Files\QuickTime\qttask.exe
            C:\WINDOWS\eHome\ehmsas.exe
            C:\Program Files\iPod\bin\iPodService.exe
            C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
            C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe
            C:\Program Files\Brother\ControlCenter3\brccMCtl.exe
            C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
            C:\Program Files\Java\jre6\bin\jusched.exe
            C:\Program Files\Brother\Brmfcmon\BrMfcmon.exe
            C:\Program Files\SweetIM\Messenger\SweetIM.exe
            C:\WINDOWS\system32\ctfmon.exe
            C:\Program Files\Ares\Ares.exe
            C:\Program Files\Microsoft ActiveSync\wcescomm.exe
            C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
            C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\AlertModule\0\AlertModule.exe
            C:\Program Files\Windows Media Player\WMPNSCFG.exe
            C:\DOCUME~1\NOLWEN~1\LOCALS~1\Temp\settdebugx.exe
            C:\Program Files\Malware Defense\mdefense.exe
            C:\Program Files\Ulead Systems\Ulead Photo Express 4.0 SE\CalCheck.exe
            C:\PROGRA~1\MI3AA1~1\rapimgr.exe
            C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
            C:\DOCUME~1\NOLWEN~1\LOCALS~1\Temp\wscsvc32.exe
            C:\PROGRA~1\Crawler\CToolbar.exe
            C:\Program Files\Orange\systray\systrayapp.exe
            C:\Program Files\Windows Live\Toolbar\wltuser.exe
            C:\Program Files\Internet Explorer\Iexplore.exe
            C:\WINDOWS\system32\drwtsn32.exe
            C:\WINDOWS\system32\drwtsn32.exe
            C:\Program Files\Orange\Launcher\Launcher.exe
            C:\Program Files\Orange\connectivity\connectivitymanager.exe
            C:\Program Files\Orange\connectivity\CoreCom\CoreCom.exe
            C:\Program Files\Orange\connectivity\CoreCom\OraConfigRecover.exe
            C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTCOMModule\1\FTCOMModule.exe
            C:\Program Files\Mozilla Firefox\firefox.exe
            C:\Program Files\Internet Explorer\Iexplore.exe
            C:\Program Files\Internet Explorer\Iexplore.exe
            C:\Documents and Settings\nolwen boucher\Bureau\RSIT.exe
            C:\Program Files\Trend Micro\HijackThis\nolwen boucher.exe

            R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.crawler.com/search/dispatcher.aspx?tp=aus&qkw=%s&tbid=66017
            R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://home.sweetim.com/
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://www.crawler.com/search/ie.aspx?tb_id=66017
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,CustomizeSearch = http://dnl.crawler.com/support/sa_customize.aspx?TbId=66017
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
            R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
            R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.crawler.com/search/ie.aspx?tb_id=66017
            R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://dnl.crawler.com/support/sa_customize.aspx?TbId=66017
            R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = https://www.bing.com/?FORM=TOOLBR&cc=fr&toHttps=1&redig=4527FFF1C12746FC9EDB535C75E80ECC
            R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
            R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\Program Files\Orange\SearchURLHook\SearchPageURL.dll
            R3 - URLSearchHook: SweetIM ToolbarURLSearchHook Class - {EEE6C35D-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgHelper.dll
            O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
            O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (file missing)
            O2 - BHO: (no name) - {1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} - C:\PROGRA~1\Crawler\ctbr.dll
            O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
            O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
            O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
            O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.3.4501.1418\swg.dll
            O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
            O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
            O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
            O2 - BHO: SWEETIE - {EEE6C35C-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll
            O3 - Toolbar: &Crawler Toolbar - {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - C:\PROGRA~1\Crawler\ctbr.dll
            O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
            O3 - Toolbar: SweetIM Toolbar for Internet Explorer - {EEE6C35B-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll
            O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
            O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
            O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
            O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
            O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet /nodetect
            O4 - HKLM\..\Run: [MsmqIntCert] regsvr32 /s mqrt.dll
            O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] CHDAudPropShortcut.exe
            O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
            O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
            O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
            O4 - HKLM\..\Run: [Cpqset] C:\Program Files\Hewlett-Packard\Default Settings\cpqset.exe
            O4 - HKLM\..\Run: [RecGuard] C:\Windows\SMINST\RecGuard.exe
            O4 - HKLM\..\Run: [Reminder] C:\Windows\CREATOR\Remind_XP.exe
            O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
            O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
            O4 - HKLM\..\Run: [ASocksrv] SocksA.exe
            O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Fichiers communs\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
            O4 - HKLM\..\Run: [PaperPort PTD] "C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe"
            O4 - HKLM\..\Run: [IndexSearch] "C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe"
            O4 - HKLM\..\Run: [PPort11reminder] "C:\Program Files\ScanSoft\PaperPort\Ereg\Ereg.exe" -r "C:\Documents and Settings\All Users\Application Data\ScanSoft\PaperPort\11\Config\Ereg\Ereg.ini
            O4 - HKLM\..\Run: [BrMfcWnd] C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe /AUTORUN
            O4 - HKLM\..\Run: [ControlCenter3] C:\Program Files\Brother\ControlCenter3\brctrcen.exe /autorun
            O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
            O4 - HKLM\..\Run: [ORAHSSSessionManager] "C:\Program Files\Orange\SessionManager\SessionManager.exe"
            O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
            O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
            O4 - HKLM\..\Run: [SweetIM] C:\Program Files\SweetIM\Messenger\SweetIM.exe
            O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
            O4 - HKCU\..\Run: [Steam] "c:\program files\steam\steam.exe" -silent
            O4 - HKCU\..\Run: [MsnMsgr] ~"C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
            O4 - HKCU\..\Run: [BSserver] FileKan.exe
            O4 - HKCU\..\Run: [ares] "C:\Program Files\Ares\Ares.exe" -h
            O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
            O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
            O4 - HKCU\..\Run: [settdebugx.exe] C:\DOCUME~1\NOLWEN~1\LOCALS~1\Temp\settdebugx.exe
            O4 - HKCU\..\Run: [Malware Defense] "C:\Program Files\Malware Defense\mdefense.exe" -noscan
            O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
            O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
            O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
            O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
            O4 - Global Startup: Contrôleur de calendrier Ulead.lnk = C:\Program Files\Ulead Systems\Ulead Photo Express 4.0 SE\CalCheck.exe
            O4 - Global Startup: Démarrage rapide de HP Photosmart Premier.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
            O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
            O8 - Extra context menu item: Crawler Search - tbr:iemenu
            O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
            O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
            O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
            O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
            O9 - Extra 'Tools' menuitem: Créer un Favori de l'appareil mobile... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
            O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
            O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
            O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
            O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
            O9 - Extra button: PokerStars.net - {FA9B9510-9FCB-4ca0-818C-5D0987B47C4D} - C:\Program Files\PokerStars.NET\PokerStarsUpdate.exe
            O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
            O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
            O14 - IERESET.INF: START_PAGE_URL=https://www.msn.com/fr-fr?cobrand=hp-notebook.msn.com&ocid=HPDHP&pc=HPNTDF
            O15 - Trusted Zone: http://*.mappy.com
            O15 - Trusted Zone: http://*.orange.fr
            O15 - Trusted Zone: http://rw.search.ke.voila.fr
            O15 - Trusted Zone: http://orange.weborama.fr
            O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - https://www.kaspersky.fr/?domain=webscanner.kaspersky.fr
            O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
            O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w3/resources/MSNPUpld.cab
            O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} (OnlineScanner Control) - https://www.eset.com/
            O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.cab
            O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
            O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab
            O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
            O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
            O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
            O17 - HKLM\System\CCS\Services\Tcpip\..\{FD3B7044-5FCB-426C-A425-8501D09013D2}: NameServer = 192.168.1.1
            O18 - Protocol: tbr - {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - C:\PROGRA~1\Crawler\ctbr.dll
            O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
            O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
            O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom SA - C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\1\FTRTSVC.exe
            O23 - Service: Service Google Update (gupdate1c98e1ba61181d0) (gupdate1c98e1ba61181d0) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
            O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
            O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
            O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
            O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
            O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
            O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
            O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
            O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
            O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe
            0
            1. tu es vraiment infecté
              ms c bizar ke ton anti-virus ne lai pa blocké avan kil ne sinstal sur ton PC .

              ta koi comm anti-virus
              0
              1. avira antivir, mais depuis que le problème est apparut je ne voit plus le logo de mon antivirus, mais celui du logiciel qui me pose probleme!
                0
                1. repere le nom du logo

                  pui va sur
                  demaré
                  panneau de configuration
                  programmes
                  desinstaller un programme

                  et kd ta été dans tous sa tu cherche le nom du logo et tu le suprime

                  et di moi si il a bien été suprimer
                  0
                  1. j'ai supprimer le logiciel, une fois supprimer celui-ci ma mi plein de raccourci pour des sites porno, j'ai mis a la corbeille les liens puis vidé la corbeille, l'ordinateur doit être encore contaminé, si se virus a pu contaminer le pc, peut être suis-je toujours contaminer par un autre virus sans même le savoir!

                    Le logo de mon antivirus n'est toujours pas revenu, j'ai peur pour mes parent qui achetent régulièrement sur des site (amazon) par carte bancaire

                    Merci de votre aide, j'aimerais nettoyer mon ordinateur entièrement!
                    0
                    1. oui je pense ke tu est encor contaminer
                      essaye de telecharger antivir personal et tu fai un scann complet

                      ( jai peur ossi pr tes parent paske ya ptetre un raiseau de physhing ... fo kils surveil leur compte bancaire pi si ya des mouvement inquietan sur leur compte fo kils fasse ts pr ke sa sesse. ils vont ds leur banque il explike leur probleme o banquier et il va fair le nessecaire )
                      0
                      1. je suis toujours contaminer, je vais leur dire de vérifier leur compte!

                        un nouveau message apparait

                        "Email-Worm.Win32.NetSky.q"
                        ainsi que
                        "Net-Worm.Win32.Mytob.t"

                        Merci d'avance pour votre aide
                        0
                        1. DE RIEN tu peu me tutoyer g ke 14 ans :)

                          meintenant tu fai le truk habituel tu le suprime pi tu me di si sa va

                          c un ver informatike ki ta contaminer ton PC
                          0
                          1. Ok, mais le problème persiste, se que j'ai supprimer tout a leur est revenu, je l'ai de nouveau désinstaller!

                            ça commence a être vraiment pénible, merci d'avance!
                            0
                            1. Contributeur sécurité
                              bonjour

                              Lalexnono9,

                              arrêtes les dégats....je vais t'aider

                              déjà ton rapport log n'est pas complet

                              postes le à nouveau, il est ici C:\rsit\log.txt

                              0
                              1. Merci, de ton aide rapide

                                voici le rapport complet

                                Logfile of random's system information tool 1.06 (written by random/random)
                                Run by nolwen boucher at 2010-01-02 22:30:54
                                Microsoft Windows XP Professionnel Service Pack 3
                                System drive C: has 8 GB (8%) free of 105 GB
                                Total RAM: 1022 MB (36% free)

                                Logfile of Trend Micro HijackThis v2.0.2
                                Scan saved at 22:30:58, on 02/01/2010
                                Platform: Windows XP SP3 (WinNT 5.01.2600)
                                MSIE: Internet Explorer v8.00 (8.00.6001.18702)
                                Boot mode: Normal

                                Running processes:
                                C:\WINDOWS\System32\smss.exe
                                C:\WINDOWS\system32\winlogon.exe
                                C:\WINDOWS\system32\services.exe
                                C:\WINDOWS\system32\lsass.exe
                                C:\WINDOWS\system32\svchost.exe
                                C:\WINDOWS\System32\svchost.exe
                                C:\WINDOWS\system32\spoolsv.exe
                                C:\WINDOWS\eHome\ehRecvr.exe
                                C:\WINDOWS\eHome\ehSched.exe
                                C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\1\FTRTSVC.exe
                                C:\WINDOWS\System32\svchost.exe
                                C:\Program Files\Java\jre6\bin\jqs.exe
                                C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
                                C:\WINDOWS\system32\nvsvc32.exe
                                C:\WINDOWS\system32\PnkBstrA.exe
                                C:\WINDOWS\system32\PnkBstrB.exe
                                C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
                                C:\WINDOWS\system32\svchost.exe
                                C:\WINDOWS\system32\mqsvc.exe
                                C:\WINDOWS\system32\mqtgsvc.exe
                                C:\WINDOWS\system32\dllhost.exe
                                C:\WINDOWS\system32\wbem\wmiapsrv.exe
                                C:\WINDOWS\Explorer.EXE
                                C:\WINDOWS\ehome\ehtray.exe
                                C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
                                C:\WINDOWS\system32\RUNDLL32.EXE
                                C:\Program Files\HP\QuickPlay\QPService.exe
                                C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe
                                C:\Program Files\iTunes\iTunesHelper.exe
                                C:\Program Files\QuickTime\qttask.exe
                                C:\WINDOWS\eHome\ehmsas.exe
                                C:\Program Files\iPod\bin\iPodService.exe
                                C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
                                C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe
                                C:\Program Files\Brother\ControlCenter3\brccMCtl.exe
                                C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
                                C:\Program Files\Java\jre6\bin\jusched.exe
                                C:\Program Files\Brother\Brmfcmon\BrMfcmon.exe
                                C:\Program Files\SweetIM\Messenger\SweetIM.exe
                                C:\WINDOWS\system32\ctfmon.exe
                                C:\Program Files\Ares\Ares.exe
                                C:\Program Files\Microsoft ActiveSync\wcescomm.exe
                                C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
                                C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\AlertModule\0\AlertModule.exe
                                C:\Program Files\Windows Media Player\WMPNSCFG.exe
                                C:\DOCUME~1\NOLWEN~1\LOCALS~1\Temp\settdebugx.exe
                                C:\Program Files\Malware Defense\mdefense.exe
                                C:\Program Files\Ulead Systems\Ulead Photo Express 4.0 SE\CalCheck.exe
                                C:\PROGRA~1\MI3AA1~1\rapimgr.exe
                                C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
                                C:\DOCUME~1\NOLWEN~1\LOCALS~1\Temp\wscsvc32.exe
                                C:\PROGRA~1\Crawler\CToolbar.exe
                                C:\Program Files\Orange\systray\systrayapp.exe
                                C:\Program Files\Windows Live\Toolbar\wltuser.exe
                                C:\Program Files\Internet Explorer\Iexplore.exe
                                C:\WINDOWS\system32\drwtsn32.exe
                                C:\WINDOWS\system32\drwtsn32.exe
                                C:\Program Files\Orange\Launcher\Launcher.exe
                                C:\Program Files\Orange\connectivity\connectivitymanager.exe
                                C:\Program Files\Orange\connectivity\CoreCom\CoreCom.exe
                                C:\Program Files\Orange\connectivity\CoreCom\OraConfigRecover.exe
                                C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTCOMModule\1\FTCOMModule.exe
                                C:\Program Files\Mozilla Firefox\firefox.exe
                                C:\Program Files\Internet Explorer\Iexplore.exe
                                C:\Program Files\Internet Explorer\Iexplore.exe
                                C:\Documents and Settings\nolwen boucher\Bureau\RSIT.exe
                                C:\Program Files\Trend Micro\HijackThis\nolwen boucher.exe

                                R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.crawler.com/search/dispatcher.aspx?tp=aus&qkw=%s&tbid=66017
                                R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://home.sweetim.com/
                                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://www.crawler.com/search/ie.aspx?tb_id=66017
                                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,CustomizeSearch = http://dnl.crawler.com/support/sa_customize.aspx?TbId=66017
                                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                                R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
                                R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.crawler.com/search/ie.aspx?tb_id=66017
                                R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://dnl.crawler.com/support/sa_customize.aspx?TbId=66017
                                R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = https://www.bing.com/?FORM=TOOLBR&cc=fr&toHttps=1&redig=4527FFF1C12746FC9EDB535C75E80ECC
                                R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                                R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\Program Files\Orange\SearchURLHook\SearchPageURL.dll
                                R3 - URLSearchHook: SweetIM ToolbarURLSearchHook Class - {EEE6C35D-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgHelper.dll
                                O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
                                O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (file missing)
                                O2 - BHO: (no name) - {1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} - C:\PROGRA~1\Crawler\ctbr.dll
                                O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
                                O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
                                O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                                O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.3.4501.1418\swg.dll
                                O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
                                O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
                                O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
                                O2 - BHO: SWEETIE - {EEE6C35C-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll
                                O3 - Toolbar: &Crawler Toolbar - {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - C:\PROGRA~1\Crawler\ctbr.dll
                                O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
                                O3 - Toolbar: SweetIM Toolbar for Internet Explorer - {EEE6C35B-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll
                                O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
                                O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
                                O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
                                O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
                                O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet /nodetect
                                O4 - HKLM\..\Run: [MsmqIntCert] regsvr32 /s mqrt.dll
                                O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] CHDAudPropShortcut.exe
                                O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                                O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
                                O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
                                O4 - HKLM\..\Run: [Cpqset] C:\Program Files\Hewlett-Packard\Default Settings\cpqset.exe
                                O4 - HKLM\..\Run: [RecGuard] C:\Windows\SMINST\RecGuard.exe
                                O4 - HKLM\..\Run: [Reminder] C:\Windows\CREATOR\Remind_XP.exe
                                O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
                                O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                                O4 - HKLM\..\Run: [ASocksrv] SocksA.exe
                                O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Fichiers communs\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
                                O4 - HKLM\..\Run: [PaperPort PTD] "C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe"
                                O4 - HKLM\..\Run: [IndexSearch] "C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe"
                                O4 - HKLM\..\Run: [PPort11reminder] "C:\Program Files\ScanSoft\PaperPort\Ereg\Ereg.exe" -r "C:\Documents and Settings\All Users\Application Data\ScanSoft\PaperPort\11\Config\Ereg\Ereg.ini
                                O4 - HKLM\..\Run: [BrMfcWnd] C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe /AUTORUN
                                O4 - HKLM\..\Run: [ControlCenter3] C:\Program Files\Brother\ControlCenter3\brctrcen.exe /autorun
                                O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
                                O4 - HKLM\..\Run: [ORAHSSSessionManager] "C:\Program Files\Orange\SessionManager\SessionManager.exe"
                                O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
                                O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
                                O4 - HKLM\..\Run: [SweetIM] C:\Program Files\SweetIM\Messenger\SweetIM.exe
                                O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
                                O4 - HKCU\..\Run: [Steam] "c:\program files\steam\steam.exe" -silent
                                O4 - HKCU\..\Run: [MsnMsgr] ~"C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
                                O4 - HKCU\..\Run: [BSserver] FileKan.exe
                                O4 - HKCU\..\Run: [ares] "C:\Program Files\Ares\Ares.exe" -h
                                O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
                                O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
                                O4 - HKCU\..\Run: [settdebugx.exe] C:\DOCUME~1\NOLWEN~1\LOCALS~1\Temp\settdebugx.exe
                                O4 - HKCU\..\Run: [Malware Defense] "C:\Program Files\Malware Defense\mdefense.exe" -noscan
                                O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
                                O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
                                O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
                                O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
                                O4 - Global Startup: Contrôleur de calendrier Ulead.lnk = C:\Program Files\Ulead Systems\Ulead Photo Express 4.0 SE\CalCheck.exe
                                O4 - Global Startup: Démarrage rapide de HP Photosmart Premier.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
                                O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
                                O8 - Extra context menu item: Crawler Search - tbr:iemenu
                                O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
                                O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
                                O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
                                O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
                                O9 - Extra 'Tools' menuitem: Créer un Favori de l'appareil mobile... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
                                O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
                                O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
                                O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                                O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                                O9 - Extra button: PokerStars.net - {FA9B9510-9FCB-4ca0-818C-5D0987B47C4D} - C:\Program Files\PokerStars.NET\PokerStarsUpdate.exe
                                O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                                O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                                O14 - IERESET.INF: START_PAGE_URL=https://www.msn.com/fr-fr?cobrand=hp-notebook.msn.com&ocid=HPDHP&pc=HPNTDF
                                O15 - Trusted Zone: http://*.mappy.com
                                O15 - Trusted Zone: http://*.orange.fr
                                O15 - Trusted Zone: http://rw.search.ke.voila.fr
                                O15 - Trusted Zone: http://orange.weborama.fr
                                O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - https://www.kaspersky.fr/?domain=webscanner.kaspersky.fr
                                O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
                                O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w3/resources/MSNPUpld.cab
                                O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} (OnlineScanner Control) - https://www.eset.com/
                                O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.cab
                                O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
                                O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab
                                O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
                                O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
                                O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
                                O17 - HKLM\System\CCS\Services\Tcpip\..\{FD3B7044-5FCB-426C-A425-8501D09013D2}: NameServer = 192.168.1.1
                                O18 - Protocol: tbr - {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - C:\PROGRA~1\Crawler\ctbr.dll
                                O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
                                O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
                                O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom SA - C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\1\FTRTSVC.exe
                                O23 - Service: Service Google Update (gupdate1c98e1ba61181d0) (gupdate1c98e1ba61181d0) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
                                O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                                O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
                                O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
                                O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
                                O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
                                O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
                                O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
                                O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
                                O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe
                                0
                                1. javai le meme PB et jai reussi a ts reparer les probleme de mon PC
                                  je tai di de faire ts ske g fait ms toi c plus perspicasse ...
                                  je seche ...
                                  EXCUSE-MOI !

                                  slt,
                                  je vais suivre la conversation du forum

                                  FELIZ ANO NUEVO a ts
                                  0
                                  1. Contributeur sécurité
                                    effectivement plusieur infections

                                    on commence par la plus méchante

                                    Attention, avant de commencer, lit attentivement la procédure, et imprime la

                                    Télécharge ComboFix de sUBs en le renommant MDG.exe avant de l’enregistrer sur ton Bureau :

                                    http://download.bleepingcomputer.com/sUBs/ComboFix.exe

                                    /!\ Déconnecte-toi du net et DESACTIVES TOUTES LES DEFENSES, antivirus et antispyware y compris /!\

                                    (si tu n'y arrive pas...continues)

                                    ---> Double-clique sur ComboFix.exe
                                    Un "pop-up" va apparaître qui dit que ComboFix est utilisé à vos risques et avec aucune garantie... Clique sur oui pour accepter

                                    SURTOUT INSTALLES LA CONSOLE DE RECUPERATION
                                    (si il te le propose remets provisoirement internet)

                                    ---> Mets-le en langue française F
                                    Tape sur la touche 1 (Yes) pour démarrer le scan.

                                    Ne touche à rien(souris, clavier) tant que le scan n'est pas terminé, car tu risques de planter ton PC

                                    En fin de scan, il est possible que ComboFix ait besoin de redémarrer le PC pour finaliser la désinfection, laisse-le faire.

                                    Une fois le scan achevé, un rapport va s'afficher : Poste son contenu

                                    /!\ Réactive la protection en temps réel de ton antivirus et de ton antispyware avant de te reconnecter à Internet. /!\

                                    Note : Le rapport se trouve également là : C:\ComboFix.txt

                                    0
                                    1. Voila le rapport

                                      ComboFix 10-01-02.01 - nolwen boucher 03/01/2010 0:16.1.2 - x86
                                      Microsoft Windows XP Professionnel 5.1.2600.3.1252.33.1036.18.1022.627 [GMT 1:00]
                                      Lancé depuis: c:\documents and settings\nolwen boucher\Bureau\MDG.exe.exe
                                      AV: Avira AntiVir PersonalEdition *On-access scanning enabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}
                                      .

                                      (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
                                      .

                                      c:\docume~1\NOLWEN~1\LOCALS~1\Temp\wscsvc32.exe
                                      c:\program files\Malware Defense
                                      c:\program files\Malware Defense\md.db
                                      c:\windows\kb913800.exe
                                      c:\windows\system32\drivers\H8SRTenpabawqjn.sys
                                      c:\windows\system32\f
                                      c:\windows\system32\H8SRTrniydlvdwu.dll
                                      c:\windows\system32\H8SRTwupkdsjpjp.dll
                                      c:\windows\system32\H8SRTypxvvkkypb.dat
                                      c:\windows\system32\krl32mainweq.dll
                                      c:\windows\system32\srcr.dat

                                      .
                                      ((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
                                      .

                                      -------\Service_H8SRTd.sys
                                      -------\Legacy_H8SRTd.sys

                                      ((((((((((((((((((((((((((((( Fichiers créés du 2009-12-02 au 2010-01-02 ))))))))))))))))))))))))))))))))))))
                                      .

                                      2010-01-02 22:55 . 2010-01-02 22:59 -------- d-----w- C:\MDG.exe
                                      2010-01-02 21:57 . 2010-01-02 21:57 -------- d-----w- c:\windows\1A8A214F6BAC4E01A27D25C19A484908.TMP
                                      2010-01-02 21:30 . 2010-01-02 21:31 -------- d-----w- C:\rsit
                                      2010-01-02 20:15 . 2010-01-02 20:15 -------- d-sh--w- c:\documents and settings\NOLWEN~2\Temporary Internet Files
                                      2010-01-02 20:15 . 2010-01-02 20:15 -------- d-sh--w- c:\documents and settings\NOLWEN~2\Historique
                                      2010-01-02 20:15 . 2010-01-02 20:15 -------- d-----w- c:\documents and settings\nolwen bouchei?
                                      2009-12-11 16:17 . 2009-12-11 16:17 -------- d-----w- C:\57acc657c090f6a9c1ddb437b0607918

                                      .
                                      (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
                                      .
                                      2010-01-02 23:40 . 2007-04-20 16:41 -------- d-----w- c:\program files\Steam
                                      2010-01-02 23:08 . 2008-06-12 10:39 -------- d-----w- c:\program files\Crawler
                                      2010-01-02 20:02 . 2008-05-22 16:11 -------- d-----w- c:\documents and settings\All Users\Application Data\Google Updater
                                      2009-12-21 22:21 . 2006-09-13 14:02 -------- d-----w- c:\program files\Google
                                      2009-12-14 19:28 . 2009-06-16 16:51 -------- d-----w- c:\program files\SweetIM
                                      2009-12-14 19:21 . 2009-12-14 19:20 5865064 ----a-w- c:\documents and settings\All Users\Application Data\SweetIM\Messenger\update\sweetimsetup.exe
                                      2009-12-07 19:10 . 2007-01-23 22:44 664 ----a-w- c:\windows\system32\d3d9caps.dat
                                      2009-11-24 17:26 . 2006-12-25 12:38 11080 ----a-w- c:\documents and settings\nolwen boucher\Application Data\wklnhst.dat
                                      2009-11-24 12:23 . 2006-06-29 09:24 88784 ----a-w- c:\windows\system32\perfc00C.dat
                                      2009-11-24 12:23 . 2006-06-29 09:24 523032 ----a-w- c:\windows\system32\perfh00C.dat
                                      2009-11-23 04:13 . 2008-05-06 15:08 -------- d-----w- c:\documents and settings\nolwen boucher\Application Data\uTorrent
                                      2009-11-07 09:09 . 2006-09-13 21:25 -------- d-----w- c:\program files\Java
                                      2009-11-07 09:08 . 2009-11-07 09:08 152576 ----a-w- c:\documents and settings\nolwen boucher\Application Data\Sun\Java\jre1.6.0_17\lzma.dll
                                      2009-11-07 09:04 . 2009-11-07 09:04 79488 ----a-w- c:\documents and settings\nolwen boucher\Application Data\Sun\Java\jre1.6.0_17\gtapi.dll
                                      2009-10-29 07:42 . 2006-03-25 04:00 916480 ----a-w- c:\windows\system32\wininet.dll
                                      2009-10-21 05:39 . 2006-03-25 04:00 75776 ----a-w- c:\windows\system32\strmfilt.dll
                                      2009-10-21 05:39 . 2006-03-25 04:00 25088 ----a-w- c:\windows\system32\httpapi.dll
                                      2009-10-20 16:20 . 2006-03-25 04:00 265728 ----a-w- c:\windows\system32\drivers\http.sys
                                      2009-10-13 10:33 . 2006-03-25 04:00 271360 ----a-w- c:\windows\system32\oakley.dll
                                      2009-10-12 13:39 . 2006-03-25 04:00 79872 ----a-w- c:\windows\system32\raschap.dll
                                      2009-10-12 13:39 . 2006-03-25 04:00 150528 ----a-w- c:\windows\system32\rastls.dll
                                      2009-10-11 03:17 . 2008-12-10 19:39 411368 ----a-w- c:\windows\system32\deploytk.dll
                                      2009-05-07 20:36 . 2009-05-07 20:36 6830592 --sha-w- c:\program files\ehthumbs.db
                                      2006-12-25 14:24 . 2006-12-25 14:24 251 ----a-w- c:\program files\wt3d.ini
                                      2008-02-20 11:00 . 2008-02-20 11:00 8192 --sha-w- c:\windows\o2cLicStore.bin
                                      .

                                      ((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
                                      .
                                      .
                                      *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
                                      REGEDIT4

                                      [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
                                      "{EEE6C35D-6118-11DC-9C72-001320C79847}"= "c:\program files\SweetIM\Toolbars\Internet Explorer\mgHelper.dll" [2009-10-19 187192]

                                      [HKEY_CLASSES_ROOT\clsid\{eee6c35d-6118-11dc-9c72-001320c79847}]
                                      [HKEY_CLASSES_ROOT\SweetIM_URLSearchHook.ToolbarURLSearchHook.1]
                                      [HKEY_CLASSES_ROOT\TypeLib\{EEE6C35F-6118-11DC-9C72-001320C79847}]
                                      [HKEY_CLASSES_ROOT\SweetIM_URLSearchHook.ToolbarURLSearchHook]

                                      [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{EEE6C35C-6118-11DC-9C72-001320C79847}]
                                      2009-10-19 15:15 1345336 ----a-w- c:\program files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll

                                      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
                                      "{EEE6C35B-6118-11DC-9C72-001320C79847}"= "c:\program files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll" [2009-10-19 1345336]

                                      [HKEY_CLASSES_ROOT\clsid\{eee6c35b-6118-11dc-9c72-001320c79847}]
                                      [HKEY_CLASSES_ROOT\SWEETIE.IEToolbar.1]
                                      [HKEY_CLASSES_ROOT\TypeLib\{EEE6C35E-6118-11DC-9C72-001320C79847}]
                                      [HKEY_CLASSES_ROOT\SWEETIE.IEToolbar]

                                      [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
                                      "{EEE6C35B-6118-11DC-9C72-001320C79847}"= "c:\program files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll" [2009-10-19 1345336]

                                      [HKEY_CLASSES_ROOT\clsid\{eee6c35b-6118-11dc-9c72-001320c79847}]
                                      [HKEY_CLASSES_ROOT\SWEETIE.IEToolbar.1]
                                      [HKEY_CLASSES_ROOT\TypeLib\{EEE6C35E-6118-11DC-9C72-001320C79847}]
                                      [HKEY_CLASSES_ROOT\SWEETIE.IEToolbar]

                                      [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                                      "Steam"="c:\program files\steam\steam.exe" [2009-11-06 1217808]
                                      "ares"="c:\program files\Ares\Ares.exe" [2009-02-03 1004544]
                                      "WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2006-11-03 204288]

                                      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                                      "ehTray"="c:\windows\ehome\ehtray.exe" [2005-08-05 64512]
                                      "hpWirelessAssistant"="c:\program files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe" [2006-05-03 458752]
                                      "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-07-20 7581696]
                                      "NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-07-20 86016]
                                      "nwiz"="nwiz.exe" [2006-07-20 1519616]
                                      "MsmqIntCert"="mqrt.dll" [2008-04-14 177152]
                                      "High Definition Audio Property Page Shortcut"="CHDAudPropShortcut.exe" [2006-06-02 61952]
                                      "QPService"="c:\program files\HP\QuickPlay\QPService.exe" [2006-07-19 102400]
                                      "QlbCtrl"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2006-06-19 163840]
                                      "Cpqset"="c:\program files\Hewlett-Packard\Default Settings\cpqset.exe" [2006-06-19 40960]
                                      "RecGuard"="c:\windows\SMINST\RecGuard.exe" [2005-10-11 1187840]
                                      "Reminder"="c:\windows\CREATOR\Remind_XP.exe" [2006-02-09 643072]
                                      "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2004-10-13 278528]
                                      "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2006-12-27 98304]
                                      "SSBkgdUpdate"="c:\program files\Fichiers communs\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2006-10-25 210472]
                                      "PaperPort PTD"="c:\program files\ScanSoft\PaperPort\pptd40nt.exe" [2007-01-29 30248]
                                      "IndexSearch"="c:\program files\ScanSoft\PaperPort\IndexSearch.exe" [2007-01-29 46632]
                                      "PPort11reminder"="c:\program files\ScanSoft\PaperPort\Ereg\Ereg.exe" [2007-02-01 255528]
                                      "BrMfcWnd"="c:\program files\Brother\Brmfcmon\BrMfcWnd.exe" [2007-03-12 663552]
                                      "ControlCenter3"="c:\program files\Brother\ControlCenter3\brctrcen.exe" [2007-01-26 65536]
                                      "avgnt"="c:\program files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-07-19 266497]
                                      "ORAHSSSessionManager"="c:\program files\Orange\SessionManager\SessionManager.exe" [2008-06-10 107248]
                                      "HP Software Update"="c:\program files\Hp\HP Software Update\HPWuSchd2.exe" [2008-12-08 54576]
                                      "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-10-11 149280]
                                      "SweetIM"="c:\program files\SweetIM\Messenger\SweetIM.exe" [2009-10-20 111928]

                                      [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
                                      "CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

                                      c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
                                      Contr“leur de calendrier Ulead.lnk - c:\program files\Ulead Systems\Ulead Photo Express 4.0 SE\CalCheck.exe [2007-10-16 69632]
                                      D‚marrage rapide de HP Photosmart Premier.lnk - c:\program files\HP\Digital Imaging\bin\hpqthb08.exe [2005-9-24 73728]
                                      Lancement rapide d'Adobe Reader.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2008-4-23 29696]

                                      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
                                      "Symantec Core LC"=2 (0x2)
                                      "SPBBCSvc"=2 (0x2)
                                      "SNDSrvc"=2 (0x2)
                                      "SAVScan"=3 (0x3)
                                      "NSCService"=2 (0x2)
                                      "navapsvc"=2 (0x2)
                                      "ccProxy"=2 (0x2)
                                      "ccISPwdSvc"=3 (0x3)
                                      "ccEvtMgr"=2 (0x2)
                                      "AddFiltr"=3 (0x3)

                                      [HKEY_LOCAL_MACHINE\software\microsoft\security center]
                                      "AntiVirusOverride"=dword:00000001

                                      [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
                                      "DisableMonitoring"=dword:00000001

                                      [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
                                      "EnableFirewall"= 0 (0x0)

                                      [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
                                      "%windir%\\system32\\sessmgr.exe"=
                                      "c:\\WINDOWS\\system32\\mqsvc.exe"=
                                      "c:\\Program Files\\iTunes\\iTunes.exe"=
                                      "c:\\Program Files\\Cyanide\\Chaos-League\\ChaosLeague.exe"=
                                      "c:\\Program Files\\THQ\\Dawn of War - Dark Crusade\\DarkCrusade.exe"=
                                      "c:\\Program Files\\Messenger\\msmsgs.exe"=
                                      "c:\\Documents and Settings\\nolwen boucher\\Bureau\\JEU\\nexuiz-23\\Nexuiz\\nexuiz-sdl.exe"=
                                      "c:\\Program Files\\SopCast\\SopCast.exe"=
                                      "c:\\Documents and Settings\\nolwen boucher\\Bureau\\JEU\\nexuiz-23\\Nexuiz\\nexuiz.exe"=
                                      "c:\\Program Files\\Steam\\Steam.exe"=
                                      "c:\\Program Files\\Steam\\SteamApps\\lalex7\\half-life 2 deathmatch\\hl2.exe"=
                                      "c:\\Program Files\\Steam\\SteamApps\\lalex7\\counter-strike source\\hl2.exe"=
                                      "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
                                      "c:\\Program Files\\Microsoft Games\\Age of Empires III\\age3.exe"=
                                      "c:\\WINDOWS\\system32\\PnkBstrA.exe"=
                                      "c:\\WINDOWS\\system32\\PnkBstrB.exe"=
                                      "c:\\Program Files\\uTorrent\\uTorrent.exe"=
                                      "c:\\Program Files\\Steam\\SteamApps\\lalex2008\\condition zero\\hl.exe"=
                                      "c:\\Program Files\\Ares\\Ares.exe"=
                                      "c:\program files\Microsoft ActiveSync\rapimgr.exe"= c:\program files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
                                      "c:\program files\Microsoft ActiveSync\wcescomm.exe"= c:\program files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
                                      "c:\program files\Microsoft ActiveSync\WCESMgr.exe"= c:\program files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
                                      "c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
                                      "c:\\Program Files\\TmNationsForever\\TmForever.exe"=
                                      "c:\\Program Files\\Orange\\Connectivity\\ConnectivityManager.exe"=
                                      "c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
                                      "c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=

                                      [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
                                      "26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service

                                      R2 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr_tdi.sys [21/05/2009 15:18 54752]
                                      R3 5U870CAP_VID_1262&PID_25FD;HP Pavilion Webcam ;c:\windows\system32\drivers\5U870CAP.sys [06/06/2006 21:39 61952]
                                      S2 gupdate1c98e1ba61181d0;Service Google Update (gupdate1c98e1ba61181d0);c:\program files\Google\Update\GoogleUpdate.exe [13/02/2009 21:42 133104]
                                      S3 fsssvc;Service Windows Live Contrôle parental;c:\program files\Windows Live\Family Safety\fsssvc.exe [05/08/2009 21:48 704864]
                                      S3 MBAMCatchMe;MBAMCatchMe;c:\program files\Malwarebytes' Anti-Malware\catchme.sys [24/03/2008 12:22 27136]
                                      .
                                      Contenu du dossier 'Tâches planifiées'

                                      2010-01-02 c:\windows\Tasks\Google Software Updater.job
                                      - c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2007-12-04 21:35]

                                      2010-01-02 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
                                      - c:\program files\Google\Update\GoogleUpdate.exe [2009-02-13 20:42]

                                      2010-01-02 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
                                      - c:\program files\Google\Update\GoogleUpdate.exe [2009-02-13 20:42]
                                      .
                                      .
                                      ------- Examen supplémentaire -------
                                      .
                                      uStart Page = hxxp://home.sweetim.com
                                      uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}
                                      uInternet Connection Wizard,ShellNext = iexplore
                                      uSearchURL,(Default) = hxxp://g.msn.fr/0SEFRFR/SAOS01?FORM=TOOLBR
                                      IE: Crawler Search - tbr:iemenu
                                      IE: {{FA9B9510-9FCB-4ca0-818C-5D0987B47C4D} - c:\program files\PokerStars.NET\PokerStarsUpdate.exe
                                      TCP: {FD3B7044-5FCB-426C-A425-8501D09013D2} = 192.168.1.1
                                      Handler: tbr - {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - c:\progra~1\Crawler\ctbr.dll
                                      DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} - hxxp://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
                                      FF - ProfilePath - c:\documents and settings\nolwen boucher\Application Data\Mozilla\Firefox\Profiles\ycvuybe5.default\
                                      FF - prefs.js: browser.search.defaulturl - hxxp://search.sweetim.com/search.asp?src=2&q=
                                      FF - prefs.js: browser.search.selectedEngine - SweetIM Search
                                      FF - prefs.js: browser.startup.homepage - hxxp://www.google.fr/
                                      FF - prefs.js: keyword.URL - hxxp://search.sweetim.com/search.asp?src=2&q=
                                      FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll
                                      FF - plugin: c:\program files\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll
                                      FF - plugin: c:\program files\Google\Update\1.2.183.13\npGoogleOneClick8.dll
                                      FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
                                      FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
                                      .
                                      - - - - ORPHELINS SUPPRIMES - - - -

                                      HKCU-Run-MsnMsgr - ~c:\program files\Windows Live\Messenger\MsnMsgr.Exe
                                      HKCU-Run-Malware Defense - c:\program files\Malware Defense\mdefense.exe
                                      HKLM-Run-SynTPEnh - c:\program files\Synaptics\SynTP\SynTPEnh.exe

                                      **************************************************************************

                                      catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
                                      Rootkit scan 2010-01-03 00:38
                                      Windows 5.1.2600 Service Pack 3 NTFS

                                      Recherche de processus cachés ...

                                      Recherche d'éléments en démarrage automatique cachés ...

                                      HKLM\Software\Microsoft\Windows\CurrentVersion\Run
                                      Cpqset = c:\program files\Hewlett-Packard\Default Settings\cpqset.exe????????????L?@? ???xR??????`?@?????L?@
                                      HKCU\Software\Microsoft\Windows\CurrentVersion\Run
                                      MsnMsgr = ~"c:\program files\Windows Live\Messenger\MsnMsgr.Exe" /background?

                                      Recherche de fichiers cachés ...

                                      c:\docume~1\NOLWEN~1\LOCALS~1\Temp\cc3data_init.xml 7102 bytes

                                      Scan terminé avec succès
                                      Fichiers cachés: 1

                                      **************************************************************************
                                      .
                                      --------------------- DLLs chargées dans les processus actifs ---------------------

                                      - - - - - - - > 'explorer.exe'(1168)
                                      c:\program files\SweetIM\Messenger\mgAdaptersProxy.dll
                                      c:\windows\system32\eappprxy.dll
                                      c:\windows\system32\webcheck.dll
                                      c:\windows\system32\WPDShServiceObj.dll
                                      c:\windows\system32\PortableDeviceTypes.dll
                                      c:\windows\system32\PortableDeviceApi.dll
                                      .
                                      ------------------------ Autres processus actifs ------------------------
                                      .
                                      c:\program files\Avira\AntiVir PersonalEdition Classic\avguard.exe
                                      c:\windows\system32\msdtc.exe
                                      c:\program files\Avira\AntiVir PersonalEdition Classic\sched.exe
                                      c:\windows\eHome\ehRecvr.exe
                                      c:\windows\eHome\ehSched.exe
                                      c:\progra~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\1\FTRTSVC.exe
                                      c:\program files\Java\jre6\bin\jqs.exe
                                      c:\program files\Fichiers communs\LightScribe\LSSrvc.exe
                                      c:\windows\system32\nvsvc32.exe
                                      c:\windows\system32\PnkBstrA.exe
                                      c:\windows\system32\PnkBstrB.exe
                                      c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
                                      c:\windows\system32\mqsvc.exe
                                      c:\program files\Hewlett-Packard\Shared\hpqwmiex.exe
                                      c:\windows\ehome\mcrdsvc.exe
                                      c:\program files\Windows Media Player\WMPNetwk.exe
                                      c:\windows\system32\mqtgsvc.exe
                                      c:\windows\system32\dllhost.exe
                                      c:\windows\system32\wbem\wmiapsrv.exe
                                      c:\windows\eHome\ehmsas.exe
                                      c:\windows\system32\RUNDLL32.EXE
                                      c:\program files\iPod\bin\iPodService.exe
                                      c:\windows\system32\wscntfy.exe
                                      c:\program files\Brother\ControlCenter3\brccMCtl.exe
                                      c:\program files\Brother\Brmfcmon\BrMfcmon.exe
                                      c:\program files\Microsoft ActiveSync\wcescomm.exe
                                      c:\progra~1\MI3AA1~1\rapimgr.exe
                                      c:\progra~1\FICHIE~1\France Telecom\Shared Modules\AlertModule\0\AlertModule.exe
                                      c:\program files\HP\Digital Imaging\bin\hpqimzone.exe
                                      c:\program files\Orange\systray\systrayapp.exe
                                      .
                                      **************************************************************************
                                      .
                                      Heure de fin: 2010-01-03 00:48:47 - La machine a redémarré
                                      ComboFix-quarantined-files.txt 2010-01-02 23:48

                                      Avant-CF: 8 120 135 680 octets libres
                                      Après-CF: 11 739 906 048 octets libres

                                      - - End Of File - - 30D15D1FD026A3E6E198304ABDFB90AB

                                      ça a durée une bonne heure, l'icône de mon antivirus est reparut, et je n'ai plus de pub, il y a du mieux!
                                      Que dois-je faire maintenant?
                                      merci beaucoup pour votre aide
                                      0
                                      1. Contributeur sécurité
                                        dans cet ordre

                                        1)

                                        Téléchargez USBFIX de Chiquitine29, C_xx

                                        http://pagesperso-orange.fr/NosTools/Chiquitine29/UsbFix.exe
                                        ou
                                        https://www.ionos.fr/?affiliate_id=77097

                                        /!\ Utilisateur de vista et windows 7 :
                                        ne pas oublier de désactiver Le contrôle des comptes utilisateurs
                                        https://www.commentcamarche.net/faq/8343-vista-desactiver-l-uac

                                        /!\ Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) susceptible d'avoir été infectées sans les ouvrir

                                        • Double clic sur le raccourci UsbFix présent sur le bureau .

                                        • Choisir l'option2
                                        (d’autres options disponibles, voir le tutoriel).
                                        • Laissez travailler l'outil.
                                        Le menu démarrer et les icônes vont disparaître.. c'est normal.

                                        Si un message te demande de redémarrer l'ordinateur fais le ...

                                        ● Au redémarrage, le fix se relance... laisses l'opération s'effectuer.

                                        ● Le bloc note s'ouvre avec un rapport, envoies le dans la prochaine réponse

                                        • Note : Le rapport UsbFix.txt est sauvegardé a la racine du disque. ( C:\UsbFix.txt )

                                        ( CTRL+A Pour tout sélectionner , CTRL+C pour copier et CTRL+V pour coller )

                                        • Note : "Process.exe", une composante de l'outil, est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool.
                                        Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.
                                        Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall...) d'où l'alerte émise par ces antivirus.

                                        • Tuto : http://pagesperso-orange.fr/NosTools/usbfix.html

                                        UsbFix peut te demander d'uploader un dossier compressé à cette adresse : https://www.ionos.fr/?affiliate_id=77097

                                        Il est enregistré sur ton bureau.

                                        Merci de l'envoyer à l'adresse indiquée afin d'aider l'auteur de UsbFix dans ses recherches.

                                        Merci

                                        ...............................

                                        2)
                                        Téléchargez MalwareByte's Anti-Malware

                                        http://www.malwarebytes.org/mbam/program/mbam-setup.exe

                                        . Enregistres le sur le bureau
                                        . Double cliques sur le fichier téléchargé pour lancer le processus d'installation.
                                        . Dans l'onglet "mise à jour", cliques sur le bouton Recherche de mise à jour
                                        . Si le pare-feu demande l'autorisation de se connecter pour malwarebytes, accepte
                                        . Une fois la mise à jour terminé
                                        . Rend-toi dans l'onglet, Recherche
                                        . Sélectionnes Exécuter un examen complet
                                        . Cliques sur Rechercher
                                        . Le scan démarre.
                                        . A la fin de l'analyse, un message s'affiche : L'examen s'est terminé normalement. Cliquez sur 'Afficher les résultats' pour afficher tous les objets trouvés.
                                        . Cliques sur Ok pour poursuivre.
                                        . Si des malwares ont été détectés, clique sur Afficher les résultats
                                        . Sélectionnes tout (ou laisses cochés) et cliques sur Supprimer la sélection Malwarebytes va détruire les fichiers et clés de registre et en mettre une copie dans la quarantaine.
                                        . Malwarebytes va ouvrir le bloc-notes et y copier le rapport d'analyse.
                                        . Rends toi dans l'onglet rapport/log
                                        . Tu cliques dessus pour l'afficher, une fois affiché
                                        . Tu cliques sur edition en haut du boc notes, et puis sur sélectionner tous
                                        . Tu recliques sur edition et puis sur copier et tu reviens sur le forum et dans ta réponse
                                        . tu cliques droit dans le cadre de la reponse et coller

                                        Si tu as besoin d'aide regarde ces tutoriels :
                                        Aide: https://www.malekal.com/tutoriel-malwarebyte-anti-malware/
                                        http://www.infos-du-net.com/forum/278396-11-tuto-malwarebytes-anti-malware-mbam

                                        0
                                        • 1
                                        • 2