Generic host process

Résolu
Bonjour,

Comme beaucoup de monde avant moi, j'ai un message qui s'affiche en cours de navigation : "Generic Host Process" puis un autre message qui m'annonce que la session va se fermer en me donnant un compte à rebours de 1minute.
J'ai fais pas mal de manipulations comme indiqué dans ce forum et dans d'autres, visiblement je n'ai pas de virus Sasser ou Blaster, je suis sur la version SP3 de windows et Firefox 3.5.7 cela fait un mois que ça dure et j'avoue en avoir vraiment marre !

Merci pour votre aide.
Configuration: Windows XP
Firefox 3.5.7

24 réponses

Résumé de la discussion

La problématique centrale concerne l'apparition répétée d'un message Generic Host Process et un compte à rebours annonçant la fermeture de la session sous Windows XP SP3 et Firefox 3.5.7. Des manipulations multiples ont été évoquées comme possibles solutions, sans succès avéré, et des soupçons portent sur lsass.exe et d'autres éléments du système, malgré l'absence de virus Sasser ou Blaster. Les réponses proposent des analyses avec HijackThis et rapports système, puis des outils comme ComboFix et des analyses VirusTotal et RSIT pour évaluer les fichiers suspects et nettoyer les éléments malveillants. D'autres éléments notent la présence de services et processus variés et soulignent la nécessité de réactiver les protections après les manipulations avancées.

Bobot (l’IA à votre service)
  1. Contributeur sécurité
    bonjour

    • Télécharge Random's System Information Tool (RSIT) de Random/Random.

    (outil de diagnostic)

    http://images.malwareremoval.com/random/RSIT.exe

    • Enregistre le sur ton Bureau.

    • Double clique sur RSIT.exe pour lancer l'outil.

    • Clique sur "Continue" à l'écran Disclaimer.

    • Si l'outil HijackThis n'est pas présent ou non détecté sur l'ordinateur, RSIT le téléchargera (autorise l'accès dans ton pare-feu s'il te le demande)

    et tu devras accepter la licence.

    • Une fois le scan terminé, deux rapports vont apparaître : poste les dans deux messages séparés stp

    Les rapports se trouvent à cet endroit:
    C:\rsit\info.txt
    C:\rsit\log.txt

    1. Merci pour ton aide, voici le rapport :

      info.txt logfile of random's system information tool 1.06 2010-02-02 17:04:24

      ======Uninstall list======

      -->C:\WINDOWS\IsUn040c.exe -fC:\WINDOWS\orun32.isu
      -->C:\WINDOWS\system32\RunDll32.Exe C:\WINDOWS\system32\SetupAPI.Dll,InstallHinfSection DefaultUninstall.NTx86 4 C:\WINDOWS\INF\tdudf.Inf
      -->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{D43F13A1-1E39-4BD4-9682-DF889FE75421}\setup.exe" -l0x40c
      -->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{D43F13A1-1E39-4BD4-9682-DF889FE75421}\setup.exe" -l0x40c /remove
      -->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
      32 Bit HP CIO Components Installer-->MsiExec.exe /I{F1E63043-54FC-429B-AB2C-31AF9FBA4BC7}
      Adobe Flash Player 10 Plugin-->C:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe
      Adobe Flash Player 9 ActiveX-->C:\WINDOWS\system32\Macromed\Flash\FlashUtil9b.exe -uninstallDelete
      Adobe Reader 7.0.9 - Français-->MsiExec.exe /I{AC76BA86-7AD7-1036-7B44-A70900000002}
      ALPS Touch Pad Driver-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{9F72EF8B-AEC9-4CA5-B483-143980AFD6FD}\setup.exe" UNINSTALL
      Assist TOSHIBA-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{12B3A009-A080-4619-9A2A-C6DB151D8D67}\Setup.exe" -l0x40c
      Assistant de connexion Windows Live-->MsiExec.exe /I{D3116CC7-24DC-4CA3-9CE1-23FED836E9F2}
      Atheros Client Utility-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{71D658CF-4E0D-4DA8-AA67-8C0B6F1C01FE}\setup.exe" -l0x40c
      Atheros Wireless LAN MiniPCI/PCIe card Driver-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{05832D65-6EDB-4D32-BA78-BCD0E2B91C02}\setup.exe" -l0x40c
      ATI - Utilitaire de désinstallation du logiciel-->C:\Program Files\ATI Technologies\UninstallAll\AtiCimUn.exe
      ATI Display Driver-->rundll32 C:\WINDOWS\system32\atiiiexx.dll,_InfEngUnInstallINFFile_RunDLL@16 -force_restart -flags:0x2010001 -inf_class:DISPLAY -clean
      Barre d'outils MSN Search-->MsiExec.exe /X{B2CF0FAC-D52C-41D8-81E0-BFD7A3E7C84B}
      Correctif pour Lecteur Windows Media 11 (KB939683)-->"C:\WINDOWS\$NtUninstallKB939683$\spuninst\spuninst.exe"
      Correctif pour Windows Internet Explorer 7 (KB947864)-->"C:\WINDOWS\ie7updates\KB947864-IE7\spuninst\spuninst.exe"
      Correctif pour Windows XP (KB952287)-->"C:\WINDOWS\$NtUninstallKB952287$\spuninst\spuninst.exe"
      Correctif pour Windows XP (KB961118)-->"C:\WINDOWS\$NtUninstallKB961118$\spuninst\spuninst.exe"
      Correctif pour Windows XP (KB970653-v3)-->"C:\WINDOWS\$NtUninstallKB970653-v3$\spuninst\spuninst.exe"
      Correctif pour Windows XP (KB976098-v2)-->"C:\WINDOWS\$NtUninstallKB976098-v2$\spuninst\spuninst.exe"
      Galerie de photos Windows Live-->MsiExec.exe /X{B131E59D-202C-43C6-84C9-68F0C37541F1}
      Gestion d'énergie TOSHIBA-->C:\WINDOWS\IsUn040c.exe -f"C:\Program Files\TOSHIBA\Power Saver\Uninst.isu" -c"C:\WINDOWS\system32\TPSDel.dll"
      Google Earth-->MsiExec.exe /I{1E04F83B-2AB9-4301-9EF7-E86307F79C72}
      High Definition Audio Driver Package - KB888111-->"C:\WINDOWS\$NtUninstallKB888111WXPSP2$\spuninst\spuninst.exe"
      HijackThis 2.0.2-->"C:\Program Files\Trend Micro\HijackThis\HijackThis.exe" /uninstall
      Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)-->C:\WINDOWS\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall /qb+ REBOOTPROMPT=""
      Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)-->C:\WINDOWS\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {A7EEA2F2-BFCD-4A54-A575-7B81A786E658} /qb+ REBOOTPROMPT=""
      Hotfix for Windows Media Format 11 SDK (KB929399)-->"C:\WINDOWS\$NtUninstallKB929399$\spuninst\spuninst.exe"
      HP Customer Participation Program 9.0-->C:\Program Files\HP\Digital Imaging\ExtCapUninstall\hpzscr01.exe -datfile hpqhsc01.dat
      HP Imaging Device Functions 9.0-->C:\Program Files\HP\Digital Imaging\DeviceManagement\hpzscr01.exe -datfile hpqbud01.dat
      HP OCR Software 9.0-->C:\Program Files\HP\Digital Imaging\OCR\hpzscr01.exe -datfile hpqbud11.dat
      HP Photosmart All-In-One Software 9.0-->C:\Program Files\HP\Digital Imaging\{D64BC2CF-0F12-47d7-B412-B4F3FD684253}\setup\hpzscr01.exe -datfile hposcr21.dat
      HP Photosmart Essential 2.01-->C:\Program Files\HP\Digital Imaging\PhotoSmartEssential\hpzscr01.exe -datfile hpqbud13.dat
      HP Smart Web Printing-->MsiExec.exe /X{415CDA53-9100-476F-A7B2-476691E117C7}
      HP Solution Center 9.0-->C:\Program Files\HP\Digital Imaging\eSupport\hpzscr01.exe -datfile hpqbud05.dat
      HP Update-->MsiExec.exe /X{AB40272D-92AB-4F30-B36B-22EDE16F8FE5}
      HPSSupply-->MsiExec.exe /X{487B0B9B-DCD4-440D-89A0-A6EDE1A545A3}
      Installation Windows Live-->C:\Program Files\Windows Live\Installer\wlarp.exe
      Installation Windows Live-->MsiExec.exe /I{46ABBC54-1872-4AA3-95E2-F2C063A63F31}
      InterVideo WinDVD for TOSHIBA-->"C:\Program Files\InstallShield Installation Information\{91810AFC-A4F8-4EBA-A5AA-B198BBC81144}\setup.exe" REMOVEALL
      Junk Mail filter update-->MsiExec.exe /I{E2DFE069-083E-4631-9B6C-43C48E991DE5}
      Lecteur Windows Media 11-->"C:\Program Files\Windows Media Player\Setup_wm.exe" /Uninstall
      livebox-->C:\Program Files\InstallShield Installation Information\{17342E3B-0818-4A6F-BFF8-99476605ADD6}\Setup.exe -runfromtemp -l0x040c -removeonly
      Logitech Desktop Messenger-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{900B1197-53F5-4F46-A882-2CFFFE2EEDCB}\Setup.exe" -l0x40c UNINSTALL
      Logitech QuickCam-->MsiExec.exe /X{364EC092-93CF-4DDC-9D7A-7278452028E0}
      Macromedia Flash Player-->MsiExec.exe /X{0456ebd7-5f67-4ab6-852e-63781e3f389c}
      Malwarebytes' Anti-Malware-->"C:\Program Files\Malwarebytes' Anti-Malware\unins001.exe"
      Manuels TOSHIBA-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\10\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{3EB6332B-AF02-457C-A31C-835458C5B48B}\setup.exe" -l0x40c -removeonly
      Microsoft .NET Framework 1.1 French Language Pack-->MsiExec.exe /X{9A394342-4A68-4EBA-85A6-55B559F4E700}
      Microsoft .NET Framework 1.1 Security Update (KB953297)-->"C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\hotfix.exe" "C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\M953297\M953297Uninstall.msp"
      Microsoft .NET Framework 1.1-->msiexec.exe /X {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
      Microsoft .NET Framework 1.1-->MsiExec.exe /X{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
      Microsoft .NET Framework 2.0 Service Pack 2-->MsiExec.exe /I{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}
      Microsoft .NET Framework 3.0 Service Pack 2-->MsiExec.exe /I{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}
      Microsoft .NET Framework 3.5 SP1-->C:\WINDOWS\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setup.exe
      Microsoft .NET Framework 3.5 SP1-->MsiExec.exe /I{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}
      Microsoft Choice Guard-->MsiExec.exe /X{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}
      Microsoft Compression Client Pack 1.0 for Windows XP-->"C:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe"
      Microsoft Internationalized Domain Names Mitigation APIs-->"C:\WINDOWS\$NtServicePackUninstallIDNMitigationAPIs$\spuninst\spuninst.exe"
      Microsoft National Language Support Downlevel APIs-->"C:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$\spuninst\spuninst.exe"
      Microsoft Office Live Add-in 1.3-->MsiExec.exe /I{57F0ED40-8F11-41AA-B926-4A66D0D1A9CC}
      Microsoft Office XP Professional avec FrontPage-->MsiExec.exe /I{9028040C-6000-11D3-8CFE-0050048383C9}
      Microsoft Photo 2006 Starter Edition-->"C:\Program Files\Fichiers communs\Microsoft Shared\Picture It!\RmvSuite.exe" ADDREMOVE=1 SKU=TRIAL VERSION=11
      Microsoft Search Enhancement Pack-->MsiExec.exe /X{4CBA3D4C-8F51-4D60-B27E-F6B641C571E7}
      Microsoft Silverlight-->MsiExec.exe /X{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
      Microsoft SQL Server 2005 Compact Edition [ENU]-->MsiExec.exe /I{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}
      Microsoft Sync Framework Runtime Native v1.0 (x86)-->MsiExec.exe /I{8A74E887-8F0F-4017-AF53-CBA42211AAA5}
      Microsoft Sync Framework Services Native v1.0 (x86)-->MsiExec.exe /I{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}
      Microsoft User-Mode Driver Framework Feature Pack 1.0-->"C:\WINDOWS\$NtUninstallWudf01000$\spuninst\spuninst.exe"
      Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148-->MsiExec.exe /X{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}
      Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17-->MsiExec.exe /X{9A25302D-30C0-39D9-BD6F-21E6EC160475}
      Microsoft Works-->MsiExec.exe /I{6B1CB38D-E2E4-4A30-933D-EFDEBA76AD9C}
      Mise à jour critique pour Lecteur Windows Media 11 (KB959772)-->"C:\WINDOWS\$NtUninstallKB959772_WM11$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Lecteur Windows Media (KB952069)-->"C:\WINDOWS\$NtUninstallKB952069_WM9$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Lecteur Windows Media (KB954155)-->"C:\WINDOWS\$NtUninstallKB954155_WM9$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Lecteur Windows Media (KB968816)-->"C:\WINDOWS\$NtUninstallKB968816_WM9$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Lecteur Windows Media (KB973540)-->"C:\WINDOWS\$NtUninstallKB973540_WM9$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Lecteur Windows Media 10 (KB911565)-->"C:\WINDOWS\$NtUninstallKB911565$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Lecteur Windows Media 10 (KB917734)-->"C:\WINDOWS\$NtUninstallKB917734_WMP10$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Lecteur Windows Media 10 (KB936782)-->"C:\WINDOWS\$NtUninstallKB936782_WMP10$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Lecteur Windows Media 11 (KB936782)-->"C:\WINDOWS\$NtUninstallKB936782_WMP11$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Lecteur Windows Media 11 (KB954154)-->"C:\WINDOWS\$NtUninstallKB954154_WM11$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Step by Step Interactive Training (KB898458)-->"C:\WINDOWS\$NtUninstallKB898458$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Step by Step Interactive Training (KB923723)-->"C:\WINDOWS\$NtUninstallKB923723$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows Internet Explorer 7 (KB928090)-->"C:\WINDOWS\ie7updates\KB928090-IE7\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows Internet Explorer 7 (KB931768)-->"C:\WINDOWS\ie7updates\KB931768-IE7\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows Internet Explorer 7 (KB933566)-->"C:\WINDOWS\ie7updates\KB933566-IE7\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows Internet Explorer 7 (KB937143)-->"C:\WINDOWS\ie7updates\KB937143-IE7\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows Internet Explorer 7 (KB938127)-->"C:\WINDOWS\ie7updates\KB938127-IE7\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows Internet Explorer 7 (KB939653)-->"C:\WINDOWS\ie7updates\KB939653-IE7\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows Internet Explorer 7 (KB942615)-->"C:\WINDOWS\ie7updates\KB942615-IE7\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows Internet Explorer 7 (KB944533)-->"C:\WINDOWS\ie7updates\KB944533-IE7\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows Internet Explorer 7 (KB950759)-->"C:\WINDOWS\ie7updates\KB950759-IE7\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows Internet Explorer 7 (KB953838)-->"C:\WINDOWS\ie7updates\KB953838-IE7\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows Internet Explorer 7 (KB958215)-->"C:\WINDOWS\ie7updates\KB958215-IE7\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows Internet Explorer 7 (KB960714)-->"C:\WINDOWS\ie7updates\KB960714-IE7\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows Internet Explorer 7 (KB961260)-->"C:\WINDOWS\ie7updates\KB961260-IE7\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows Internet Explorer 7 (KB963027)-->"C:\WINDOWS\ie7updates\KB963027-IE7\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows Internet Explorer 7 (KB969897)-->"C:\WINDOWS\ie7updates\KB969897-IE7\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows Internet Explorer 7 (KB972260)-->"C:\WINDOWS\ie7updates\KB972260-IE7\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows Internet Explorer 7 (KB974455)-->"C:\WINDOWS\ie7updates\KB974455-IE7\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows Internet Explorer 7 (KB976325)-->"C:\WINDOWS\ie7updates\KB976325-IE7\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows Internet Explorer 7 (KB978207)-->"C:\WINDOWS\ie7updates\KB978207-IE7\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows Internet Explorer 8 (KB971961)-->"C:\WINDOWS\ie8updates\KB971961-IE8\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows Internet Explorer 8 (KB978207)-->"C:\WINDOWS\ie8updates\KB978207-IE8\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB923561)-->"C:\WINDOWS\$NtUninstallKB923561$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB938464)-->"C:\WINDOWS\$NtUninstallKB938464$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB938464-v2)-->"C:\WINDOWS\$NtUninstallKB938464-v2$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB941569)-->"C:\WINDOWS\$NtUninstallKB941569$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB946648)-->"C:\WINDOWS\$NtUninstallKB946648$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB950760)-->"C:\WINDOWS\$NtUninstallKB950760$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB950762)-->"C:\WINDOWS\$NtUninstallKB950762$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB950974)-->"C:\WINDOWS\$NtUninstallKB950974$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB951066)-->"C:\WINDOWS\$NtUninstallKB951066$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB951376)-->"C:\WINDOWS\$NtUninstallKB951376$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB951376-v2)-->"C:\WINDOWS\$NtUninstallKB951376-v2$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB951698)-->"C:\WINDOWS\$NtUninstallKB951698$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB951748)-->"C:\WINDOWS\$NtUninstallKB951748$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB952004)-->"C:\WINDOWS\$NtUninstallKB952004$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB952954)-->"C:\WINDOWS\$NtUninstallKB952954$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB953839)-->"C:\WINDOWS\$NtUninstallKB953839$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB954211)-->"C:\WINDOWS\$NtUninstallKB954211$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB954459)-->"C:\WINDOWS\$NtUninstallKB954459$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB954600)-->"C:\WINDOWS\$NtUninstallKB954600$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB955069)-->"C:\WINDOWS\$NtUninstallKB955069$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB956391)-->"C:\WINDOWS\$NtUninstallKB956391$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB956572)-->"C:\WINDOWS\$NtUninstallKB956572$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB956744)-->"C:\WINDOWS\$NtUninstallKB956744$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB956802)-->"C:\WINDOWS\$NtUninstallKB956802$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB956803)-->"C:\WINDOWS\$NtUninstallKB956803$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB956841)-->"C:\WINDOWS\$NtUninstallKB956841$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB956844)-->"C:\WINDOWS\$NtUninstallKB956844$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB957095)-->"C:\WINDOWS\$NtUninstallKB957095$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB957097)-->"C:\WINDOWS\$NtUninstallKB957097$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB958644)-->"C:\WINDOWS\$NtUninstallKB958644$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB958687)-->"C:\WINDOWS\$NtUninstallKB958687$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB958690)-->"C:\WINDOWS\$NtUninstallKB958690$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB958869)-->"C:\WINDOWS\$NtUninstallKB958869$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB959426)-->"C:\WINDOWS\$NtUninstallKB959426$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB960225)-->"C:\WINDOWS\$NtUninstallKB960225$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB960715)-->"C:\WINDOWS\$NtUninstallKB960715$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB960803)-->"C:\WINDOWS\$NtUninstallKB960803$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB960859)-->"C:\WINDOWS\$NtUninstallKB960859$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB961371)-->"C:\WINDOWS\$NtUninstallKB961371$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB961373)-->"C:\WINDOWS\$NtUninstallKB961373$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB961501)-->"C:\WINDOWS\$NtUninstallKB961501$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB968537)-->"C:\WINDOWS\$NtUninstallKB968537$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB969059)-->"C:\WINDOWS\$NtUninstallKB969059$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB969898)-->"C:\WINDOWS\$NtUninstallKB969898$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB969947)-->"C:\WINDOWS\$NtUninstallKB969947$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB970238)-->"C:\WINDOWS\$NtUninstallKB970238$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB970430)-->"C:\WINDOWS\$NtUninstallKB970430$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB971486)-->"C:\WINDOWS\$NtUninstallKB971486$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB971557)-->"C:\WINDOWS\$NtUninstallKB971557$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB971633)-->"C:\WINDOWS\$NtUninstallKB971633$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB971657)-->"C:\WINDOWS\$NtUninstallKB971657$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB971961)-->"C:\WINDOWS\$NtUninstallKB971961$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB972270)-->"C:\WINDOWS\$NtUninstallKB972270$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB973346)-->"C:\WINDOWS\$NtUninstallKB973346$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB973354)-->"C:\WINDOWS\$NtUninstallKB973354$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB973507)-->"C:\WINDOWS\$NtUninstallKB973507$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB973525)-->"C:\WINDOWS\$NtUninstallKB973525$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB973869)-->"C:\WINDOWS\$NtUninstallKB973869$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB973904)-->"C:\WINDOWS\$NtUninstallKB973904$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB974112)-->"C:\WINDOWS\$NtUninstallKB974112$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB974318)-->"C:\WINDOWS\$NtUninstallKB974318$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB974392)-->"C:\WINDOWS\$NtUninstallKB974392$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB974571)-->"C:\WINDOWS\$NtUninstallKB974571$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB975025)-->"C:\WINDOWS\$NtUninstallKB975025$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB975467)-->"C:\WINDOWS\$NtUninstallKB975467$\spuninst\spuninst.exe"
      Mise à jour pour Windows Internet Explorer 7 (KB976749)-->"C:\WINDOWS\ie7updates\KB976749-IE7\spuninst\spuninst.exe"
      Mise à jour pour Windows XP (KB951072-v2)-->"C:\WINDOWS\$NtUninstallKB951072-v2$\spuninst\spuninst.exe"
      Mise à jour pour Windows XP (KB951978)-->"C:\WINDOWS\$NtUninstallKB951978$\spuninst\spuninst.exe"
      Mise à jour pour Windows XP (KB955759)-->"C:\WINDOWS\$NtUninstallKB955759$\spuninst\spuninst.exe"
      Mise à jour pour Windows XP (KB955839)-->"C:\WINDOWS\$NtUninstallKB955839$\spuninst\spuninst.exe"
      Mise à jour pour Windows XP (KB961503)-->"C:\WINDOWS\$NtUninstallKB961503$\spuninst\spuninst.exe"
      Mise à jour pour Windows XP (KB967715)-->"C:\WINDOWS\$NtUninstallKB967715$\spuninst\spuninst.exe"
      Mise à jour pour Windows XP (KB968389)-->"C:\WINDOWS\$NtUninstallKB968389$\spuninst\spuninst.exe"
      Mise à jour pour Windows XP (KB971737)-->"C:\WINDOWS\$NtUninstallKB971737$\spuninst\spuninst.exe"
      Mise à jour pour Windows XP (KB973687)-->"C:\WINDOWS\$NtUninstallKB973687$\spuninst\spuninst.exe"
      Mise à jour pour Windows XP (KB973815)-->"C:\WINDOWS\$NtUninstallKB973815$\spuninst\spuninst.exe"
      Mozilla Firefox (3.5.7)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
      MSN-->C:\Program Files\MSN\MsnInstaller\msninst.exe /Action:ARP
      MSVCRT-->MsiExec.exe /I{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}
      MSXML 4.0 SP2 (KB927978)-->MsiExec.exe /I{37477865-A3F1-4772-AD43-AAFC6BCFF99F}
      MSXML 4.0 SP2 (KB936181)-->MsiExec.exe /I{C04E32E0-0416-434D-AFB9-6969D703A9EF}
      MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
      MSXML 4.0 SP2 (KB973688)-->MsiExec.exe /I{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}
      MVision-->MsiExec.exe /I{35725FBC-A136-4A46-9F29-091759D9BB93}
      Navigateur Orange-->C:\Program Files\Orange\Uninstall\Browser\Shell.exe MainUninstall.shl
      Orange - Logiciels Internet-->C:\Program Files\Orange\installation\core\Installgui.exe -u
      Outil de diagnostic PC TOSHIBA-->C:\WINDOWS\IsUn040c.exe -f"C:\Program Files\TOSHIBA\PCDiag\Uninst.isu"
      Outil de téléchargement Windows Live-->MsiExec.exe /I{205C6BDD-7B73-42DE-8505-9A093F35A238}
      Panneau de contrôle ATI-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{0BEDBD4E-2D34-47B5-9973-57E62B29307C}\setup.exe"
      Programme de gestion Camera de Logitech®-->"C:\Program Files\Fichiers communs\LogiShrd\QCDRV\BIN\SETUP.EXE" UNINSTALL REMOVEPROMPT
      QuickTime-->MsiExec.exe /I{1451DE6B-ABE1-4F62-BE9A-B363A17588A2}
      REALTEK Gigabit and Fast Ethernet NIC Driver-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{94FB906A-CF42-4128-A509-D353026A607E}\Setup.exe" -l0x40c REMOVE
      Realtek High Definition Audio Driver-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}\Setup.exe" -l0x40c -removeonly
      Réducteur de bruit lect. CD/DVD-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{9FE35071-CAB2-4E79-93E7-BFC6A2DC5C5D}\Setup.exe" -l0x40c
      SAGEM F@st 800-840-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{4AE3A0CB-87B0-4F51-BECD-3D1F8DFDD62F}\setup.exe" -l0x40c
      Security Update for CAPICOM (KB931906)-->MsiExec.exe /I{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
      Security Update for CAPICOM (KB931906)-->MsiExec.exe /X{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
      Segoe UI-->MsiExec.exe /I{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}
      Son virtuel TOSHIBA-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{8B12BA86-ADAC-4BA6-B441-FFC591087252}\setup.exe" /uninstall
      TOSHIBA Accessibility-->C:\PROGRA~1\FICHIE~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{3A57482F-BEBC-47E4-ADA1-6302403C7E50} /l1036
      TOSHIBA ConfigFree-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{BDD83DC9-BEE9-4654-A5DA-CC46C250088D}\setup.exe" -l0x40c UNINSTALL
      TOSHIBA Direct Disc Writer-->MsiExec.exe /X{400830CA-F056-4BBE-80A3-9DF9CA4FB889}
      TOSHIBA Disc Creator-->MsiExec.exe /X{529DDE6B-4F31-438B-B218-F36266ABD8C0}
      TOSHIBA Hardware Setup-->C:\PROGRA~1\FICHIE~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{5279374D-87FE-4879-9385-F17278EBB9D3} /l1036
      TOSHIBA Mot de passe responsable-->C:\PROGRA~1\FICHIE~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{51B4E156-14A5-4904-9AE4-B1AA2A0E46BE} /l1036
      TOSHIBA Software Modem-->Tosmreg -U
      Touch and Launch-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{5D96E2B1-D9AC-46E0-9073-425C5F63E338}\setup.exe"
      Uniblue RegistryBooster 2010-->"C:\Program Files\Uniblue\RegistryBooster\unins000.exe"
      Uniblue System Tweaker-->"C:\Program Files\Uniblue\System Tweaker\unins000.exe"
      Update for Microsoft .NET Framework 3.5 SP1 (KB963707)-->C:\WINDOWS\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {B2AE9C82-DC7B-3641-BFC8-87275C4F3607} /qb+ REBOOTPROMPT=""
      Utilitaire de zoom TOSHIBA-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{64212898-097F-4F3F-AECA-6D34A7EF82DF}\Setup.exe" -l0x40c
      Utilitaire Hotkey TOSHIBA-->C:\PROGRA~1\FICHIE~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{7900D3A6-A9E8-4954-ACCB-AB15867978BF} /l1036
      Utilitaire TouchPad ON/OFF-->C:\PROGRA~1\FICHIE~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{80977342-27E8-4FF7-8B6A-D8D89461DA7F} /l1036
      Windows Internet Explorer 8-->"C:\WINDOWS\ie8\spuninst\spuninst.exe"
      Windows Live Call-->MsiExec.exe /I{82C7B308-0BDD-49D8-8EA5-9CD3A3F9DF41}
      Windows Live Communications Platform-->MsiExec.exe /I{ED00D08A-3C5F-488D-93A0-A04F21F23956}
      Windows Live Contrôle parental-->MsiExec.exe /X{D5D81435-B8DE-4CAF-867F-7998F2B92CFC}
      Windows Live FolderShare-->MsiExec.exe /X{2075CB0A-D26F-4DAA-B424-5079296B43BA}
      Windows Live Mail-->MsiExec.exe /I{5DD76286-9BE7-4894-A990-E905E91AC818}
      Windows Live Messenger-->MsiExec.exe /X{770F1BEC-2871-4E70-B837-FB8525FFA3B1}
      Windows Live Toolbar-->MsiExec.exe /X{F7D27C70-90F5-49B9-B188-0A133C0CE353}
      Windows Live Writer-->MsiExec.exe /X{4634B21A-CC07-4396-890C-2B8168661FEA}
      Windows Media Format 11 runtime-->"C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll
      Windows Media Format 11 runtime-->"C:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe"
      Windows Media Player 11-->"C:\WINDOWS\$NtUninstallwmp11$\spuninst\spuninst.exe"
      Windows XP Service Pack 3-->"C:\WINDOWS\$NtServicePackUninstall$\spuninst\spuninst.exe"

      ======Security center information======

      FW: Norton Internet Worm Protection (disabled)

      ======System event log======

      Computer Name: YOUR-35063AB16-
      Event Code: 7036
      Message: Le service Gestionnaire de connexions d'accès distant est entré dans l'état : en cours d'exécution.

      Record Number: 49190
      Source Name: Service Control Manager
      Time Written: 20100127174541.000000+060
      Event Type: Informations
      User:

      Computer Name: YOUR-35063AB16-
      Event Code: 7035
      Message: Un contrôle Démarrer a correctement été envoyé au service Gestionnaire de connexions d'accès distant.

      Record Number: 49189
      Source Name: Service Control Manager
      Time Written: 20100127174541.000000+060
      Event Type: Informations
      User: AUTORITE NT\SYSTEM

      Computer Name: YOUR-35063AB16-
      Event Code: 7036
      Message: Le service Téléphonie est entré dans l'état : en cours d'exécution.

      Record Number: 49188
      Source Name: Service Control Manager
      Time Written: 20100127174541.000000+060
      Event Type: Informations
      User:

      Computer Name: YOUR-35063AB16-
      Event Code: 7036
      Message: Le service Service de la passerelle de la couche Application est entré dans l'état : en cours d'exécution.

      Record Number: 49187
      Source Name: Service Control Manager
      Time Written: 20100127174541.000000+060
      Event Type: Informations
      User:

      Computer Name: YOUR-35063AB16-
      Event Code: 7035
      Message: Un contrôle Démarrer a correctement été envoyé au service Service de la passerelle de la couche Application.

      Record Number: 49186
      Source Name: Service Control Manager
      Time Written: 20100127174541.000000+060
      Event Type: Informations
      User: AUTORITE NT\SYSTEM

      =====Application event log=====

      Computer Name: YOUR-35063AB16-
      Event Code: 1004
      Message: Échec de détection du produit '{364EC092-93CF-4DDC-9D7A-7278452028E0}', fonctionnalité 'QuickCam', composant '{B52C7B4D-F46F-438C-ADF2-05A138C57757}. La ressource 'HKEY_CURRENT_USER\Software\Logitech\QuickCam10\DesktopShortcutKey' n'existe pas

      Record Number: 48117
      Source Name: MsiInstaller
      Time Written: 20100131192656.000000+060
      Event Type: Avertissement
      User: YOUR-35063AB16-\nathalie

      Computer Name: YOUR-35063AB16-
      Event Code: 1001
      Message: Échec de détection du produit '{364EC092-93CF-4DDC-9D7A-7278452028E0}', fonctionnalité 'QuickCam' lors de la demande du composant '{62BA7C13-20BB-41F7-A6A4-482632CE53D4}'

      Record Number: 48116
      Source Name: MsiInstaller
      Time Written: 20100131192656.000000+060
      Event Type: Avertissement
      User: YOUR-35063AB16-\nathalie

      Computer Name: YOUR-35063AB16-
      Event Code: 1004
      Message: Échec de détection du produit '{364EC092-93CF-4DDC-9D7A-7278452028E0}', fonctionnalité 'QuickCam', composant '{B52C7B4D-F46F-438C-ADF2-05A138C57757}. La ressource 'HKEY_CURRENT_USER\Software\Logitech\QuickCam10\DesktopShortcutKey' n'existe pas

      Record Number: 48115
      Source Name: MsiInstaller
      Time Written: 20100131192656.000000+060
      Event Type: Avertissement
      User: YOUR-35063AB16-\nathalie

      Computer Name: YOUR-35063AB16-
      Event Code: 1001
      Message: Échec de détection du produit '{364EC092-93CF-4DDC-9D7A-7278452028E0}', fonctionnalité 'QuickCam' lors de la demande du composant '{62BA7C13-20BB-41F7-A6A4-482632CE53D4}'

      Record Number: 48114
      Source Name: MsiInstaller
      Time Written: 20100131192655.000000+060
      Event Type: Avertissement
      User: YOUR-35063AB16-\nathalie"NUM

      Computer Name: YOUR-35063AB16-
      Event Code: 1004
      Message: Échec de détection du produit '{364EC092-93CF-4DDC-9D7A-7278452028E0}', fonctionnalité 'QuickCam', composant '{B52C7B4D-F46F-438C-ADF2-05A138C57757}. La ressource 'HKEY_CURRENT_USER\Software\Logitech\QuickCam10\DesktopShortcutKey' n'existe pas

      Record Number: 48113
      Source Name: MsiInstaller
      Time Written: 20100131192655.000000+060
      Event Type: Avertissement
      User: YOUR-35063AB16-\nathalie

      ======Environment variables======

      "ComSpec"=%SystemRoot%\system32\cmd.exe
      "Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;C:\Program Files\ATI Technologies\ATI Control Panel;C:\Program Files\QuickTime\QTSystem\
      "windir"=%SystemRoot%
      "FP_NO_HOST_CHECK"=NO
      "OS"=Windows_NT
      "PROCESSOR_ARCHITECTURE"=x86
      "PROCESSOR_LEVEL"=6
      "PROCESSOR_IDENTIFIER"=x86 Family 6 Model 14 Stepping 8, GenuineIntel
      "PROCESSOR_REVISION"=0e08
      "NUMBER_OF_PROCESSORS"=1
      "PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
      "TEMP"=%SystemRoot%\TEMP
      "TMP"=%SystemRoot%\TEMP
      "CLASSPATH"=.;C:\Program Files\QuickTime\QTSystem\QTJava.zip
      "QTJAVA"=C:\Program Files\QuickTime\QTSystem\QTJava.zip

      -----------------EOF-----------------
    2. Et voici la suite, rapport log :

      Logfile of random's system information tool 1.06 (written by random/random)
      Run by nathalie at 2010-02-02 17:04:02
      Microsoft Windows XP Édition familiale Service Pack 3
      System drive C: has 45 GB (79%) free of 57 GB
      Total RAM: 446 MB (22% free)

      Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 17:04:15, on 02/02/2010
      Platform: Windows XP SP3 (WinNT 5.01.2600)
      MSIE: Internet Explorer v8.00 (8.00.6001.18702)
      Boot mode: Normal

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\Ati2evxx.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\Program Files\Fichiers communs\LogiShrd\LVMVFM\LVPrcSrv.exe
      C:\WINDOWS\system32\acs.exe
      C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
      C:\WINDOWS\system32\dllhost.exe
      C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\Program Files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe
      C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\TODDSrv.exe
      C:\WINDOWS\system32\Ati2evxx.exe
      C:\WINDOWS\Explorer.EXE
      C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
      C:\WINDOWS\RTHDCPL.EXE
      C:\Program Files\Apoint2K\Apoint.exe
      C:\Program Files\ltmoh\Ltmoh.exe
      C:\WINDOWS\AGRSMMSG.exe
      C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe
      C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe
      C:\Program Files\TOSHIBA\TouchPad\TPTray.exe
      C:\WINDOWS\system32\ZoomingHook.exe
      C:\WINDOWS\system32\TPSMain.exe
      C:\Program Files\TOSHIBA\Utilitaire de zoom TOSHIBA\SmoothView.exe
      C:\Program Files\TOSHIBA\Tvs\TvsTray.exe
      C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe
      C:\Program Files\TOSHIBA\TOSHIBA Direct Disc Writer\ddwmon.exe
      C:\Program Files\TOSHIBA\ConfigFree\CFSServ.exe
      C:\Program Files\Fichiers communs\LogiShrd\LComMgr\Communications_Helper.exe
      C:\Program Files\Logitech\QuickCam\Quickcam.exe
      C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
      C:\Program Files\Orange\Systray\SystrayApp.exe
      C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
      C:\WINDOWS\system32\ctfmon.exe
      C:\Program Files\Windows Live\Messenger\msnmsgr.exe
      C:\Program Files\Apoint2K\Apntex.exe
      C:\WINDOWS\system32\rundll32.exe
      C:\WINDOWS\system32\TPSBattM.exe
      C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\AlertModule\0\AlertModule.exe
      C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
      C:\Program Files\TOSHIBA\ConfigFree\CFXFER.exe
      C:\Program Files\Fichiers communs\Logishrd\LQCVFX\COCIManager.exe
      C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
      C:\WINDOWS\System32\svchost.exe
      C:\Program Files\Mozilla Firefox\firefox.exe
      C:\Program Files\Orange\Launcher\Launcher.exe
      C:\Program Files\Orange\connectivity\connectivitymanager.exe
      C:\Program Files\Orange\Deskboard\deskboard.exe
      C:\Program Files\Orange\connectivity\CoreCom\CoreCom.exe
      C:\Program Files\Orange\connectivity\CoreCom\OraConfigRecover.exe
      C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTCOMModule\0\FTCOMModule.exe
      C:\Documents and Settings\nathalie\Mes documents\Téléchargements\RSIT.exe
      C:\Program Files\Trend Micro\HijackThis\nathalie.exe

      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?FORM=TOOLBR&cc=fr&toHttps=1&redig=4527FFF1C12746FC9EDB535C75E80ECC
      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
      R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = https://www.bing.com/?FORM=TOOLBR&cc=fr&toHttps=1&redig=4527FFF1C12746FC9EDB535C75E80ECC
      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,First Home Page = https://support.microsoft.com/en-US/topic/internet-explorer-downloads-d49e1f0d-571c-9a7b-d97e-be248806ca70
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
      R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\Program Files\Orange\SearchURLHook\SearchPageURL.dll
      O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Smart Web Printing\hpswp_printenhancer.dll
      O2 - BHO: HP Print Clips - {053F9267-DC04-4294-A72C-58F732D338C0} - C:\Program Files\HP\Smart Web Printing\hpswp_framework.dll
      O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
      O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
      O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
      O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
      O2 - BHO: Barre d'outils MSN Search Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar Suite\TB\02.05.0000.1105\fr-fr\msntb.dll
      O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
      O3 - Toolbar: Barre d'outils MSN Search - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar Suite\TB\02.05.0000.1105\fr-fr\msntb.dll
      O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
      O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
      O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
      O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
      O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
      O4 - HKLM\..\Run: [LtMoh] C:\Program Files\ltmoh\Ltmoh.exe
      O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
      O4 - HKLM\..\Run: [PadTouch] C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe
      O4 - HKLM\..\Run: [CeEKEY] C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe
      O4 - HKLM\..\Run: [HWSetup] C:\Program Files\TOSHIBA\TOSHIBA Applet\HWSetup.exe hwSetUP
      O4 - HKLM\..\Run: [SVPWUTIL] C:\Program Files\Toshiba\Windows Utilities\SVPWUTIL.exe SVPwUTIL
      O4 - HKLM\..\Run: [TPNF] C:\Program Files\TOSHIBA\TouchPad\TPTray.exe
      O4 - HKLM\..\Run: [Zooming] ZoomingHook.exe
      O4 - HKLM\..\Run: [TPSMain] TPSMain.exe
      O4 - HKLM\..\Run: [SmoothView] C:\Program Files\TOSHIBA\Utilitaire de zoom TOSHIBA\SmoothView.exe
      O4 - HKLM\..\Run: [Tvs] C:\Program Files\TOSHIBA\Tvs\TvsTray.exe
      O4 - HKLM\..\Run: [NDSTray.exe] NDSTray.exe
      O4 - HKLM\..\Run: [DDWMon] C:\Program Files\TOSHIBA\TOSHIBA Direct Disc Writer\\ddwmon.exe
      O4 - HKLM\..\Run: [autoclk] autoclk.exe
      O4 - HKLM\..\Run: [adiras] adiras.exe
      O4 - HKLM\..\Run: [CFSServ.exe] CFSServ.exe -NoClient
      O4 - HKLM\..\Run: [ORAHSSSessionManager] C:\Program Files\Orange\SessionManager\SessionManager.exe
      O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Fichiers communs\LogiShrd\LComMgr\Communications_Helper.exe"
      O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam\Quickcam.exe" /hide
      O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
      O4 - HKLM\..\Run: [SystrayORAHSS] "C:\Program Files\Orange\Systray\SystrayApp.exe"
      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
      O4 - HKCU\..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
      O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
      O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
      O4 - HKCU\..\Run: [TomTomHOME.exe] "C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe"
      O4 - HKCU\..\Run: [winappCMP] rundll32.exe "C:\Documents and Settings\nathalie\Local Settings\Application Data\winappCMP\winappCMP.dll", DllInit
      O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
      O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
      O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
      O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
      O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
      O8 - Extra context menu item: &MSN Search - res://C:\Program Files\MSN Toolbar Suite\TB\02.05.0000.1105\fr-fr\msntb.dll/search.htm
      O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MsOffice\Office10\EXCEL.EXE/3000
      O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
      O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
      O9 - Extra button: Livre de reliures HP - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
      O9 - Extra button: Sélection intelligente HP - {700259D7-1666-479a-93B1-3250410481E8} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
      O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra button: Wanadoo - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - https://www.orange.fr/portail (file missing) (HKCU)
      O15 - Trusted Zone: https://www.orange.fr/portail
      O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
      O23 - Service: Service de configuration Atheros (ACS) - Unknown owner - C:\WINDOWS\system32\acs.exe
      O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
      O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
      O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom SA - C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
      O23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe
      O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Fichiers communs\LogiShrd\LVMVFM\LVPrcSrv.exe
      O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Fichiers communs\LogiShrd\SrvLnch\SrvLnch.exe
      O23 - Service: TOSHIBA Optical Disc Drive Service (TODDSrv) - TOSHIBA Corporation - C:\WINDOWS\system32\TODDSrv.exe
  2. Contributeur sécurité
    tres infecté

    Attention, avant de commencer, lit attentivement la procédure, et imprime la

    Télécharge ComboFix de sUBs sur ton Bureau :

    http://download.bleepingcomputer.com/sUBs/ComboFix.exe

    /!\ Déconnecte-toi du net et DESACTIVES TOUTES LES DEFENSES, antivirus et antispyware y compris /!\

    ---> Double-clique sur ComboFix.exe
    Un "pop-up" va apparaître qui dit que ComboFix est utilisé à vos risques et avec aucune garantie... Clique sur oui pour accepter

    SURTOUT INSTALLES LA CONSOLE DE RECUPERATION
    (si il te le propose remets provisoirement internet)

    ---> Mets-le en langue française F
    Tape sur la touche 1 (Yes) pour démarrer le scan.

    Ne touche à rien(souris, clavier) tant que le scan n'est pas terminé, car tu risques de planter ton PC

    En fin de scan, il est possible que ComboFix ait besoin de redémarrer le PC pour finaliser la désinfection, laisse-le faire.

    Une fois le scan achevé, un rapport va s'afficher : Poste son contenu

    /!\ Réactive la protection en temps réel de ton antivirus et de ton antispyware avant de te reconnecter à Internet. /!\

    Note : Le rapport se trouve également là : C:\ComboFix.txt

    1. et voilà le rapport de ComboFix :

      ComboFix 10-02-01.05 - nathalie 02/02/2010 20:07:33.1.1 - x86
      Microsoft Windows XP Édition familiale 5.1.2600.3.1252.33.1036.18.446.184 [GMT 1:00]
      Lancé depuis: c:\documents and settings\nathalie\Mes documents\Téléchargements\ComboFix.exe
      FW: Norton Internet Worm Protection *disabled* {990F9400-4CEE-43EA-A83A-D013ADD8EA6E}
      .

      (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
      .

      c:\documents and settings\All Users\Application Data\Macromedia\SwUpdate
      c:\documents and settings\All Users\Application Data\Macromedia\SwUpdate\Flags.dtd
      c:\documents and settings\All Users\Application Data\Macromedia\SwUpdate\UA.dtd
      c:\documents and settings\All Users\Application Data\Macromedia\SwUpdate\UAcpt.dtd
      c:\documents and settings\nathalie\Application Data\MSA\download.list
      c:\documents and settings\nathalie\Application Data\MSA\mscj.exe
      c:\documents and settings\nathalie\Local Settings\Application Data\winappCMP\winappCMP.dll
      C:\Thumbs.db
      c:\windows\system32\11478.exe
      c:\windows\system32\15724.exe
      c:\windows\system32\16827.exe
      c:\windows\system32\18467.exe
      c:\windows\system32\19169.exe
      c:\windows\system32\23281.exe
      c:\windows\system32\24464.exe
      c:\windows\system32\26500.exe
      c:\windows\system32\26962.exe
      c:\windows\system32\28145.exe
      c:\windows\system32\29358.exe
      c:\windows\system32\5705.exe
      c:\windows\system32\6334.exe
      c:\windows\system32\9961.exe
      c:\windows\system32\AutoRun.inf

      Une copie infectée de c:\windows\system32\DRIVERS\atapi.sys a été trouvée et désinfectée
      Copie restaurée à partir de - Kitty ate it :p
      .
      ((((((((((((((((((((((((((((( Fichiers créés du 2010-01-02 au 2010-02-02 ))))))))))))))))))))))))))))))))))))
      .

      2010-02-02 16:04 . 2010-02-02 18:08 -------- d-----w- C:\rsit
      2010-01-29 13:06 . 2010-01-29 13:06 -------- d-----w- c:\windows\system32\wbem\Repository
      2010-01-28 19:17 . 2010-01-28 19:17 -------- d-----w- c:\documents and settings\NetworkService\IETldCache
      2010-01-28 19:07 . 2010-01-28 19:07 -------- d-----w- c:\windows\system32\NtmsData
      2010-01-27 05:13 . 2010-01-27 05:13 -------- d-----w- c:\documents and settings\nathalie\ErrorLogs
      2010-01-27 02:17 . 2010-01-29 13:04 3472 ----a-w- c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
      2010-01-27 02:01 . 2010-01-27 02:01 -------- d-----w- c:\windows\ie8updates
      2010-01-27 02:01 . 2009-12-21 19:06 246272 -c----w- c:\windows\system32\dllcache\ieproxy.dll
      2010-01-27 02:01 . 2009-12-21 19:07 12800 -c----w- c:\windows\system32\dllcache\xpshims.dll
      2010-01-26 16:34 . 2010-01-29 13:05 -------- d-----w- c:\program files\KB824146Scan
      2010-01-26 13:07 . 2010-01-26 13:07 -------- d-----w- c:\documents and settings\nathalie\Local Settings\Application Data\WMTools Downloaded Files
      2010-01-26 10:18 . 2010-01-26 10:18 -------- d--h--w- c:\windows\msdownld.tmp
      2010-01-26 10:15 . 2010-01-26 10:17 -------- dc-h--w- c:\windows\ie8
      2010-01-26 10:01 . 2010-01-26 10:01 -------- d-sh--w- c:\documents and settings\nathalie\PrivacIE
      2010-01-26 10:00 . 2010-01-26 10:00 -------- d-sh--w- c:\documents and settings\nathalie\IETldCache
      2010-01-26 09:26 . 2010-01-26 09:26 -------- d-sh--w- c:\windows\system32\config\systemprofile\IETldCache
      2010-01-26 09:10 . 2010-01-26 09:10 -------- d-----w- C:\ab2846195912247de0614a2a
      2010-01-26 08:13 . 2010-01-26 08:21 -------- d-----w- c:\windows\SxsCaPendDel
      2010-01-26 07:16 . 2010-01-26 07:16 -------- d-----w- c:\documents and settings\nathalie\Local Settings\Application Data\Threat Expert
      2010-01-26 07:16 . 2010-01-26 07:16 -------- d-----w- c:\documents and settings\All Users\Application Data\HPSSUPPLY
      2010-01-26 07:16 . 2010-01-26 07:16 -------- d-----w- c:\documents and settings\nathalie\Application Data\HPAppData
      2010-01-26 07:15 . 2010-01-26 07:15 -------- d-----w- c:\documents and settings\nathalie\Documents and Settings
      2010-01-26 07:15 . 2010-01-26 07:15 -------- d-----w- C:\Application Data
      2010-01-26 07:15 . 2010-01-26 07:15 -------- d-----w- c:\documents and settings\nathalie\Local Settings\Application Data\Apple
      2010-01-21 13:23 . 2010-01-21 13:29 167062 ----a-w- c:\windows\hpoins21.dat
      2010-01-21 13:23 . 2007-09-05 18:31 8138 ------w- c:\windows\hpomdl21.dat
      2010-01-21 12:38 . 2010-01-21 12:40 -------- d-----w- c:\documents and settings\nathalie\Application Data\System Tweaker
      2010-01-21 05:33 . 2010-01-29 13:05 -------- d-----w- c:\program files\Uniblue
      2010-01-21 04:29 . 2010-01-26 16:54 -------- d-----w- c:\documents and settings\nathalie\Application Data\Uniblue
      2010-01-21 03:01 . 2010-01-21 03:01 -------- d-----w- c:\program files\TrendMicro
      2010-01-14 22:41 . 2010-01-26 07:15 -------- d-----w- c:\documents and settings\nathalie\Application Data\Apple Computer
      2010-01-14 22:40 . 2009-05-18 13:17 26600 ----a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
      2010-01-14 22:40 . 2008-04-17 12:12 107368 ----a-w- c:\windows\system32\GEARAspi.dll
      2010-01-14 22:39 . 2010-01-14 22:40 -------- d-----w- c:\documents and settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
      2010-01-14 22:37 . 2010-01-26 07:14 -------- d-----w- c:\program files\QuickTime
      2010-01-14 22:37 . 2010-01-26 07:15 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple Computer
      2010-01-14 22:34 . 2010-01-14 22:59 -------- d-----w- c:\documents and settings\nathalie\Local Settings\Application Data\Apple Computer
      2010-01-06 21:56 . 2010-01-06 21:56 -------- d-----w- c:\documents and settings\nathalie\Application Data\Malwarebytes
      2010-01-06 21:56 . 2010-01-06 21:56 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
      2010-01-06 21:56 . 2010-02-02 18:35 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
      2010-01-06 18:59 . 2010-01-06 18:59 -------- d-----w- c:\program files\Trend Micro
      2010-01-06 18:38 . 2010-01-06 18:46 -------- d-----w- c:\program files\Navilog1
      2010-01-06 18:24 . 2010-01-06 18:24 -------- dc-h--w- c:\documents and settings\All Users\Application Data\{7516B6E8-5C01-4895-B079-DFC32A4ADEE1}
      2010-01-06 18:23 . 2010-01-06 18:23 -------- d-----w- c:\documents and settings\nathalie\Application Data\Fighters
      2010-01-06 18:23 . 2010-01-06 18:23 -------- d-----w- c:\documents and settings\nathalie\Local Settings\Application Data\PackageAware
      2010-01-06 18:19 . 2010-01-23 05:46 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
      2010-01-06 13:13 . 2010-02-02 19:13 -------- d-----w- c:\documents and settings\nathalie\Local Settings\Application Data\winappCMP
      2010-01-06 13:11 . 2010-02-02 19:13 -------- d-----w- c:\documents and settings\nathalie\Application Data\MSA

      .
      (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
      .
      2010-02-01 13:42 . 2009-01-20 12:29 96512 ----a-w- c:\windows\system32\drivers\atapi.sys
      2010-01-31 17:19 . 2006-05-26 05:48 87992 ----a-w- c:\windows\system32\perfc00C.dat
      2010-01-31 17:19 . 2006-05-26 05:48 517132 ----a-w- c:\windows\system32\perfh00C.dat
      2010-01-26 07:12 . 2009-11-14 06:25 -------- d-----w- c:\program files\Microsoft Silverlight
      2010-01-21 14:22 . 2008-03-26 18:06 -------- d-----w- c:\program files\Windows Media Connect 2
      2010-01-21 13:28 . 2008-05-22 19:02 -------- d-----w- c:\program files\HP
      2010-01-09 01:11 . 2008-08-20 19:23 -------- d-----w- c:\program files\WordBiz
      2010-01-06 19:50 . 2006-10-13 16:55 131 -c--a-w- c:\documents and settings\nathalie\Local Settings\Application Data\fusioncache.dat
      2009-12-21 19:07 . 2006-05-26 05:48 916480 ----a-w- c:\windows\system32\wininet.dll
      2009-12-08 18:00 . 2006-10-13 16:57 33248 ----a-w- c:\documents and settings\nathalie\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
      2009-11-21 15:58 . 2009-01-20 12:30 471552 ----a-w- c:\windows\AppPatch\aclayers.dll
      .

      ((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
      .
      .
      *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
      REGEDIT4

      [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
      "TOSCDSPD"="c:\program files\TOSHIBA\TOSCDSPD\toscdspd.exe" [2005-04-11 65536]
      "msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856]

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
      "CFSServ.exe"="CFSServ.exe -NoClient" [X]
      "ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2006-03-17 344064]
      "RTHDCPL"="RTHDCPL.EXE" [2006-04-18 16143872]
      "Apoint"="c:\program files\Apoint2K\Apoint.exe" [2004-03-23 196608]
      "LtMoh"="c:\program files\ltmoh\Ltmoh.exe" [2005-12-16 188416]
      "AGRSMMSG"="AGRSMMSG.exe" [2006-03-18 89541]
      "PadTouch"="c:\program files\TOSHIBA\Touch and Launch\PadExe.exe" [2005-12-22 1077329]
      "CeEKEY"="c:\program files\TOSHIBA\E-KEY\CeEKey.exe" [2006-03-16 634880]
      "HWSetup"="c:\program files\TOSHIBA\TOSHIBA Applet\HWSetup.exe" [2004-05-01 28672]
      "SVPWUTIL"="c:\program files\Toshiba\Windows Utilities\SVPWUTIL.exe" [2004-05-01 65536]
      "TPNF"="c:\program files\TOSHIBA\TouchPad\TPTray.exe" [2006-04-04 53248]
      "Zooming"="ZoomingHook.exe" [2005-06-06 24576]
      "TPSMain"="TPSMain.exe" [2005-08-12 266240]
      "SmoothView"="c:\program files\TOSHIBA\Utilitaire de zoom TOSHIBA\SmoothView.exe" [2005-05-17 118784]
      "Tvs"="c:\program files\TOSHIBA\Tvs\TvsTray.exe" [2006-02-02 73728]
      "NDSTray.exe"="NDSTray.exe" [BU]
      "DDWMon"="c:\program files\TOSHIBA\TOSHIBA Direct Disc Writer\\ddwmon.exe" [2006-04-28 262144]
      "ORAHSSSessionManager"="c:\program files\Orange\SessionManager\SessionManager.exe" [2007-09-25 102400]
      "LogitechCommunicationsManager"="c:\program files\Fichiers communs\LogiShrd\LComMgr\Communications_Helper.exe" [2007-07-25 563984]
      "LogitechQuickCamRibbon"="c:\program files\Logitech\QuickCam\Quickcam.exe" [2007-07-25 2027792]
      "HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-03-11 49152]
      "SystrayORAHSS"="c:\program files\Orange\Systray\SystrayApp.exe" [2007-09-25 94208]
      "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-11-10 417792]

      [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
      "CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

      c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
      HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2007-3-11 210520]

      [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
      "DisableMonitoring"=dword:00000001

      [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
      "%windir%\\system32\\sessmgr.exe"=
      "c:\\Program Files\\TOSHIBA\\ConfigFree\\CFXFER.exe"=
      "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
      "c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
      "c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
      "c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
      "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
      "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
      "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
      "c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
      "c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
      "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
      "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
      "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
      "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
      "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
      "c:\\Program Files\\Orange\\Connectivity\\ConnectivityManager.exe"=

      R2 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr_tdi.sys [14/11/2009 07:24 54752]
      R2 tdudf;TOSHIBA UDF File System Driver;c:\windows\system32\drivers\tdudf.sys [18/04/2006 14:12 98816]
      S3 fsssvc;Service Windows Live Contrôle parental;c:\program files\Windows Live\Family Safety\fsssvc.exe [05/08/2009 22:48 704864]

      [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
      HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
      hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
      HPService REG_MULTI_SZ HPSLPSVC
      .
      Contenu du dossier 'Tâches planifiées'

      2010-01-21 c:\windows\Tasks\Windows Update.job
      - c:\program files\Windows Media Player\wmplayer.exe [2006-05-26 08:59]
      .
      .
      ------- Examen supplémentaire -------
      .
      uSearchMigratedDefaultURL = hxxp://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}
      uSearchURL,(Default) = hxxp://g.msn.fr/0SEFRFR/SAOS01?FORM=TOOLBR
      IE: &MSN Search - c:\program files\MSN Toolbar Suite\TB\02.05.0000.1105\fr-fr\msntb.dll/search.htm
      IE: E&xporter vers Microsoft Excel - c:\progra~1\MsOffice\Office10\EXCEL.EXE/3000
      Trusted Zone: orange.fr\www
      Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\program files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
      FF - ProfilePath - c:\documents and settings\nathalie\Application Data\Mozilla\Firefox\Profiles\2edf4pi1.default\
      FF - prefs.js: browser.search.defaulturl - hxxp://www.bing.com/search?FORM=IEFM1&q=
      FF - prefs.js: browser.startup.homepage - hxxp://orange.fr/
      FF - prefs.js: keyword.URL - hxxp://www.bing.com/search?FORM=IEFM1&q=
      FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
      FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
      .
      - - - - ORPHELINS SUPPRIMES - - - -

      HKCU-Run-TomTomHOME.exe - c:\program files\TomTom HOME 2\TomTomHOMERunner.exe
      HKCU-Run-winappCMP - c:\documents and settings\nathalie\Local Settings\Application Data\winappCMP\winappCMP.dll
      HKLM-Run-autoclk - autoclk.exe
      HKLM-Run-adiras - adiras.exe

      **************************************************************************

      catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
      Rootkit scan 2010-02-02 20:31
      Windows 5.1.2600 Service Pack 3 NTFS

      Recherche de processus cachés ...

      Recherche d'éléments en démarrage automatique cachés ...

      Recherche de fichiers cachés ...

      Scan terminé avec succès
      Fichiers cachés: 0

      **************************************************************************
      .
      --------------------- DLLs chargées dans les processus actifs ---------------------

      - - - - - - - > 'winlogon.exe'(588)
      c:\windows\system32\Ati2evxx.dll

      - - - - - - - > 'explorer.exe'(7124)
      c:\program files\Fichiers communs\Logishrd\LVMVFM\LVPrcInj.dll
      c:\windows\system32\webcheck.dll
      c:\progra~1\FICHIE~1\MICROS~1\WEBCOM~1\10\OWC10.DLL
      c:\progra~1\FICHIE~1\MICROS~1\WEBCOM~1\10\1036\owci10.dll
      c:\windows\system32\msls31.dll
      c:\windows\system32\eappprxy.dll
      c:\windows\system32\WPDShServiceObj.dll
      c:\windows\system32\TPwrCfg.DLL
      c:\windows\system32\TPwrReg.dll
      c:\windows\system32\TPSTrace.DLL
      c:\windows\system32\PortableDeviceTypes.dll
      c:\windows\system32\PortableDeviceApi.dll
      .
      ------------------------ Autres processus actifs ------------------------
      .
      c:\windows\system32\Ati2evxx.exe
      c:\program files\Fichiers communs\LogiShrd\LVMVFM\LVPrcSrv.exe
      c:\windows\system32\acs.exe
      c:\program files\TOSHIBA\ConfigFree\CFSvcs.exe
      c:\windows\system32\dllhost.exe
      c:\progra~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
      c:\program files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe
      c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
      c:\windows\system32\TODDSrv.exe
      c:\windows\system32\Ati2evxx.exe
      c:\program files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe
      c:\windows\RTHDCPL.EXE
      c:\windows\AGRSMMSG.exe
      c:\windows\system32\ZoomingHook.exe
      c:\windows\system32\TPSMain.exe
      c:\program files\TOSHIBA\ConfigFree\NDSTray.exe
      c:\program files\TOSHIBA\TOSHIBA Direct Disc Writer\ddwmon.exe
      c:\windows\system32\TPSBattM.exe
      c:\program files\Apoint2K\Apntex.exe
      c:\program files\Fichiers communs\Logishrd\LQCVFX\COCIManager.exe
      c:\program files\HP\Digital Imaging\bin\hpqSTE08.exe
      .
      **************************************************************************
      .
      Heure de fin: 2010-02-02 20:36:31 - La machine a redémarré
      ComboFix-quarantined-files.txt 2010-02-02 19:36

      Avant-CF: 47 301 517 312 octets libres
      Après-CF: 48 068 624 384 octets libres

      WindowsXP-KB310994-SP2-Home-BootDisk-FRA.exe
      [boot loader]
      timeout=2
      default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
      [operating systems]
      c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
      multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP dition familiale" /noexecute=optin /fastdetect

      - - End Of File - - B56AC4C73250946A02466DD98F1EE8A5
  3. Contributeur sécurité
    ok

    desinstalles et supprimes Malwarebytes' Anti-Malware que tu possèdes déjà
    et retélecharges le

    Téléchargez MalwareByte's Anti-Malware

    http://www.malwarebytes.org/mbam/program/mbam-setup.exe

    . Enregistres le sur le bureau
    . Double cliques sur le fichier téléchargé pour lancer le processus d'installation.
    . Dans l'onglet "mise à jour", cliques sur le bouton Recherche de mise à jour
    . Si le pare-feu demande l'autorisation de se connecter pour malwarebytes, accepte
    . Une fois la mise à jour terminé
    . Rend-toi dans l'onglet, Recherche
    . Sélectionnes Exécuter un examen complet (examen assez long)
    . Cliques sur Rechercher
    . Le scan démarre.
    . A la fin de l'analyse, un message s'affiche : L'examen s'est terminé normalement. Cliquez sur 'Afficher les résultats' pour afficher tous les objets trouvés.
    . Cliques sur Ok pour poursuivre.
    . Si des malwares ont été détectés, clique sur Afficher les résultats
    . Sélectionnes tout (ou laisses cochés) et cliques sur Supprimer la sélection Malwarebytes va détruire les fichiers et clés de registre et en mettre une copie dans la quarantaine.
    . Malwarebytes va ouvrir le bloc-notes et y copier le rapport d'analyse.
    . Rends toi dans l'onglet rapport/log
    . Tu cliques dessus pour l'afficher, une fois affiché
    . Tu cliques sur edition en haut du boc notes, et puis sur sélectionner tous
    . Tu recliques sur edition et puis sur copier et tu reviens sur le forum et dans ta réponse
    . tu cliques droit dans le cadre de la reponse et coller

    Si tu as besoin d'aide regarde ces tutoriels :
    Aide: https://www.malekal.com/tutoriel-malwarebyte-anti-malware/
    http://www.infos-du-net.com/forum/278396-11-tuto-malwarebytes-anti-malware-mbam

    1. Malwarebytes' Anti-Malware 1.44
      Version de la base de données: 3682
      Windows 5.1.2600 Service Pack 3
      Internet Explorer 8.0.6001.18702

      03/02/2010 13:45:15
      mbam-log-2010-02-03 (13-45-15).txt

      Type de recherche: Examen complet (C:\|D:\|)
      Eléments examinés: 193557
      Temps écoulé: 49 minute(s), 34 second(s)

      Processus mémoire infecté(s): 0
      Module(s) mémoire infecté(s): 0
      Clé(s) du Registre infectée(s): 0
      Valeur(s) du Registre infectée(s): 0
      Elément(s) de données du Registre infecté(s): 0
      Dossier(s) infecté(s): 0
      Fichier(s) infecté(s): 3

      Processus mémoire infecté(s):
      (Aucun élément nuisible détecté)

      Module(s) mémoire infecté(s):
      (Aucun élément nuisible détecté)

      Clé(s) du Registre infectée(s):
      (Aucun élément nuisible détecté)

      Valeur(s) du Registre infectée(s):
      (Aucun élément nuisible détecté)

      Elément(s) de données du Registre infecté(s):
      (Aucun élément nuisible détecté)

      Dossier(s) infecté(s):
      (Aucun élément nuisible détecté)

      Fichier(s) infecté(s):
      C:\Qoobox\Quarantine\C\Documents and Settings\nathalie\Application Data\MSA\mscj.exe.vir (Trojan.Vilsel) -> Quarantined and deleted successfully.
      C:\System Volume Information\_restore{DBC1A09E-2881-490F-BAF5-D5B982B90D07}\RP1\A0000058.exe (Trojan.Vilsel) -> Quarantined and deleted successfully.
      C:\Program Files\Internet Explorer\minftnet.exe (Adware.Agent) -> Quarantined and deleted successfully.
  4. Contributeur sécurité
    ok

    relances RSIT et postes le rapport log stp
    1. Logfile of random's system information tool 1.06 (written by random/random)
      Run by nathalie at 2010-02-03 15:31:57
      Microsoft Windows XP Édition familiale Service Pack 3
      System drive C: has 46 GB (80%) free of 57 GB
      Total RAM: 446 MB (24% free)

      Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 15:32:21, on 03/02/2010
      Platform: Windows XP SP3 (WinNT 5.01.2600)
      MSIE: Internet Explorer v8.00 (8.00.6001.18702)
      Boot mode: Normal

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\Ati2evxx.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\Program Files\Fichiers communs\LogiShrd\LVMVFM\LVPrcSrv.exe
      C:\WINDOWS\system32\acs.exe
      C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
      C:\WINDOWS\system32\dllhost.exe
      C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\Program Files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe
      C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\TODDSrv.exe
      C:\WINDOWS\system32\Ati2evxx.exe
      C:\WINDOWS\Explorer.EXE
      C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
      C:\WINDOWS\RTHDCPL.EXE
      C:\Program Files\Apoint2K\Apoint.exe
      C:\Program Files\ltmoh\Ltmoh.exe
      C:\WINDOWS\AGRSMMSG.exe
      C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe
      C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe
      C:\Program Files\TOSHIBA\TouchPad\TPTray.exe
      C:\WINDOWS\system32\ZoomingHook.exe
      C:\WINDOWS\system32\TPSMain.exe
      C:\Program Files\TOSHIBA\Utilitaire de zoom TOSHIBA\SmoothView.exe
      C:\Program Files\TOSHIBA\Tvs\TvsTray.exe
      C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe
      C:\Program Files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe
      C:\Program Files\TOSHIBA\TOSHIBA Direct Disc Writer\ddwmon.exe
      C:\Program Files\TOSHIBA\ConfigFree\CFSServ.exe
      C:\Program Files\Fichiers communs\LogiShrd\LComMgr\Communications_Helper.exe
      C:\Program Files\Logitech\QuickCam\Quickcam.exe
      C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
      C:\Program Files\Orange\Systray\SystrayApp.exe
      C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
      C:\Program Files\Windows Live\Messenger\msnmsgr.exe
      C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
      C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\AlertModule\0\AlertModule.exe
      C:\WINDOWS\system32\TPSBattM.exe
      C:\Program Files\TOSHIBA\ConfigFree\CFXFER.exe
      C:\Program Files\Apoint2K\Apntex.exe
      C:\Program Files\Fichiers communs\Logishrd\LQCVFX\COCIManager.exe
      C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
      C:\Program Files\Orange\Launcher\Launcher.exe
      C:\Program Files\Orange\connectivity\connectivitymanager.exe
      C:\Program Files\Orange\connectivity\CoreCom\CoreCom.exe
      C:\Program Files\Orange\connectivity\CoreCom\OraConfigRecover.exe
      C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTCOMModule\0\FTCOMModule.exe
      C:\WINDOWS\System32\svchost.exe
      C:\Program Files\Mozilla Firefox\firefox.exe
      C:\Documents and Settings\nathalie\Mes documents\Téléchargements\RSIT(2).exe
      C:\Program Files\trend micro\nathalie.exe

      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
      R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = https://www.bing.com/?FORM=TOOLBR&cc=fr&toHttps=1&redig=4527FFF1C12746FC9EDB535C75E80ECC
      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,First Home Page = https://support.microsoft.com/en-US/topic/internet-explorer-downloads-d49e1f0d-571c-9a7b-d97e-be248806ca70
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
      R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\Program Files\Orange\SearchURLHook\SearchPageURL.dll
      O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Smart Web Printing\hpswp_printenhancer.dll
      O2 - BHO: HP Print Clips - {053F9267-DC04-4294-A72C-58F732D338C0} - C:\Program Files\HP\Smart Web Printing\hpswp_framework.dll
      O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
      O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
      O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
      O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
      O2 - BHO: Barre d'outils MSN Search Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar Suite\TB\02.05.0000.1105\fr-fr\msntb.dll
      O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
      O3 - Toolbar: Barre d'outils MSN Search - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar Suite\TB\02.05.0000.1105\fr-fr\msntb.dll
      O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
      O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
      O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
      O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
      O4 - HKLM\..\Run: [LtMoh] C:\Program Files\ltmoh\Ltmoh.exe
      O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
      O4 - HKLM\..\Run: [PadTouch] C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe
      O4 - HKLM\..\Run: [CeEKEY] C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe
      O4 - HKLM\..\Run: [HWSetup] C:\Program Files\TOSHIBA\TOSHIBA Applet\HWSetup.exe hwSetUP
      O4 - HKLM\..\Run: [SVPWUTIL] C:\Program Files\Toshiba\Windows Utilities\SVPWUTIL.exe SVPwUTIL
      O4 - HKLM\..\Run: [TPNF] C:\Program Files\TOSHIBA\TouchPad\TPTray.exe
      O4 - HKLM\..\Run: [Zooming] ZoomingHook.exe
      O4 - HKLM\..\Run: [TPSMain] TPSMain.exe
      O4 - HKLM\..\Run: [SmoothView] C:\Program Files\TOSHIBA\Utilitaire de zoom TOSHIBA\SmoothView.exe
      O4 - HKLM\..\Run: [Tvs] C:\Program Files\TOSHIBA\Tvs\TvsTray.exe
      O4 - HKLM\..\Run: [NDSTray.exe] NDSTray.exe
      O4 - HKLM\..\Run: [DDWMon] C:\Program Files\TOSHIBA\TOSHIBA Direct Disc Writer\\ddwmon.exe
      O4 - HKLM\..\Run: [CFSServ.exe] CFSServ.exe -NoClient
      O4 - HKLM\..\Run: [ORAHSSSessionManager] C:\Program Files\Orange\SessionManager\SessionManager.exe
      O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Fichiers communs\LogiShrd\LComMgr\Communications_Helper.exe"
      O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam\Quickcam.exe" /hide
      O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
      O4 - HKLM\..\Run: [SystrayORAHSS] "C:\Program Files\Orange\Systray\SystrayApp.exe"
      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
      O4 - HKCU\..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
      O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
      O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
      O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
      O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
      O8 - Extra context menu item: &MSN Search - res://C:\Program Files\MSN Toolbar Suite\TB\02.05.0000.1105\fr-fr\msntb.dll/search.htm
      O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MsOffice\Office10\EXCEL.EXE/3000
      O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
      O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
      O9 - Extra button: Livre de reliures HP - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
      O9 - Extra button: Sélection intelligente HP - {700259D7-1666-479a-93B1-3250410481E8} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
      O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra button: Wanadoo - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - https://www.orange.fr/portail (file missing) (HKCU)
      O15 - Trusted Zone: https://www.orange.fr/portail
      O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
      O23 - Service: Service de configuration Atheros (ACS) - Unknown owner - C:\WINDOWS\system32\acs.exe
      O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
      O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
      O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom SA - C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
      O23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe
      O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Fichiers communs\LogiShrd\LVMVFM\LVPrcSrv.exe
      O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Fichiers communs\LogiShrd\SrvLnch\SrvLnch.exe
      O23 - Service: TOSHIBA Optical Disc Drive Service (TODDSrv) - TOSHIBA Corporation - C:\WINDOWS\system32\TODDSrv.exe
  5. Contributeur sécurité
    ok

    Télécharge Haxfix (Marckie) et Enregistrer le sur le Bureau :

    http://download.bleepingcomputer.com/marckie/haxfix.exe

    Lancer l'utilitaire Appuyer sur une touche comme demandé Saisir le chiffre "1" et presse "entrée" pour créer et afficher un rapport.

    Poster le contenu de ce rapport sur le Forum
    1. Bonjour,

      Voici le rapport obtenu lorsque je réponds "N" a la question posée : if you want to search in the most import windows folders.
      Si je réponds "Y" if you want to search the whole C: drive., cela prend des heures et je ne retrouve pas de rapport.

      HAXFIX logfile - by Marckie

      version 5.093
      04/02/2010 11:18:11,18

      --- INFORMATION ---

      Manufacturer: TOSHIBA - Model: Satellite A110
      Operating System: Microsoft Windows XP Édition familiale -- 5.1.2600 -- Service Pack 3 --
      Processor: Intel(R) Celeron(R) M CPU 410 @ 1.46GHz
      Number of Processors: 1
      Work Station
      Bootmode: Normal boot
      Total RAM: 446 MB (free 163 MB - 36%)

      Computername: YOUR-35063AB16-
      Domain: MSHOME
      User: nathalie (Administrator account)

      Bootdevice: \Device\HarddiskVolume1
      Systemdrive: C:
      Windowsdirectory: C:\WINDOWS
      Systemdirectory: C:\WINDOWS\system32

      Internet Explorer Version: 8.0.6001.18702

      Firewall: Norton Internet Worm Protection 2006 [Not Enabled]

      --- Checking for Haxdoor ---

      checking for a3d files
      a3d files not found

      checking for matching notify keys
      matching notify keys found
      AtiE

      checking for matching services
      matching services found
      CmBatt

      checking for matching safeboot services
      no matching safeboot services found

      --- Checking for Goldun - Spybanker ---

      checking for SSODL keys
      no ssodl keys found

      checking for notify keys
      no notify keys found

      checking for services
      no services found

      checking for random used files and services
      -- these files are not necessarily malicious
      -- scanning most important windows folders
      no known random used services or files found

      checking for browser helper objects
      no known browser helper objects found

      checking for appinit files
      no files found

      checking for possible infected files
      please submit these file here: https://www.bleepingcomputer.com/submit-malware.php?channel=11
      no files found

      checking for Active Setup Installed Components
      no known Active Setup Installed Components found

      checking iexplore.exe
      iexplore.exe is not infected

      --- Checking for other Goldun, Spybanker and Haxdoor files ---
      no other Haxdoor or Goldun files found

      --- Catchme logfile - thank you Gmer ---

      catchme 0.3.1398.3 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
      Rootkit scan 2010-02-04 11:18:39
      Windows 5.1.2600 Service Pack 3 NTFS

      scanning hidden processes ...

      scanning hidden services & system hive ...

      scanning hidden registry entries ...

      scanning hidden files ...

      scan completed successfully
      hidden processes: 0
      hidden services: 0
      hidden files: 0

      --- Analysing Catchme logfile ---

      no matching regkeys found

      Finished!

      Merci encore pour ta précieuse aide .
      1. Contributeur sécurité
        Relancer "HaxFix" en cliquant sur l'icône (sur le bureau).
        Fermer toutes les autres fenêtres et applications.
        Presser la touche "2" puis "entrée" et suivre les indications.
        Le nettoyage sera fini Après redémarrage et un rapport sera généré à la racine de la partition principale (c:\haxfix.txt).

        ...................

        ensuite

        refais moi un nouveau RSIT pour voir si cela a fonctionné
        1. Voici le rapport généré par l'éxécution de l'option 2 :

          HAXFIX logfile - by Marckie

          version 5.093
          04/02/2010 12:45:10,37

          --- Auto Haxdoorfix ---

          Haxdoorfix Part 1

          matching notifykey found: AtiExt

          searching for matching services
          services not found, haxdoorkey AtiE not added to delete

          no infections found

          Haxdoorfix Part 2

          searching for notifykeys
          no notifykeys found

          searching for services
          no services found

          searching for safeboot services
          no safeboot services found

          --- Goldun- and SpyBankerfix ---

          searching for other goldun- spybanker- and haxdoorfiles:
          no other Haxdoor or Goldun files found

          checking iexplore.exe
          iexplore.exe is not infected

          searching for SSODLkeys
          no SSODLkeys found

          searching for browser helper objects
          no known browser helper objects found

          searching for appinit files

          checking for Active Setup Installed Components
          no known Active Setup Installed Components found

          searching for notifykeys
          no notify keys found

          searching for services
          no services found

          Finished
          1. voici le rapport de RSIT :
            Logfile of random's system information tool 1.06 (written by random/random)
            Run by nathalie at 2010-02-04 12:56:17
            Microsoft Windows XP Édition familiale Service Pack 3
            System drive C: has 46 GB (80%) free of 57 GB
            Total RAM: 446 MB (25% free)

            Logfile of Trend Micro HijackThis v2.0.2
            Scan saved at 12:56:26, on 04/02/2010
            Platform: Windows XP SP3 (WinNT 5.01.2600)
            MSIE: Internet Explorer v8.00 (8.00.6001.18702)
            Boot mode: Normal

            Running processes:
            C:\WINDOWS\System32\smss.exe
            C:\WINDOWS\system32\winlogon.exe
            C:\WINDOWS\system32\services.exe
            C:\WINDOWS\system32\lsass.exe
            C:\WINDOWS\system32\Ati2evxx.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\System32\svchost.exe
            C:\WINDOWS\system32\spoolsv.exe
            C:\Program Files\Fichiers communs\LogiShrd\LVMVFM\LVPrcSrv.exe
            C:\WINDOWS\system32\acs.exe
            C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
            C:\WINDOWS\system32\dllhost.exe
            C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\system32\svchost.exe
            C:\Program Files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe
            C:\WINDOWS\System32\svchost.exe
            C:\WINDOWS\System32\svchost.exe
            C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\system32\TODDSrv.exe
            C:\WINDOWS\system32\Ati2evxx.exe
            C:\WINDOWS\Explorer.EXE
            C:\Program Files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe
            C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
            C:\WINDOWS\RTHDCPL.EXE
            C:\Program Files\Apoint2K\Apoint.exe
            C:\Program Files\ltmoh\Ltmoh.exe
            C:\WINDOWS\AGRSMMSG.exe
            C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe
            C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe
            C:\Program Files\TOSHIBA\TouchPad\TPTray.exe
            C:\WINDOWS\system32\ZoomingHook.exe
            C:\WINDOWS\system32\TPSMain.exe
            C:\Program Files\TOSHIBA\Utilitaire de zoom TOSHIBA\SmoothView.exe
            C:\Program Files\TOSHIBA\Tvs\TvsTray.exe
            C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe
            C:\Program Files\TOSHIBA\TOSHIBA Direct Disc Writer\ddwmon.exe
            C:\Program Files\TOSHIBA\ConfigFree\CFSServ.exe
            C:\Program Files\Fichiers communs\LogiShrd\LComMgr\Communications_Helper.exe
            C:\Program Files\Logitech\QuickCam\Quickcam.exe
            C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
            C:\Program Files\Orange\Systray\SystrayApp.exe
            C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
            C:\Program Files\Windows Live\Messenger\msnmsgr.exe
            C:\WINDOWS\system32\ctfmon.exe
            C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
            C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\AlertModule\0\AlertModule.exe
            C:\Program Files\TOSHIBA\ConfigFree\CFXFER.exe
            C:\WINDOWS\system32\TPSBattM.exe
            C:\Program Files\Apoint2K\Apntex.exe
            C:\Program Files\Fichiers communs\Logishrd\LQCVFX\COCIManager.exe
            C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
            C:\Program Files\Orange\Launcher\Launcher.exe
            C:\Program Files\Orange\connectivity\connectivitymanager.exe
            C:\Program Files\Orange\Deskboard\deskboard.exe
            C:\Program Files\Orange\connectivity\CoreCom\CoreCom.exe
            C:\Program Files\Orange\connectivity\CoreCom\OraConfigRecover.exe
            C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTCOMModule\0\FTCOMModule.exe
            C:\Documents and Settings\nathalie\Mes documents\Téléchargements\RSIT.exe
            C:\Program Files\trend micro\nathalie.exe

            R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
            R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
            R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.msn.fr/0SEFRFR/SAOS01?FORM=TOOLBR
            R1 - HKCU\Software\Microsoft\Internet Explorer\Main,First Home Page = http://www.windows.fr/ie8/bienvenue
            R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
            R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\Program Files\Orange\SearchURLHook\SearchPageURL.dll
            O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Smart Web Printing\hpswp_printenhancer.dll
            O2 - BHO: HP Print Clips - {053F9267-DC04-4294-A72C-58F732D338C0} - C:\Program Files\HP\Smart Web Printing\hpswp_framework.dll
            O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
            O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
            O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
            O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
            O2 - BHO: Barre d'outils MSN Search Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar Suite\TB\02.05.0000.1105\fr-fr\msntb.dll
            O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
            O3 - Toolbar: Barre d'outils MSN Search - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar Suite\TB\02.05.0000.1105\fr-fr\msntb.dll
            O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
            O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
            O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
            O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
            O4 - HKLM\..\Run: [LtMoh] C:\Program Files\ltmoh\Ltmoh.exe
            O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
            O4 - HKLM\..\Run: [PadTouch] C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe
            O4 - HKLM\..\Run: [CeEKEY] C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe
            O4 - HKLM\..\Run: [HWSetup] C:\Program Files\TOSHIBA\TOSHIBA Applet\HWSetup.exe hwSetUP
            O4 - HKLM\..\Run: [SVPWUTIL] C:\Program Files\Toshiba\Windows Utilities\SVPWUTIL.exe SVPwUTIL
            O4 - HKLM\..\Run: [TPNF] C:\Program Files\TOSHIBA\TouchPad\TPTray.exe
            O4 - HKLM\..\Run: [Zooming] ZoomingHook.exe
            O4 - HKLM\..\Run: [TPSMain] TPSMain.exe
            O4 - HKLM\..\Run: [SmoothView] C:\Program Files\TOSHIBA\Utilitaire de zoom TOSHIBA\SmoothView.exe
            O4 - HKLM\..\Run: [Tvs] C:\Program Files\TOSHIBA\Tvs\TvsTray.exe
            O4 - HKLM\..\Run: [NDSTray.exe] NDSTray.exe
            O4 - HKLM\..\Run: [DDWMon] C:\Program Files\TOSHIBA\TOSHIBA Direct Disc Writer\\ddwmon.exe
            O4 - HKLM\..\Run: [CFSServ.exe] CFSServ.exe -NoClient
            O4 - HKLM\..\Run: [ORAHSSSessionManager] C:\Program Files\Orange\SessionManager\SessionManager.exe
            O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Fichiers communs\LogiShrd\LComMgr\Communications_Helper.exe"
            O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam\Quickcam.exe" /hide
            O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
            O4 - HKLM\..\Run: [SystrayORAHSS] "C:\Program Files\Orange\Systray\SystrayApp.exe"
            O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
            O4 - HKCU\..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
            O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
            O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
            O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
            O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
            O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
            O8 - Extra context menu item: &MSN Search - res://C:\Program Files\MSN Toolbar Suite\TB\02.05.0000.1105\fr-fr\msntb.dll/search.htm
            O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MsOffice\Office10\EXCEL.EXE/3000
            O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
            O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
            O9 - Extra button: Livre de reliures HP - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
            O9 - Extra button: Sélection intelligente HP - {700259D7-1666-479a-93B1-3250410481E8} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
            O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
            O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
            O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
            O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
            O9 - Extra button: Wanadoo - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - http://www.wanadoo.fr (file missing) (HKCU)
            O15 - Trusted Zone: https://www.orange.fr/portail
            O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
            O23 - Service: Service de configuration Atheros (ACS) - Unknown owner - C:\WINDOWS\system32\acs.exe
            O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
            O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
            O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom SA - C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
            O23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe
            O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Fichiers communs\LogiShrd\LVMVFM\LVPrcSrv.exe
            O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Fichiers communs\LogiShrd\SrvLnch\SrvLnch.exe
            O23 - Service: TOSHIBA Optical Disc Drive Service (TODDSrv) - TOSHIBA Corporation - C:\WINDOWS\system32\TODDSrv.exe
            1. Contributeur sécurité
              bon il l'a vu mais pas supprimé

              tant pis, on va faire autrement

              1)
              Téléchargez USBFIX de El Desaparecido, C_xx

              http://pagesperso-orange.fr/NosTools/Chiquitine29/UsbFix.exe
              ou
              https://www.ionos.fr/?affiliate_id=77097

              /!\ Utilisateur de vista et windows 7 :
              ne pas oublier de désactiver Le contrôle des comptes utilisateurs
              https://www.commentcamarche.net/faq/8343-vista-desactiver-l-uac

              /!\ Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) susceptible d'avoir été infectées sans les ouvrir

              • Double clic sur le raccourci UsbFix présent sur le bureau .

              • Choisir l'option2 suppression
              (d’autres options disponibles, voir le tutoriel).
              • Laissez travailler l'outil.
              Le menu démarrer et les icônes vont disparaître.. c'est normal.

              Si un message te demande de redémarrer l'ordinateur fais le ...

              ● Au redémarrage, le fix se relance... laisses l'opération s'effectuer.

              ● Le bloc note s'ouvre avec un rapport, envoies le dans la prochaine réponse

              • Note : Le rapport UsbFix.txt est sauvegardé a la racine du disque. ( C:\UsbFix.txt )

              ( CTRL+A Pour tout sélectionner , CTRL+C pour copier et CTRL+V pour coller )

              • Note : "Process.exe", une composante de l'outil, est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool.
              Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.
              Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall...) d'où l'alerte émise par ces antivirus.

              • Tuto : http://pagesperso-orange.fr/NosTools/usbfix.html

              UsbFix peut te demander d'uploader un dossier compressé à cette adresse : https://www.ionos.fr/?affiliate_id=77097

              Il est enregistré sur ton bureau.

              Merci de l'envoyer à l'adresse indiquée afin d'aider l'auteur de UsbFix dans ses recherches.

              ......................

              2)
              Desactive ton antivirus le temps de la manip ainsi que ton parefeu si présent(car il est detecté a tort comme infection)

              ▶ Télécharge et installe List&Kill'em et enregistre le sur ton bureau
              http://sd-1.archive-host.com/membres/up/829108531491024/List_Killem_Install.exe

              double clique ( clic droit "executer en tant qu'administrateur" pour Vista/7 ) sur le raccourci sur ton bureau pour lancer l'installation

              coche la case "creer une icone sur le bureau"

              une fois terminée , clic sur "terminer" et le programme se lancer seul

              choisis la langue puis choisis l'option 1 = Mode Recherche

              ▶ laisse travailler l'outil

              à l'apparition de la fenetre blanche , c'est un peu long , c'est normal , le programme n'est pas bloqué.

              un rapport du nom de catchme apparait sur ton bureau , ignore-le,ne le poste pas , mais ne le supprime pas pour l instant, le scan n'est pas fini.

              ▶ Poste le contenu du rapport qui s'ouvre aux 100 % du scan à l'ecran "COMPLETED"

              tu peux supprimer le rapport catchme.log de ton bureau maintenant.

              1. ############################## | UsbFix V6.088 |

                User : nathalie (Administrateurs) # YOUR-35063AB16-
                Update on 04/02/2010 by El Desaparecido , C_XX & Chimay8
                Start at: 14:14:18 | 04/02/2010
                Website : http://pagesperso-orange.fr/NosTools/index.html
                Contact : FindyKill.Contact@gmail.com

                Intel(R) Celeron(R) M CPU 410 @ 1.46GHz
                Microsoft Windows XP Édition familiale (5.1.2600 32-bit) # Service Pack 3
                Internet Explorer 8.0.6001.18702
                Windows Firewall Status : Enabled
                FW : Norton Internet Worm Protection[ (!) Disabled ]2006

                C:\ -> Disque fixe local # 55,89 Go (44,72 Go free) # NTFS
                D:\ -> Disque CD-ROM

                ############################## | Processus actifs |

                C:\WINDOWS\System32\smss.exe
                C:\WINDOWS\system32\csrss.exe
                C:\WINDOWS\system32\winlogon.exe
                C:\WINDOWS\system32\services.exe
                C:\WINDOWS\system32\lsass.exe
                C:\WINDOWS\system32\Ati2evxx.exe
                C:\WINDOWS\system32\svchost.exe
                C:\WINDOWS\system32\svchost.exe
                C:\WINDOWS\System32\svchost.exe
                C:\WINDOWS\system32\svchost.exe
                C:\WINDOWS\system32\svchost.exe
                C:\WINDOWS\system32\logonui.exe
                C:\WINDOWS\system32\spoolsv.exe
                C:\Program Files\Fichiers communs\LogiShrd\LVMVFM\LVPrcSrv.exe
                C:\WINDOWS\system32\acs.exe
                C:\WINDOWS\system32\svchost.exe
                C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
                C:\WINDOWS\system32\dllhost.exe
                C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
                C:\WINDOWS\system32\svchost.exe
                C:\WINDOWS\system32\svchost.exe
                C:\Program Files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe
                C:\WINDOWS\System32\svchost.exe
                C:\WINDOWS\System32\svchost.exe
                C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
                C:\WINDOWS\system32\svchost.exe
                C:\WINDOWS\system32\TODDSrv.exe
                C:\WINDOWS\system32\wuauclt.exe
                C:\WINDOWS\System32\alg.exe
                C:\WINDOWS\system32\Ati2evxx.exe
                C:\WINDOWS\system32\userinit.exe
                C:\WINDOWS\Explorer.EXE
                C:\WINDOWS\system32\wbem\wmiprvse.exe
                C:\WINDOWS\system32\rundll32.exe
                C:\Program Files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe
                C:\WINDOWS\system32\wbem\wmiprvse.exe

                ################## | Elements infectieux |

                Supprimé ! C:\Recycler\S-1-5-21-2891362985-3777591491-2704356655-1006

                ################## | Registre |

                ################## | Mountpoints2 |

                ################## | Listing des fichiers présent |

                [13/10/2006 17:53|--a------|216] C:\Boot.bak
                [02/02/2010 20:02|-rahs----|286] C:\boot.ini
                [05/08/2004 11:00|-rahs----|4952] C:\Bootfont.bin
                [03/08/2004 23:00|--a------|263488] C:\cmldr
                [02/02/2010 20:36|--a------|16737] C:\ComboFix.txt
                [26/05/2006 07:02|--a------|0] C:\CONFIG.SYS
                [28/01/2010 12:43|--a------|536825] C:\HaxFix.exe
                [04/02/2010 12:45|--a------|1018] C:\HaxFix.txt
                [?|?|?] C:\hiberfil.sys
                [26/05/2006 07:02|-rahs----|0] C:\IO.SYS
                [26/05/2006 07:02|-rahs----|0] C:\MSDOS.SYS
                [05/08/2004 11:00|-rahs----|47564] C:\NTDETECT.COM
                [06/08/2008 07:56|-rahs----|252240] C:\ntldr
                [?|?|?] C:\pagefile.sys
                [30/05/2006 23:10|--ah-----|229] C:\SWSTAMP.TXT
                [04/02/2010 14:16|--a------|3000] C:\UsbFix.txt
                [04/02/2010 13:38|--a------|1606] C:\UsbFix_Upload_Me_YOUR-35063AB16-.zip

                ################## | Vaccination |

                # C:\autorun.inf -> Dossier créé par UsbFix .

                ################## | Upload |

                Veuillez envoyer le fichier : C:\UsbFix_Upload_Me_YOUR-35063AB16-.zip : https://www.ionos.fr/?affiliate_id=77097
                Merci pour votre contribution .

                ################## | ! Fin du rapport # UsbFix V6.088 ! |
                1. Contributeur sécurité
                  vu

                  => killem
                  1. Voici le rapport de Kill'em :

                    List'em by g3n-h@ckm@n 1.2.2.0

                    User : nathalie (Administrateurs)
                    Update on 03/02/2010 by g3n-h@ckm@n ::::: 16.30
                    Start at: 15:17:24 | 04/02/2010
                    Contact : https://forums.commentcamarche.net/forum/virus-securite-7

                    Intel(R) Celeron(R) M CPU 410 @ 1.46GHz
                    Microsoft Windows XP Édition familiale (5.1.2600 32-bit) # Service Pack 3
                    Internet Explorer 8.0.6001.18702
                    Windows Firewall Status : Disabled
                    FW : Norton Internet Worm Protection[ (!) Disabled ]2006

                    C:\ -> Disque fixe local | 55,89 Go (44,71 Go free) | NTFS
                    D:\ -> Disque CD-ROM

                    ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Processes running

                    C:\WINDOWS\System32\smss.exe
                    C:\WINDOWS\system32\csrss.exe
                    C:\WINDOWS\system32\winlogon.exe
                    C:\WINDOWS\system32\services.exe
                    C:\WINDOWS\system32\lsass.exe
                    C:\WINDOWS\system32\Ati2evxx.exe
                    C:\WINDOWS\system32\svchost.exe
                    C:\WINDOWS\system32\svchost.exe
                    C:\WINDOWS\System32\svchost.exe
                    C:\WINDOWS\system32\svchost.exe
                    C:\WINDOWS\system32\svchost.exe
                    C:\WINDOWS\system32\spoolsv.exe
                    C:\Program Files\Fichiers communs\LogiShrd\LVMVFM\LVPrcSrv.exe
                    C:\WINDOWS\system32\acs.exe
                    C:\WINDOWS\system32\svchost.exe
                    C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
                    C:\WINDOWS\system32\dllhost.exe
                    C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
                    C:\WINDOWS\system32\svchost.exe
                    C:\WINDOWS\system32\svchost.exe
                    C:\Program Files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe
                    C:\WINDOWS\System32\svchost.exe
                    C:\WINDOWS\System32\svchost.exe
                    C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
                    C:\WINDOWS\system32\svchost.exe
                    C:\WINDOWS\system32\TODDSrv.exe
                    C:\WINDOWS\System32\alg.exe
                    C:\WINDOWS\system32\Ati2evxx.exe
                    C:\WINDOWS\Explorer.EXE
                    C:\WINDOWS\system32\wbem\wmiprvse.exe
                    C:\Program Files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe
                    C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
                    C:\WINDOWS\RTHDCPL.EXE
                    C:\Program Files\Apoint2K\Apoint.exe
                    C:\Program Files\ltmoh\Ltmoh.exe
                    C:\WINDOWS\AGRSMMSG.exe
                    C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe
                    C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe
                    C:\Program Files\TOSHIBA\TouchPad\TPTray.exe
                    C:\WINDOWS\system32\ZoomingHook.exe
                    C:\WINDOWS\system32\TPSMain.exe
                    C:\Program Files\TOSHIBA\Utilitaire de zoom TOSHIBA\SmoothView.exe
                    C:\Program Files\TOSHIBA\Tvs\TvsTray.exe
                    C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe
                    C:\Program Files\TOSHIBA\TOSHIBA Direct Disc Writer\ddwmon.exe
                    C:\Program Files\TOSHIBA\ConfigFree\CFSServ.exe
                    C:\Program Files\Fichiers communs\LogiShrd\LComMgr\Communications_Helper.exe
                    C:\Program Files\Logitech\QuickCam\Quickcam.exe
                    C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
                    C:\Program Files\Orange\Systray\SystrayApp.exe
                    C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
                    C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                    C:\WINDOWS\system32\ctfmon.exe
                    C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                    C:\Program Files\Apoint2K\Apntex.exe
                    C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\AlertModule\0\AlertModule.exe
                    C:\WINDOWS\system32\TPSBattM.exe
                    C:\Program Files\TOSHIBA\ConfigFree\CFXFER.exe
                    C:\Program Files\Fichiers communs\Logishrd\LQCVFX\COCIManager.exe
                    C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
                    C:\Program Files\Mozilla Firefox\firefox.exe
                    C:\Program Files\Orange\Launcher\Launcher.exe
                    C:\Program Files\Orange\connectivity\connectivitymanager.exe
                    C:\Program Files\Orange\Deskboard\deskboard.exe
                    C:\Program Files\Orange\connectivity\CoreCom\CoreCom.exe
                    C:\Program Files\Orange\connectivity\CoreCom\OraConfigRecover.exe
                    C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTCOMModule\0\FTCOMModule.exe
                    C:\WINDOWS\System32\svchost.exe
                    C:\Program Files\List_Kill'em\List_Kill'em.scr
                    C:\WINDOWS\system32\cmd.exe
                    C:\WINDOWS\system32\wbem\wmiprvse.exe
                    C:\Documents and Settings\nathalie\Local Settings\temp\2E.tmp\pv.exe

                    ======================
                    Keys "Run"
                    ======================
                    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                    TOSCDSPD REG_SZ C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
                    msnmsgr REG_SZ "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
                    ctfmon.exe REG_SZ C:\WINDOWS\system32\ctfmon.exe

                    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                    ATIPTA REG_SZ "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
                    RTHDCPL REG_SZ RTHDCPL.EXE
                    Apoint REG_SZ C:\Program Files\Apoint2K\Apoint.exe
                    LtMoh REG_SZ C:\Program Files\ltmoh\Ltmoh.exe
                    AGRSMMSG REG_SZ AGRSMMSG.exe
                    PadTouch REG_SZ C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe
                    CeEKEY REG_SZ C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe
                    HWSetup REG_SZ C:\Program Files\TOSHIBA\TOSHIBA Applet\HWSetup.exe hwSetUP
                    SVPWUTIL REG_SZ C:\Program Files\Toshiba\Windows Utilities\SVPWUTIL.exe SVPwUTIL
                    TPNF REG_SZ C:\Program Files\TOSHIBA\TouchPad\TPTray.exe
                    Zooming REG_SZ ZoomingHook.exe
                    TPSMain REG_SZ TPSMain.exe
                    SmoothView REG_SZ C:\Program Files\TOSHIBA\Utilitaire de zoom TOSHIBA\SmoothView.exe
                    Tvs REG_SZ C:\Program Files\TOSHIBA\Tvs\TvsTray.exe
                    NDSTray.exe REG_SZ NDSTray.exe
                    DDWMon REG_SZ C:\Program Files\TOSHIBA\TOSHIBA Direct Disc Writer\\ddwmon.exe
                    CFSServ.exe REG_SZ CFSServ.exe -NoClient
                    ORAHSSSessionManager REG_SZ C:\Program Files\Orange\SessionManager\SessionManager.exe
                    LogitechCommunicationsManager REG_SZ "C:\Program Files\Fichiers communs\LogiShrd\LComMgr\Communications_Helper.exe"
                    LogitechQuickCamRibbon REG_SZ "C:\Program Files\Logitech\QuickCam\Quickcam.exe" /hide
                    HP Software Update REG_SZ C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
                    SystrayORAHSS REG_SZ "C:\Program Files\Orange\Systray\SystrayApp.exe"
                    QuickTime Task REG_SZ "C:\Program Files\QuickTime\qttask.exe" -atboottime

                    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices]

                    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]

                    =====================
                    Other Keys
                    =====================
                    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
                    dontdisplaylastusername REG_DWORD 0 (0x0)
                    legalnoticecaption REG_SZ
                    legalnoticetext REG_SZ
                    shutdownwithoutlogon REG_DWORD 1 (0x1)
                    undockwithoutlogon REG_DWORD 1 (0x1)

                    ===============
                    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
                    NoDriveTypeAutoRun REG_DWORD 255 (0xff)
                    NoStartMenuMFUprogramsList REG_DWORD 1 (0x1)
                    NoDriveAutoRun REG_DWORD 255 (0xff)
                    HonorAutoRunSetting REG_DWORD 0 (0x0)

                    ===============
                    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
                    HonorAutoRunSetting REG_DWORD 0 (0x0)
                    NoDriveAutoRun REG_DWORD 255 (0xff)
                    NoDriveTypeAutoRun REG_DWORD 255 (0xff)

                    ===============
                    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]

                    ===============
                    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
                    AutoRestartShell REG_DWORD 1 (0x1)
                    DefaultDomainName REG_SZ YOUR-35063AB16-
                    DefaultUserName REG_SZ nathalie
                    LegalNoticeCaption REG_SZ
                    LegalNoticeText REG_SZ
                    PowerdownAfterShutdown REG_SZ 0
                    ReportBootOk REG_SZ 1
                    ShutdownWithoutLogon REG_SZ 0
                    System REG_SZ
                    VmApplet REG_SZ rundll32 shell32,Control_RunDLL "sysdm.cpl"
                    SfcQuota REG_DWORD -1 (0xffffffff)
                    allocatecdroms REG_SZ 0
                    allocatedasd REG_SZ 0
                    allocatefloppies REG_SZ 0
                    cachedlogonscount REG_SZ 10
                    forceunlocklogon REG_DWORD 0 (0x0)
                    passwordexpirywarning REG_DWORD 14 (0xe)
                    scremoveoption REG_SZ 0
                    AllowMultipleTSSessions REG_DWORD 1 (0x1)
                    UIHost REG_EXPAND_SZ logonui.exe
                    LogonType REG_DWORD 1 (0x1)
                    Background REG_SZ 0 0 0
                    DebugServerCommand REG_SZ no
                    SFCDisable REG_DWORD 0 (0x0)
                    WinStationsDisabled REG_SZ 0
                    HibernationPreviouslyEnabled REG_DWORD 1 (0x1)
                    ShowLogonOptions REG_DWORD 0 (0x0)
                    AltDefaultUserName REG_SZ nathalie
                    AltDefaultDomainName REG_SZ YOUR-35063AB16-
                    ChangePasswordUseKerberos REG_DWORD 1 (0x1)
                    Userinit REG_SZ C:\WINDOWS\system32\userinit.exe,
                    Shell REG_SZ explorer.exe
                    HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\SCLogon

                    ===============
                    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\AtiExtEvent]
                    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\crypt32chain]
                    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\cryptnet]
                    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\cscdll]
                    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\dimsntfy]
                    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ScCertProp]
                    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\Schedule]
                    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\sclgntfy]
                    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\SensLogn]
                    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\termsrv]
                    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\wlballoon]

                    ===============
                    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
                    {AEB6717E-7E19-11d0-97EE-00C04FD91972} REG_SZ

                    ===============
                    [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
                    %windir%\system32\sessmgr.exe REG_SZ %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019
                    C:\Program Files\TOSHIBA\ConfigFree\CFXFER.exe REG_SZ C:\Program Files\TOSHIBA\ConfigFree\CFXFER.exe:*:Enabled:ConfigFree SUMMIT Engine
                    %windir%\Network Diagnostic\xpnetdiag.exe REG_SZ %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000
                    C:\Program Files\Windows Live\Messenger\wlcsdk.exe REG_SZ C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call
                    C:\Program Files\Windows Live\Messenger\msnmsgr.exe REG_SZ C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger
                    C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe REG_SZ C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe:*:Enabled:Windows Live FolderShare
                    C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe REG_SZ C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe:*:Enabled:hpqtra08.exe
                    C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe REG_SZ C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe:*:Enabled:hpqste08.exe
                    C:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe REG_SZ C:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe:*:Enabled:hpofxm08.exe
                    C:\Program Files\HP\Digital Imaging\bin\hposfx08.exe REG_SZ C:\Program Files\HP\Digital Imaging\bin\hposfx08.exe:*:Enabled:hposfx08.exe
                    C:\Program Files\HP\Digital Imaging\bin\hposid01.exe REG_SZ C:\Program Files\HP\Digital Imaging\bin\hposid01.exe:*:Enabled:hposid01.exe
                    C:\Program Files\HP\Digital Imaging\bin\hpqscnvw.exe REG_SZ C:\Program Files\HP\Digital Imaging\bin\hpqscnvw.exe:*:Enabled:hpqscnvw.exe
                    C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe REG_SZ C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe:*:Enabled:hpqkygrp.exe
                    C:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe REG_SZ C:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe:*:Enabled:hpzwiz01.exe
                    C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe REG_SZ C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe:*:Enabled:hpoews01.exe
                    C:\Program Files\HP\Digital Imaging\bin\hpqnrs08.exe REG_SZ C:\Program Files\HP\Digital Imaging\bin\hpqnrs08.exe:*:Enabled:hpqnrs08.exe
                    C:\Program Files\Orange\Connectivity\ConnectivityManager.exe REG_SZ C:\Program Files\Orange\Connectivity\ConnectivityManager.exe:*:Enabled:CSS

                    [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
                    %windir%\system32\sessmgr.exe REG_SZ %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019
                    %windir%\Network Diagnostic\xpnetdiag.exe REG_SZ %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000
                    C:\Program Files\Windows Live\Messenger\wlcsdk.exe REG_SZ C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call
                    C:\Program Files\Windows Live\Messenger\msnmsgr.exe REG_SZ C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger
                    C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe REG_SZ C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe:*:Enabled:Windows Live FolderShare
                    C:\WINDOWS\Temp\alg.exe REG_SZ C:\WINDOWS\Temp\alg.exe:*:Enabled:Application Layer Gateway Service
                    C:\WINDOWS\system32\lsass.exe REG_SZ C:\WINDOWS\system32\lsass.exe:*:Enabled:LSA Shell
                    C:\WINDOWS\lsass.exe REG_SZ C:\WINDOWS\lsass.exe:*:Enabled:LSA Shell

                    ===============
                    ActivX controls
                    ===============

                    ===============
                    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\<{12d0ed0d-0ee0-4f90-8827-78cefb8f4988}
                    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}
                    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{26923b43-4d38-484f-9b9e-de460746276c}
                    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}
                    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{CB58DED6-4AF3-4080-9DF1-DEE72075169F}
                    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10072CEC-8CC1-11D1-986E-00A0C955B42F}
                    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{2179C5D3-EBFF-11CF-B6FD-00AA00B4E220}
                    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{22d6f312-b0f6-11d0-94ab-0080c74c7e95}
                    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{283807B5-2C60-11D0-A31D-00AA00B92C03}
                    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}
                    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{36f8ec70-c29a-11d1-b5c7-0000f8051515}
                    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{3af36230-a269-11d1-b5bf-0000f8051515}
                    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{3bf42070-b3b1-11d1-b5c5-0000f8051515}
                    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{411EDCF7-755D-414E-A74B-3DCD6583F589}
                    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{4278c270-a269-11d1-b5bf-0000f8051515}
                    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}
                    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA842-CC51-11CF-AAFA-00AA00B6015B}
                    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA848-CC51-11CF-AAFA-00AA00B6015C}
                    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA855-CC51-11CF-AAFA-00AA00B6015F}
                    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{45ea75a0-a269-11d1-b5bf-0000f8051515}
                    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{4f216970-c90c-11d1-b5c7-0000f8051515}
                    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{4f645220-306d-11d2-995d-00c04f98bbc9}
                    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{5945c046-1e7d-11d1-bc44-00c04fd912be}
                    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{5A8D6EE0-3E18-11D0-821E-444553540000}
                    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{5fd399c0-a70a-11d1-9948-00c04f98bbc9}
                    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{630b1da0-b465-11d1-9948-00c04f98bbc9}
                    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}
                    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{6fab99d0-bab8-11d1-994a-00c04f98bbc9}
                    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{7131646D-CD3C-40F4-97B9-CD9E4E6262EF}
                    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{73FA19D0-2D75-11D2-995D-00C04F98BBC9}
                    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{7790769C-0471-11d2-AF11-00C04FA35D02}
                    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{89820200-ECBD-11cf-8B85-00AA005B4340}
                    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{89820200-ECBD-11cf-8B85-00AA005B4383}
                    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{89B4C1CD-B018-4511-B0A1-5476DBF70820}
                    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{9381D8F2-0288-11D0-9501-00AA00B911A5}
                    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{9A394342-4A68-4EBA-85A6-55B559F4E700}
                    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}
                    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{C9E9A340-D1F1-11D0-821E-444553540600}
                    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
                    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{CC2A9BA0-3BDD-11D0-821E-444553540000}
                    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{CDD7975E-60F8-41d5-8149-19E51D6F71D0}
                    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{D27CDB6E-AE6D-11cf-96B8-444553540000}
                    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{DAA94A2A-2A8D-4D3B-9DB8-56FBECED082D}
                    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{de5aed00-a4bf-11d1-9948-00c04f98bbc9}
                    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{E92B03AB-B707-11d2-9CBD-0000F87A369E}

                    ==============
                    BHO :
                    ======
                    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{0347C33E-8762-4905-BF09-768834316C61}]
                    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{053F9267-DC04-4294-A72C-58F732D338C0}]
                    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
                    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{5C255C8A-E604-49b4-9D64-90988571CECB}]
                    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{6EBF7485-159F-4bff-A14F-B9E3AAC4465B}]
                    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
                    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0}]
                    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{E15A8DC0-8516-42A1-81EA-DC94EC1ACF10}]

                    ================
                    Internet Explorer :
                    ================
                    [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
                    Start Page REG_SZ https://www.msn.com/fr-fr

                    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
                    Start Page REG_SZ http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome

                    ========
                    Services
                    ========
                    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services]

                    Ndisuio : 0x3
                    EapHost : 0x3
                    SharedAccess : 0x2
                    wuauserv : 0x2

                    =========
                    Atapi.sys
                    =========

                    %%%% HASHDEEP-1.0
                    %%%% size,md5,sha256,filename
                    ## Invoked from: C:\Documents and Settings\nathalie\Local Settings\temp\2E.tmp
                    ## C:\> hashdeep C:\WINDOWS\System32\Drivers\atapi.sys
                    ##
                    96512,9f3a2f5aa6875c72bf062c712cfa2674,b4df1d2c56a593c6b54de57395e3b51d288f547842893b32b0f59228a0cf70b9,C:\WINDOWS\System32\Drivers\atapi.sys

                    %%%% HASHDEEP-1.0
                    %%%% size,md5,sha256,filename
                    ## Invoked from: C:\Documents and Settings\nathalie\Local Settings\temp\2E.tmp
                    ## C:\> hashdeep C:\WINDOWS\System32\DllCache\atapi.sys
                    ##
                    96512,9f3a2f5aa6875c72bf062c712cfa2674,b4df1d2c56a593c6b54de57395e3b51d288f547842893b32b0f59228a0cf70b9,C:\WINDOWS\System32\DllCache\atapi.sys

                    Sources
                    =======

                    C:\Qoobox\Quarantine\C\WINDOWS\system32\drivers\atapi.sys.vir
                    C:\Qoobox\Quarantine\C\WINDOWS\system32\drivers\atapi.sys.vir_
                    C:\WINDOWS\$NtServicePackUninstall$\atapi.sys
                    C:\WINDOWS\ERDNT\cache\atapi.sys
                    C:\WINDOWS\ServicePackFiles\i386\atapi.sys
                    C:\WINDOWS\system32\dllcache\atapi.sys
                    C:\WINDOWS\system32\drivers\atapi.sys

                    Référence :
                    ==========

                    Win XP_32b : a64013e98426e1877cb653685c5c0009
                    Win XP_SP2_32b : CDFE4411A69C224BD1D11B2DA92DAC51
                    Win XP_SP3_32b : 9F3A2F5AA6875C72BF062C712CFA2674
                    Vista_32b : e03e8c99d15d0381e02743c36afc7c6f
                    Vista_SP1_32b : 2d9c903dc76a66813d350a562de40ed9
                    Vista_SP2_32b : 1F05B78AB91C9075565A9D8A4B880BC4
                    Vista_SP2_64b : 1898FAE8E07D97F2F6C2D5326C633FAC
                    Windows 7_32b : 80C40F7FDFC376E4C5FEEC28B41C119E
                    Windows 7_64b : 02062C0B390B7729EDC9E69C680A6F3C

                    =======
                    Drive :
                    =======

                    D‚fragmenteur de disque Windows
                    Copyright (c) 2001 Microsoft Corp. et Executive Software International Inc.

                    Rapport d'analyse
                    55,89 Go total, 44,71 Go libre (79%), 1% fragment‚ (fragmentation du fichier 2%)

                    Il ne vous est pas n‚cessaire de d‚fragmenter ce volume.

                    ¤¤¤¤¤¤¤¤¤¤ Files/folders :

                    Present !! : C:\WINDOWS\002650_.tmp
                    Present !! : C:\WINDOWS\002676_.tmp
                    Present !! : C:\WINDOWS\005322_.tmp
                    Present !! : C:\WINDOWS\mbr.exe
                    Present !! : C:\WINDOWS\System32\drivers\etc\hosts.msn
                    Present !! : C:\WINDOWS\System32\SET48.tmp
                    Present !! : C:\WINDOWS\System32\SET4A.tmp
                    Present !! : C:\WINDOWS\System32\SET4F.tmp
                    Present !! : C:\WINDOWS\System32\SET56.tmp
                    Present !! : C:\WINDOWS\System32\SET5F.tmp
                    Present !! : C:\WINDOWS\System32\SET61.tmp
                    Present !! : C:\WINDOWS\System32\SET63.tmp
                    Present !! : C:\WINDOWS\System32\SET64.tmp
                    Present !! : C:\Documents and Settings\nathalie\Application Data\GDIPFONTCACHEV1.DAT
                    Present !! : C:\Documents and Settings\nathalie\Application Data\wklnhst.dat
                    Present !! : C:\Documents and Settings\nathalie\Application Data\GDIPFONTCACHEV1.DAT
                    Present !! : C:\Documents and Settings\nathalie\Application Data\wklnhst.dat

                    ¤¤¤¤¤¤¤¤¤¤ Keys :

                    Present !! : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\{0E5CBF21-D15F-11D0-8301-00AA005B4383}
                    Present !! : "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Install.exe"
                    Present !! : "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Setup.exe"

                    ============

                    catchme 0.3.1398.3 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
                    Rootkit scan 2010-02-04 15:26:33
                    Windows 5.1.2600 Service Pack 3 NTFS

                    scanning hidden processes ...

                    scanning hidden services & system hive ...

                    scanning hidden registry entries ...

                    scanning hidden files ...

                    scan completed successfully
                    hidden processes: 0
                    hidden services: 0
                    hidden files: 0

                    Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

                    device: opened successfully
                    user: MBR read successfully
                    kernel: MBR read successfully
                    user & kernel MBR OK

                    ==========
                    Programs
                    ==========

                    Adobe
                    Apoint2K
                    Atheros
                    ATI Technologies
                    ComPlus Applications
                    Creative
                    Fichiers communs
                    Google
                    Hewlett-Packard
                    HP
                    InstallShield Installation Information
                    Internet Explorer
                    InterVideo
                    KB824146Scan
                    List_Kill'em
                    Logitech
                    ltmoh
                    Malwarebytes' Anti-Malware
                    Messenger
                    Messenger Plus! Live
                    Microsoft
                    Microsoft CAPICOM 2.1.0.2
                    Microsoft Digital Image 2006
                    microsoft frontpage
                    Microsoft Office
                    Microsoft Silverlight
                    Microsoft SQL Server Compact Edition
                    Microsoft Sync Framework
                    Microsoft Works
                    Movie Maker
                    Mozilla Firefox
                    MSBuild
                    MSN
                    MSN Gaming Zone
                    MSN Toolbar Suite
                    MsOffice
                    MSXML 4.0
                    Navilog1
                    NetMeeting
                    Offre Wanadoo
                    Online Services
                    Orange
                    Outlook Express
                    QuickTime
                    Realtek
                    Reference Assemblies
                    SAGEM
                    Securitoo
                    Services en ligne
                    Symantec
                    TomTom DesktopSuite
                    TOSHIBA
                    Trend Micro
                    TrendMicro
                    Uniblue
                    Uninstall Information
                    VideoLAN
                    Wanadoo
                    Windows Live
                    Windows Live SkyDrive
                    Windows Media Connect 2
                    Windows Media Player
                    Windows NT
                    WindowsUpdate
                    WordBiz
                    xerox

                    ============
                    Drive C:
                    ============

                    2d8bd3553ec8a21835ddac6ef6f2
                    a6ba850e86dff35c49b4bb8e6fb93d
                    ab2846195912247de0614a2a
                    Application Data
                    autorun.inf
                    BJPrinter
                    Boot.bak
                    boot.ini
                    Bootfont.bin
                    cmdcons
                    cmldr
                    ComboFix.txt
                    Config.Msi
                    CONFIG.SYS
                    Documents and Settings
                    HaxFix.exe
                    HaxFix.txt
                    hiberfil.sys
                    I386
                    IO.SYS
                    Kill'em
                    List'em.txt
                    Media
                    MSDOS.SYS
                    NTDETECT.COM
                    ntldr
                    pagefile.sys
                    Program Files
                    Qoobox
                    RECYCLER
                    rsit
                    SUPPORT
                    SWSTAMP.TXT
                    System Volume Information
                    ToolsCD
                    UsbFix
                    UsbFix_Upload_Me_YOUR-35063AB16-.zip
                    VALUEADD
                    WINDOWS

                    ¤¤¤¤¤¤¤¤¤¤ Cracks | Keygens | Serials

                    ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤( EOF )¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
                2. Contributeur sécurité
                  ▶ Relance List&Kill'em (clic droit "exécuter en tant qu'administrateur" pour Vista/Seven) avec le raccourci sur ton bureau ,

                  mais cette fois-ci :

                  ▶ choisis l'option 2 = Mode Suppression

                  laisse travailler l'outil.

                  en fin de scan un rapport s'ouvre

                  ▶ colle le contenu dans ta reponse

                  Tu peux le désinstaller ensuite

                  ......................

                  Rends toi sur ce site :

                  https://www.virustotal.com/gui/

                  Clique sur parcourir et cherche ce fichier :

                  C:\WINDOWS\System32\alg.exe
                  C:\WINDOWS\Temp\alg.exe
                  C:\WINDOWS\lsass.exe

                  Clique sur Send File.

                  Un rapport va s'élaborer ligne à ligne.

                  Attends la fin. Il doit comprendre la taille du fichier envoyé.

                  Sauvegarde le rapport avec le bloc-note.

                  Copie le dans ta réponse.

                  Si tu ne trouves pas le fichier alors

                  Affiche tous les fichiers et dossiers :

                  Pour cela :
                  Clique sur démarrer/panneau de configuration/option des dossiers/affichage

                  Cocher afficher les dossiers cachés

                  Décoche la case "Masquer les fichiers protégés du système d'exploitation (recommandé)"

                  Décocher masquer les extensions dont le type est connu

                  Puis fais «appliquer» pour valider les changements.

                  Et OK
                  1. Kill'em by g3n-h@ckm@n 1.2.2.0

                    User : nathalie (Administrateurs)
                    Update on 03/02/2010 by g3n-h@ckm@n ::::: 16.30
                    Start at: 16:38:45 | 04/02/2010
                    Contact : https://forums.commentcamarche.net/forum/virus-securite-7

                    Intel(R) Celeron(R) M CPU 410 @ 1.46GHz
                    Microsoft Windows XP Édition familiale (5.1.2600 32-bit) # Service Pack 3
                    Internet Explorer 8.0.6001.18702
                    Windows Firewall Status : Disabled
                    FW : Norton Internet Worm Protection[ (!) Disabled ]2006

                    C:\ -> Disque fixe local | 55,89 Go (44,71 Go free) | NTFS
                    D:\ -> Disque CD-ROM

                    ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Processes running

                    C:\WINDOWS\System32\smss.exe
                    C:\WINDOWS\system32\csrss.exe
                    C:\WINDOWS\system32\winlogon.exe
                    C:\WINDOWS\system32\services.exe
                    C:\WINDOWS\system32\lsass.exe
                    C:\WINDOWS\system32\Ati2evxx.exe
                    C:\WINDOWS\system32\svchost.exe
                    C:\WINDOWS\system32\svchost.exe
                    C:\WINDOWS\System32\svchost.exe
                    C:\WINDOWS\system32\svchost.exe
                    C:\WINDOWS\system32\svchost.exe
                    C:\WINDOWS\system32\spoolsv.exe
                    C:\Program Files\Fichiers communs\LogiShrd\LVMVFM\LVPrcSrv.exe
                    C:\WINDOWS\system32\acs.exe
                    C:\WINDOWS\system32\svchost.exe
                    C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
                    C:\WINDOWS\system32\dllhost.exe
                    C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
                    C:\WINDOWS\system32\svchost.exe
                    C:\WINDOWS\system32\svchost.exe
                    C:\Program Files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe
                    C:\WINDOWS\System32\svchost.exe
                    C:\WINDOWS\System32\svchost.exe
                    C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
                    C:\WINDOWS\system32\svchost.exe
                    C:\WINDOWS\system32\TODDSrv.exe
                    C:\WINDOWS\System32\alg.exe
                    C:\WINDOWS\system32\Ati2evxx.exe
                    C:\WINDOWS\Explorer.EXE
                    C:\WINDOWS\system32\wbem\wmiprvse.exe
                    C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
                    C:\WINDOWS\RTHDCPL.EXE
                    C:\Program Files\Apoint2K\Apoint.exe
                    C:\Program Files\ltmoh\Ltmoh.exe
                    C:\WINDOWS\AGRSMMSG.exe
                    C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe
                    C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe
                    C:\Program Files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe
                    C:\Program Files\TOSHIBA\TouchPad\TPTray.exe
                    C:\WINDOWS\system32\ZoomingHook.exe
                    C:\WINDOWS\system32\TPSMain.exe
                    C:\Program Files\TOSHIBA\Utilitaire de zoom TOSHIBA\SmoothView.exe
                    C:\Program Files\TOSHIBA\Tvs\TvsTray.exe
                    C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe
                    C:\Program Files\TOSHIBA\TOSHIBA Direct Disc Writer\ddwmon.exe
                    C:\Program Files\TOSHIBA\ConfigFree\CFSServ.exe
                    C:\Program Files\Fichiers communs\LogiShrd\LComMgr\Communications_Helper.exe
                    C:\Program Files\Logitech\QuickCam\Quickcam.exe
                    C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
                    C:\Program Files\Orange\Systray\SystrayApp.exe
                    C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
                    C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                    C:\WINDOWS\system32\ctfmon.exe
                    C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                    C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\AlertModule\0\AlertModule.exe
                    C:\Program Files\Apoint2K\Apntex.exe
                    C:\WINDOWS\system32\TPSBattM.exe
                    C:\Program Files\TOSHIBA\ConfigFree\CFXFER.exe
                    C:\Program Files\Fichiers communs\Logishrd\LQCVFX\COCIManager.exe
                    C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
                    C:\Program Files\Orange\Launcher\Launcher.exe
                    C:\Program Files\Orange\connectivity\connectivitymanager.exe
                    C:\Program Files\Orange\Deskboard\deskboard.exe
                    C:\Program Files\Orange\connectivity\CoreCom\CoreCom.exe
                    C:\Program Files\Orange\connectivity\CoreCom\OraConfigRecover.exe
                    C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTCOMModule\0\FTCOMModule.exe
                    C:\WINDOWS\System32\svchost.exe
                    C:\Program Files\Mozilla Firefox\firefox.exe
                    C:\Program Files\List_Kill'em\List_Kill'em.scr
                    C:\WINDOWS\system32\cmd.exe
                    C:\WINDOWS\system32\wbem\wmiprvse.exe
                    C:\Documents and Settings\nathalie\Local Settings\temp\9A.tmp\pv.exe

                    Detections :
                    ==========

                    ¤¤¤¤¤¤¤¤¤¤ Files/folders :

                    Quarantined & Deleted !! : C:\WINDOWS\002650_.tmp
                    Quarantined & Deleted !! : C:\WINDOWS\002676_.tmp
                    Quarantined & Deleted !! : C:\WINDOWS\005322_.tmp
                    Quarantined & Deleted !! : C:\WINDOWS\mbr.exe

                    Quarantined & Deleted !! : C:\WINDOWS\System32\drivers\etc\hosts.msn
                    Quarantined & Deleted !! : C:\WINDOWS\System32\SET48.tmp
                    Quarantined & Deleted !! : C:\WINDOWS\System32\SET4A.tmp
                    Quarantined & Deleted !! : C:\WINDOWS\System32\SET4F.tmp
                    Quarantined & Deleted !! : C:\WINDOWS\System32\SET56.tmp
                    Quarantined & Deleted !! : C:\WINDOWS\System32\SET5F.tmp
                    Quarantined & Deleted !! : C:\WINDOWS\System32\SET61.tmp
                    Quarantined & Deleted !! : C:\WINDOWS\System32\SET63.tmp
                    Quarantined & Deleted !! : C:\WINDOWS\System32\SET64.tmp
                    Quarantined & Deleted !! : C:\Documents and Settings\nathalie\Application Data\GDIPFONTCACHEV1.DAT
                    Quarantined & Deleted !! : C:\Documents and Settings\nathalie\Application Data\wklnhst.dat

                    ==============
                    host file OK !
                    ==============

                    ========
                    Registry
                    ========
                    Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\{0E5CBF21-D15F-11D0-8301-00AA005B4383}
                    Deleted : "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Install.exe"
                    Deleted : "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Setup.exe"
                    ¤¤¤¤¤¤¤¤¤¤ Services fonctionnels

                    Ndisuio : Start = 3
                    EapHost -> Start = 2
                    Ip6Fw -> Start = 2
                    SharedAccess -> Start = 2
                    wuauserv -> Start = 2
                    wscsvc -> Start = 2

                    ============
                    Disk Cleaned
                    ============

                    ================
                    Prefetch cleaned
                    ================

                    ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤( EOF )¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
                    1. Bonjour,

                      Je n'arrive pas à trouver les fichiers :

                      C:\WINDOWS\Temp\alg.exe
                      C:\WINDOWS\lsass.exe
                      1. Contributeur sécurité
                        pourtant je les vois sur ton rapport

                        "C:\WINDOWS\Temp\alg.exe"="C:\WINDOWS\Temp\alg.exe:*:Enabled:Application Layer Gateway Service"

                        "C:\WINDOWS\lsass.exe"="C:\WINDOWS\lsass.exe:*:Enabled:LSA Shell"

                        as tu affiché les dossiers et fichiers cachés ?

                        et comment va le pc maintenant ?
                        1. Je cherche encore, mais bizarrement je ne trouve pas ces fichiers dans le disque C dans windows.

                          Par contre le PC semble aller mieux, mais je n'ai pas trop navigué ces derniers temps car je préférais régler le problème avant .
                        2. J'ai trouvé lsass.exe, voici l'analyse de Virus total :

                          Antivirus Version Dernière mise à jour Résultat
                          a-squared 4.5.0.50 2010.02.06 -
                          AhnLab-V3 5.0.0.2 2010.02.06 -
                          AntiVir 7.9.1.158 2010.02.05 -
                          Antiy-AVL 2.0.3.7 2010.02.05 -
                          Authentium 5.2.0.5 2010.02.05 -
                          Avast 4.8.1351.0 2010.02.06 -
                          AVG 9.0.0.730 2010.02.05 -
                          BitDefender 7.2 2010.02.06 -
                          CAT-QuickHeal 10.00 2010.02.06 -
                          ClamAV 0.96.0.0-git 2010.02.06 -
                          Comodo 3839 2010.02.06 -
                          DrWeb 5.0.1.12222 2010.02.06 -
                          eSafe 7.0.17.0 2010.02.04 -
                          eTrust-Vet 35.2.7286 2010.02.05 -
                          F-Prot 4.5.1.85 2010.02.05 -
                          F-Secure 9.0.15370.0 2010.02.06 -
                          Fortinet 4.0.14.0 2010.02.06 -
                          GData 19 2010.02.06 -
                          Ikarus T3.1.1.80.0 2010.02.06 -
                          Jiangmin 13.0.900 2010.02.06 -
                          K7AntiVirus 7.10.967 2010.02.05 -
                          Kaspersky 7.0.0.125 2010.02.06 -
                          McAfee 5883 2010.02.05 -
                          McAfee+Artemis 5883 2010.02.05 -
                          McAfee-GW-Edition 6.8.5 2010.02.05 -
                          Microsoft 1.5406 2010.02.06 -
                          NOD32 4840 2010.02.06 -
                          Norman 6.04.03 2010.02.05 -
                          nProtect 2009.1.8.0 2010.02.05 -
                          Panda 10.0.2.2 2010.02.05 -
                          PCTools 7.0.3.5 2010.02.06 -
                          Rising 22.33.05.04 2010.02.06 -
                          Sophos 4.50.0 2010.02.06 -
                          Sunbelt 3.2.1858.2 2010.02.06 -
                          TheHacker 6.5.1.0.181 2010.02.06 -
                          TrendMicro 9.120.0.1004 2010.02.06 -
                          VBA32 3.12.12.1 2010.02.05 -
                          ViRobot 2010.2.5.2174 2010.02.05 -
                          VirusBuster 5.0.21.0 2010.02.05 -
                          Information additionnelle
                          File size: 13312 bytes
                          MD5...: 91e6024d6d4dcdecdb36c43ecf9bbecb
                          SHA1..: f0d2a71e77908c5b9055fd848235a222532c5975
                          SHA256: d288c5cd69b8e4612b689fb33b9ccd5594634d14c14d53a842db742264a64d6b
                          ssdeep: 384:KgHUJZXmtGDWkzLWT4a8WfMptsN0BhgO49:d38z4zRfMpy0BF4
                          PEiD..: -
                          PEInfo: PE Structure information

                          ( base data )
                          entrypointaddress.: 0x14bd
                          timedatestamp.....: 0x48025186 (Sun Apr 13 18:31:34 2008)
                          machinetype.......: 0x14c (I386)

                          ( 3 sections )
                          name viradd virsiz rawdsiz ntrpy md5
                          .text 0x1000 0x10d0 0x1200 6.01 5501ba358fe3bca3fd6ff8d9d0ddcb45
                          .data 0x3000 0x6c 0x200 0.20 86a789a893c60d5e207d053188cdc250
                          .rsrc 0x4000 0x1b30 0x1c00 7.15 54488850c25258396b2c9492c36b0bd5

                          ( 5 imports )
                          > ADVAPI32.dll: FreeSid, CheckTokenMembership, AllocateAndInitializeSid, OpenThreadToken, ImpersonateSelf, RevertToSelf
                          > KERNEL32.dll: CloseHandle, GetCurrentThread, ExitThread, SetUnhandledExceptionFilter, SetErrorMode, QueryPerformanceCounter, GetTickCount, GetCurrentThreadId, GetCurrentProcessId, GetSystemTimeAsFileTime, TerminateProcess, GetCurrentProcess, UnhandledExceptionFilter, RtlUnwind, InterlockedExchange, VirtualQuery
                          > ntdll.dll: NtSetInformationProcess, RtlInitUnicodeString, NtCreateEvent, NtOpenEvent, NtSetEvent, NtClose, NtRaiseHardError, RtlAdjustPrivilege, NtShutdownSystem, RtlUnhandledExceptionFilter
                          > LSASRV.dll: LsaISetupWasRun, LsapDsDebugInitialize, LsapAuOpenSam, LsapCheckBootMode, ServiceInit, LsapInitLsa, LsapDsInitializePromoteInterface, LsapDsInitializeDsStateInfo
                          > SAMSRV.dll: SamIInitialize, SampUsingDsData

                          ( 0 exports )
                          RDS...: NSRL Reference Data Set
                          -
                          trid..: Win32 Executable Generic (42.3%)
                          Win32 Dynamic Link Library (generic) (37.6%)
                          Generic Win/DOS Executable (9.9%)
                          DOS Executable Generic (9.9%)
                          Autodesk FLIC Image File (extensions: flc, fli, cel) (0.0%)
                          sigcheck:
                          publisher....: Microsoft Corporation
                          copyright....: (c) Microsoft Corporation. All rights reserved.
                          product......: Microsoft_ Windows_ Operating System
                          description..: LSA Shell (Export Version)
                          original name: lsass.exe
                          internal name: lsass.exe
                          file version.: 5.1.2600.5512 (xpsp.080413-2113)
                          comments.....: n/a
                          signers......: -
                          signing date.: -
                          verified.....: Unsigned
                          pdfid.: -

                          ATENTION ATTENTION: VirusTotal est un service gratuit offert par Hispasec Sistemas. Il n'y a aucune garantie quant à la disponibilité et la continuité de ce service. Bien que le taux de détection permis par l'utilisation de multiples moteurs antivirus soit bien supérieur à celui offert par seulement un produit, ces résultats NE garantissent PAS qu'un fichier est sans danger. Il n'y a actuellement aucune solution qui offre un taux d'efficacité de 100% pour la détection des virus et malwares.

                          Autre fichier
                          VirusTotal © Hispasec Sistemas - Blog - Contact: info@virustotal.com - Terms of Service & Privacy Policy
                      2. Contributeur sécurité
                        vu pour issac

                        veifies ton pc en ligne et on conclut derriere
                        1. Bien vu car j'ai scanné avec Eset et il a trouvé un virus qui s'appelait je crois "Ogaric", j'ai ensuite confirmé la suppression, puis j'ai scanné à nouveau avec Eset t il n'y avait plus aucune infection, par contre je ne sais pas où sont passés les rapports.

                          En tout cas je te suis éternellement reconnaissant pour ton aide et surtout ta patience, et je m'excuse pour mes lacunes en informatique.

                          J'en termine avec deux questions :

                          Comment dois je faire pour indiquer que le sujet est résolu dans le forum ?

                          Que me conseilles-tu pour protéger mieux mon PC à l'avenir ?
                      3. Contributeur sécurité
                        dommage que tu n'est pas le rapport....

                        on nettoie

                        1)

                        Cherches et cliques sur C:\Program Files\trend micro\nathalie.exe
                        Au menu principal, choisir do a scan only, puis cocher la case devant les lignes suivantes à corriger et cliquer en bas sur Fix Checked
                        (si il manque des lignes, pas grave)

                        R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = https://www.bing.com/?FORM=TOOLBR&cc=fr&toHttps=1&redig=4527FFF1C12746FC9EDB535C75E80ECC
                        O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
                        O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
                        O4 - HKLM\..\Run: [PadTouch] C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe
                        O4 - HKLM\..\Run: [Tvs] C:\Program Files\TOSHIBA\Tvs\TvsTray.exe
                        O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
                        O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                        O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
                        O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
                        O9 - Extra button: Wanadoo - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - https://www.orange.fr/portail (file missing) (HKCU


                        .......................

                        2)

                        IMPORTANT

                        Purger la restauration systeme XP

                        http://www.bibou0007.com/windows-xp-f101/purger-la-restauration-du-systeme-sous-windows-xp-t151.htm

                        .............

                        3)
                        Télécharge ToolsCleaner2sur ton Bureau.
                        https://www.commentcamarche.net/telecharger/securite/22061-toolscleaner/

                        * Double-clique (clic droit "en tant qu'administrateur" pour Vista) sur ToolsCleaner2.exe pour le lancer.
                        * Clique sur Recherche et laisse le scan agir.
                        * Clique sur Suppression pour finaliser.
                        * Tu peux, si tu le souhaites, te servir des Options Facultatives.
                        * Clique sur Quitter pour obtenir le rapport.
                        * Poste le rapport (TCleaner.txt) qui se trouve à la racine de ton disque dur (C:\).

                        ▶Ensuite Tu peux supprimer ToolCleaner

                        4)

                        les protections...

                        otes moi moi d'un doute, je n'en vois pas sur tes rapports !

                        1. J'ai suivi tes instructions à la lettre tout a bien fonctionné, voici le rapport ci-dessous.
                          Concernant les protections, j'ai normalement une protection pévue par Orange, mais je dois vérifie si elle n'a pas été suppimé los des diverses manips.

                          [ Rapport ToolsCleaner version 2.3.11 (par A.Rothstein & dj QUIOU) ]

                          --> Recherche:

                          C:\Qoobox: trouvé !
                          C:\Documents and Settings\nathalie\Local Settings\temp\2E.tmp\mbr.log: trouvé !
                          C:\Documents and Settings\nathalie\Local Settings\temp\A7.tmp\mbr.exe: trouvé !
                          C:\Documents and Settings\nathalie\Recent\HijackThis.lnk: trouvé !
                          C:\Documents and Settings\nathalie\Recent\UsbFix.lnk: trouvé !
                          C:\Program Files\Navilog1: trouvé !
                          C:\Program Files\Navilog1\Navilog1.bat: trouvé !
                          C:\Program Files\Trend Micro\HijackThis.exe: trouvé !
                          C:\Program Files\Trend Micro\hijackthis.log: trouvé !
                          C:\Program Files\Trend Micro\HijackThis: trouvé !
                          C:\Program Files\Trend Micro\HijackThis\HijackThis.exe: trouvé !
                          C:\Program Files\Trend Micro\HijackThis\hijackthis.log: trouvé !
                          C:\Program Files\TrendMicro\HijackThis: trouvé !
                          C:\Program Files\TrendMicro\HiJackThis\hijackthis.log: trouvé !
                          C:\Qoobox\Quarantine\catchme.log: trouvé !
                          C:\WINDOWS\Haxfix: trouvé !
                          C:\WINDOWS\HaxFix\Haxfix.exe: trouvé !
                          C:\WINDOWS\HaxFix\catchme.exe: trouvé !
                          C:\WINDOWS\HaxFix\haxlog.txt: trouvé !

                          ---------------------------------
                          --> Suppression:

                          C:\Documents and Settings\nathalie\Recent\HijackThis.lnk: supprimé !
                          C:\Program Files\Navilog1\Navilog1.bat: supprimé !
                          C:\Program Files\Trend Micro\HijackThis.exe: supprimé !
                          C:\Program Files\Trend Micro\HijackThis\HijackThis.exe: supprimé !
                          C:\WINDOWS\HaxFix\Haxfix.exe: supprimé !
                          C:\WINDOWS\HaxFix\catchme.exe: supprimé !
                          C:\Documents and Settings\nathalie\Local Settings\temp\2E.tmp\mbr.log: supprimé !
                          C:\Documents and Settings\nathalie\Local Settings\temp\A7.tmp\mbr.exe: supprimé !
                          C:\Documents and Settings\nathalie\Recent\UsbFix.lnk: supprimé !
                          C:\Program Files\Trend Micro\hijackthis.log: supprimé !
                          C:\Program Files\Trend Micro\HijackThis\hijackthis.log: supprimé !
                          C:\Program Files\TrendMicro\HiJackThis\hijackthis.log: supprimé !
                          C:\Qoobox\Quarantine\catchme.log: supprimé !
                          C:\WINDOWS\HaxFix\haxlog.txt: supprimé !
                          C:\Qoobox: supprimé !
                          C:\Program Files\Navilog1: supprimé !
                          C:\Program Files\Trend Micro\HijackThis: supprimé !
                          C:\Program Files\TrendMicro\HijackThis: supprimé !
                          C:\WINDOWS\Haxfix: supprimé !
                      • 1
                      • 2